Last updated: 6 August 2026 Provider: IDEAL WORKS (Japan) Contact: support@conduitworks.dev
This Privacy Policy describes how the Atlassian Forge app Support Attachment Sync for Jira (the "App"), published by IDEAL WORKS (the "Provider", "we", "us"), handles data.
The App links Intercom customer support conversations to Jira issues and synchronises attachments from Intercom — for example screenshots, images, and videos sent by end customers — into the linked Jira issue as native Jira attachments.
The App is built on the Atlassian Forge platform and runs entirely on Atlassian's infrastructure. The Provider does not operate its own servers, databases, or hosting environment for the App.
This policy covers only the App. It does not cover Atlassian's own products and services, Intercom's services, or any other software you use.
The App stores the following in Forge key-value storage, within the Atlassian environment associated with your Jira Cloud site.
| Data | Purpose | Storage |
|---|---|---|
| Intercom access token | Authenticating API calls to Intercom | Encrypted (kvs.setSecret) |
| Intercom client secret | Verifying that incoming webhooks really come from Intercom | Encrypted (kvs.setSecret) |
| Jira issue key ↔ Intercom conversation ID mapping | Determining which issue an attachment belongs to (stored in both directions) | Forge app storage |
| Synchronisation records | Showing sync status in the issue panel and supporting troubleshooting | Forge app storage |
Synchronisation records contain, for the most recent sync of each issue:
Two consequences are worth stating plainly:
passport-scan.pdf). Such names
are stored as part of the sync record.When a synchronisation runs, attachment content and the conversation data needed to locate it pass through the App's execution context in memory only. This content is not written to the App's storage and does not persist after the operation completes.
Separately from synchronisation, the Jira issue panel fetches the linked conversation from Intercom each time the panel is displayed, and shows its state and attachment metadata (file name, size, content type) to the Jira user viewing the issue. This metadata is not stored, but it is visible to any Jira user who can view that issue.
The App exposes a Forge web trigger URL that receives notification payloads from Intercom. This URL is reachable without authentication, so every payload is verified by HMAC-SHA1 signature before anything else happens (see §4). Verified payloads are parsed in memory to extract the conversation ID and are then discarded — only the conversation ID and the linked Jira issue key are passed to the App's internal queue.
The App requests these Jira scopes and no others:
read:jira-workwrite:jira-workstorage:appThe App does not request Jira administrator permissions, nor permission to modify project configuration.
The App communicates only with the following hosts, as declared in its Forge manifest:
api.intercom.io*.intercom-attachments-1.com through *.intercom-attachments-5.com*.intercomcdn.com*.intercomassets.comThe App does not transmit any of this data to the Provider, and the Provider has no facility to receive it.
X-Hub-Signature), keyed with your Intercom client secret. A payload whose signature
does not match is discarded without being acted on, and the rejection is recorded so an
administrator can see it on the settings screen.The App transfers data only between the two services it exists to connect:
The App sends no data to the Provider, to analytics or advertising services, or to any other third party. We do not sell, rent, or trade any data.
We may disclose information only where required by applicable law. Because the Provider has no access to data stored by the App, such a request would in practice need to be directed to Atlassian or Intercom as the parties actually holding the data.
The App is designed to minimise processing: it stores no attachment content and no conversation bodies, and the Provider has no access to data held in your Forge storage.
Data subject requests. Because the Provider holds no customer data, requests from data subjects (access, erasure, rectification, restriction, portability, or objection) should be directed to you as the controller and fulfilled within Jira and Intercom. We will provide reasonable assistance if you contact us at support@conduitworks.dev.
International transfers. Where App data is stored is determined by the Atlassian Forge platform and your Jira Cloud site's configuration. Attachment retrieval involves connections to the Intercom endpoints listed in §2.
| Sub-processor | Role |
|---|---|
| Atlassian Pty Ltd | Hosts the App and stores all App data (Atlassian Forge, Jira Cloud) |
| Intercom, Inc. | Source system for conversations and attachments, accessed with the credentials you supply |
Both are services you already have a relationship with as a condition of using the App. We will update this section if any additional sub-processor is introduced.
If this policy changes materially, we will update the "Last updated" date above and publish the revised policy at the URL listed on the App's Atlassian Marketplace listing.
IDEAL WORKS Email: support@conduitworks.dev