Privacy & Data Handling

Privacy & Data Handling

Last updated: August 28, 2026

This page describes how CFGORA handles data based on current product behaviour. It should be read together with our Terms of Service.

Who operates CFGORA

CFGORA is an independent software product for Jira Cloud configuration health monitoring. CFGORA is an independent product and is not affiliated with or endorsed by Atlassian.

Contact

For privacy questions, data subject requests, account assistance, or deletion enquiries, email support@cfgora.com.

Connecting to Jira Cloud

You connect through Atlassian OAuth 2.0. Authorization happens directly with Atlassian. We do not receive or store your Atlassian password. CFGORA stores encrypted OAuth tokens needed to refresh the Jira connection and run scans.

Data accessed from Jira

During scans, CFGORA reads Jira configuration and administrative signals needed to assess site health — for example projects, workflows, custom fields, and audit records where available. This data is used only to produce health scores, findings, investigations, and recommended remediation plans. CFGORA does not modify Jira configuration.

Data stored by CFGORA

CFGORA may store: connected Jira site name and URL; encrypted Jira connection credentials; saved scan summaries and finding snapshots; recommended remediation plans and item status; notification preferences; alerts; automatic-scan settings; CFGORA workspace identity; billing identifiers and subscription status needed to operate a plan; trial timing and status; plan-interest records (plan name only); and privacy-safe billing funnel event names. Funnel events may include a random anonymous visitor identifier, session grouping id, coarse country code, marketing attribution parameters (UTM), and referrer domain. Events are linked to your CFGORA workspace when you are signed in. CFGORA does not store card numbers, CVC, or full payment-method details.

Session cookies

HTTP-only session cookies keep you signed in to CFGORA while you use the product. These cookies are not accessible to client-side JavaScript.

Anonymous website analytics

On public CFGORA marketing pages, CFGORA may set a first-party cookie with a random visitor identifier and record which public pages were visited in aggregate. Tracked routes are limited to the homepage (including the how it works section at /#how-it-works), pricing, demo, security, privacy, and terms pages. After you sign in with Atlassian, CFGORA may link that anonymous visitor identifier to your workspace for aggregate journey reporting. This cookie is not used for advertising, does not store your name or email, and does not record your IP address. Precise location is not stored — only an optional country code from infrastructure geo headers when available.

How we use your data

Data is used to provide configuration health monitoring, saved scan history, trends, remediation tracking, notifications, and workspace billing. We do not use your Jira data for advertising or unrelated profiling.

We do not sell your data

We do not sell, rent, or trade your personal information or Jira data to third parties.

Service providers

CFGORA uses third-party providers to operate the service, including Atlassian (Jira Cloud authentication and API access), Stripe (payment processing), and cloud infrastructure providers that host the application and database. These providers process data only as needed to deliver the service.

Revoking access and disconnection

You can revoke CFGORA's access from your Atlassian account settings under connected apps. You can also disconnect or change sites within CFGORA. Disconnecting stops new scans for that site but saved scan history already stored in CFGORA may remain until you request deletion.

Payments

Paid plans are processed by Stripe. Stripe handles payment method and card data. CFGORA stores only the billing identifiers, subscription status, trial timing/status, plan-interest records, and billing funnel event names needed to operate plans and measure conversion. CFGORA does not store card numbers or CVC.

Data retention

Saved scan history visibility follows your plan (7 days on Free, 90 days on Pro, 365 days on Business, or unlimited on Legacy workspaces). CFGORA retains workspace, connection, billing, and saved monitoring data while your workspace remains active. To request deletion of CFGORA workspace data, email support@cfgora.com.

Your rights

Depending on your location, you may have rights to access, correct, or delete personal data CFGORA processes, or to object to or restrict certain processing. To exercise these rights, email support@cfgora.com. We will respond using the contact details you provide.

International processing

Data may be processed in jurisdictions where CFGORA or its service providers operate. Atlassian and Stripe process data according to their own privacy policies and regional terms.

Product independence

CFGORA is an independent product and is not affiliated with or endorsed by Atlassian.

Jira and Atlassian are trademarks of Atlassian Pty Ltd.