Workflow Guard for Jira

Privacy and data flow

How Workflow Guard for Jira processes rule configuration and Jira data within Atlassian services.

Updated: 5 October 2026. This notice applies to Workflow Guard for Jira, published by NexaForge Labs using the RenewalHub website and support channel.

What the app does

Workflow Guard adds conditions and validators to company-managed Jira Cloud workflows. Atlassian Forge serves its static configuration interface. Jira evaluates the saved guards as Jira expressions when someone attempts a transition.

Data used

During configuration, the interface reads status and link-type metadata using the current user’s Jira permissions and sends generated expressions to Jira’s analyser. Jira stores the selected template, validated settings, selected IDs and display labels, readable summary, failure message and generated expression in the workflow rule.

  • At transition time, configured guards use status/category, link type/direction, parent/subtask relationships, attachment count, Fix Version released/archived state, current/completed sprint state and due dates.
  • The app counts attachments; it does not retrieve file contents or inspect file names, types or size.
  • Linked-work checks and link counts include only links Jira exposes to the transitioning user. Hidden links cannot be validated.
  • The app does not collect passwords, API tokens or other credentials. Administrator-written messages and labels may contain information that the administrator chooses to enter.

Where processing and storage happen

The app has no external application server, external database, Forge KVS or Remote, third-party analytics, advertising or crash-reporting service, and declares no external egress. SDK dependencies are bundled locally. Transition evaluation makes no app network request.

Rule configuration stays in Jira and follows Jira’s workflow lifecycle and retention controls. Removing a rule removes its active configuration; Atlassian may retain workflow or history copies under its own policies. The app has no separate customer-data database or deletion service. Atlassian may independently retain platform logs, metrics and telemetry under its policies.

Licensing and uninstall

Atlassian handles Marketplace billing and licensing. An inactive license makes configuration read-only while existing rules continue enforcing their business requirements. Before uninstalling, remove all app conditions and validators and publish the workflows. Rules left behind can block transitions.

Support correspondence

If you voluntarily email hello@renewalhub.co.za, the publisher receives your email address and information you include to respond and provide support. Email delivery and storage involve the publisher’s email provider. Support email is separate from runtime app processing. Avoid confidential work-item data, credentials and private attachments. Contact the same address about access, correction or deletion where applicable. See the website privacy notice: https://renewalhub.co.za/privacy

Changes and contact

This notice will be updated when the app’s architecture or data practices change. For privacy questions, email hello@renewalhub.co.za. Website: https://renewalhub.co.za