Legal
Privacy Policy
Inorganic Games LLC — Secure Fields
Last updated: July 16, 2026
1. Overview
This Privacy Policy explains how Inorganic Games LLC ("Inorganic Games," "we," "us," or "our") handles information in connection with Secure Fields (the "App"), a Jira Cloud app distributed through the Atlassian Marketplace. This policy covers the App only. It does not apply to our TikTok Mini Games, which are covered by a separate privacy policy.
2. Data the App stores, and where
Secure Fields exists to keep specific field values out of Jira's own data storage. When you use it:
- Protected field values, and the permission rules an admin configures for a field, are stored exclusively in Forge-hosted storage operated by Atlassian, using the storage mechanisms Atlassian designates for app data (including its Secret Store for sensitive values).
- If your site uses the App's access audit log, it records the issue ID, field ID, the acting user's account ID, the action taken, and a timestamp — never the protected value itself.
- We do not operate any servers of our own. The App makes no requests outside Atlassian's platform, and nothing it handles is sent to us, to analytics or advertising services, or to any other third party.
- We do not receive, view, or have any means of accessing your protected values. They are visible only within your own Jira site, to the users your admin has authorized.
3. Data this website collects
This page, and the rest of the App's documentation and legal pages hosted on inorganicgames.com, set no cookies and run no analytics or tracking scripts. If you email us, we receive whatever information you choose to include in that email (see Support), and nothing else.
4. Data residency
All in-scope App data (protected values, permission configuration, and audit records) is stored exclusively within Atlassian's Forge platform, under Atlassian's data residency program. That means it is hosted in the Atlassian-supported location your organization has chosen for your product, and migrates with your site if you change that location. We do not separately choose or control where this data is stored — Atlassian does.
5. Data retention and deletion
Protected values persist in Forge storage until a user with edit access overwrites them, or until the App is uninstalled and Atlassian's own data-lifecycle policies for app storage apply. Automatic deletion of a value when its issue is deleted is not yet implemented; this is on our roadmap, alongside a manual erasure procedure. If you need a value deleted before then, contact us.
6. Our role under data protection law
Because we never receive, store, or process your protected data outside Atlassian's platform, we do not believe Secure Fields makes us a data processor (under GDPR) or a business associate (under HIPAA) with respect to that data. This is our good-faith position based on how the App is built, not a substitute for your own organization's legal assessment, and it does not change your own obligations under those frameworks. Any regulated data you choose to store using Secure Fields is still subject to your organization's agreement with Atlassian, including any Business Associate Agreement or Data Processing Addendum you may have with Atlassian directly — Secure Fields does not extend or replace that relationship. If your organization requires a signed agreement with us specifically, see our Terms (Provider-Specific Terms, "Data Protection Addendum") and contact us.
7. Children's privacy
Secure Fields is a business tool for Jira Cloud administrators and their teams. It is not directed at, marketed to, or knowingly used by children.
8. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
9. Contact
Questions about this policy can be directed to:
Inorganic Games LLC
support@inorganicgames.com