Last updated 3 July 2026
Vellum (“the App”) is an audit-trail and change-history app for Jira Cloud, published by Worqflow (“we”, “us”). This policy explains what the App processes and how. Its defining characteristic is simple: your data never leaves Atlassian.
The App is built entirely on Atlassian Forge and runs inside Atlassian’s cloud infrastructure. It has no external servers and makes no network calls to any third party. It is eligible for Atlassian’s “Runs on Atlassian” program, which certifies that an app’s data stays within Atlassian’s environment. We never receive, transmit, store, or have access to your Jira data on our own systems.
To build your audit trail, the App reads and records metadata about changes to Jira work items on sites where it is installed, including:
The App reads this information using the Jira permissions you grant at install (read:jira-work, read:jira-user) and stores it using Atlassian’s Forge storage (storage:app).
All audit records are stored exclusively in Atlassian-hosted Forge storage attached to your installation, within Atlassian’s cloud. Data is logically isolated per installation. We do not copy it elsewhere.
Site administrators control how long records are retained via the App’s admin console; records older than the configured window are pruned automatically. When the App is uninstalled, its Atlassian-hosted storage for that installation is removed in accordance with Atlassian’s Forge data-lifecycle handling.
Within Jira, the App honors your project and issue-level security when displaying reports, and restricts administrative functions to Jira site administrators. Because the App runs on Forge with no external systems, Worqflow personnel have no standing access to your audit data.
The App’s sole infrastructure provider is Atlassian, which hosts and processes the data on your behalf under the Atlassian Cloud Terms and Atlassian’s Privacy Policy. We use no other sub-processors for App data.
We may update this policy; material changes will be reflected here with a revised “last updated” date.
Questions about this policy or the App’s data handling: briano@worqflow.org, or via our support portal.
← Back to Vellum