In short
The extension holds your Jira sign-in, your settings and a small cache of your own Jira data on your own device. It sends that data to exactly one place: the Atlassian site you connected it to. There is no analytics, no tracking, no advertising, and no third-party service of any kind. Disconnecting the extension erases everything it stored.
1. Who this notice is from
Jira Time Logger is published and maintained by Panit Wechasil, an independent developer, who is responsible for the extension and for this notice. There is no company behind it. Questions about either can be sent to support@jira-time-logger.app.
The extension works with Atlassian Jira Cloud. Atlassian is a separate company and its handling of your data is governed by its own privacy policy, not this one.
2. What data the extension handles
The categories below use the vocabulary Google requires for Chrome Web Store disclosures, so that this notice and the store listing say the same thing. Data is disclosed here even when it never leaves your device.
| Category | What this means in practice |
|---|---|
| Authentication information | Your Atlassian OAuth access and refresh tokens, or — if you choose API-token sign-in — your Atlassian email address and API token. These prove to Jira that requests are yours. |
| Personally identifiable information | Your Atlassian account identifier, display name and email address, read from Jira's own profile endpoint so the extension knows whose worklogs to show. If you manage people, the names and account identifiers of your direct reports are also held, so the manager view can list them. |
| Web history | While you are on a Jira page, the page address is passed from the page to the extension's background process so it can work out which issue you are viewing and offer to log against it. Addresses are used at that moment and are not recorded, profiled or transmitted. The extension runs on Atlassian sites only and cannot see any other site you visit. |
The extension also holds your own settings — your Jira site address, your daily target hours, your reminder time, which days you dismissed the banner — and a small cache of your own recent Jira issues and daily worklog totals.
When you write a note alongside a worklog, or post an approval comment, that text is sent to your Jira site because that is what you asked the extension to do. It is not stored anywhere else and is not read for any other purpose.
What the extension does not handle
- No health, financial or payment data.
- No location data.
- No clicks, scrolling, mouse movement or keystroke logging.
- No browsing history outside Atlassian sites.
- No reading of page content beyond detecting that a Jira page changed.
3. What it uses that data for
The extension has one purpose: to help you record your working time in Jira. Everything it holds serves that purpose.
- Signing you in — tokens authenticate your requests to your Jira site.
- Showing what you owe — your worklog totals drive the toolbar badge and the inline banner.
- Reminding you — your settings decide whether and when a daily reminder appears.
- Logging your time — hours, dates, issue keys and any note you write are sent to your Jira site.
- Manager review — if you have direct reports, their names and hours populate the monthly approval view.
- Not losing work — entries that fail to send are queued locally and retried.
4. Where data is kept, and for how long
Everything the extension stores is kept in your browser's own extension storage, on your device, under your browser profile. There is no server behind this extension — no backend is operated for it, and the developer receives no copy of your data.
- Sign-in tokens — until you disconnect, sign out or uninstall.
- Settings — until you change them, disconnect or uninstall.
- Cached Jira data — refreshed as you use the extension; direct-report lists are refreshed at least once every 24 hours.
- Queued entries — removed as soon as they reach Jira.
- Page addresses — used momentarily to identify the current issue, never written to storage.
Worklogs themselves live in Jira, where they are subject to your organisation's Jira retention arrangements rather than this notice.
5. Who data is shared with
One destination only: the Atlassian Jira Cloud site you connected the
extension to, over HTTPS, using your own credentials. Specifically
auth.atlassian.com and api.atlassian.com for sign-in and the Jira
API, and your own *.atlassian.net site.
There are no other recipients. No analytics provider, no crash reporting, no advertising network, no data broker, and no developer-operated server. The extension contains no third-party tracking code and loads no remote code.
6. Limited use commitments
Jira Time Logger's use of information received from Google APIs, and all other user data it handles, adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically:
- User data is not sold, and is not transferred to third parties except as needed to provide the extension's single purpose — that is, to your own Atlassian site.
- User data is not used or transferred for any purpose unrelated to that single purpose.
- User data is not used or transferred to determine creditworthiness or for lending purposes.
- User data is not used for advertising, profiling or model training.
- No human reads your data; the developer has no access to it.
7. Your choices, and how to erase your data
- Disconnect — in the extension's settings, disconnecting clears all stored data, including your tokens, settings and every cache, and cancels scheduled background work.
- Uninstall — removing the extension deletes its storage with it. Where the extension is installed by IT policy, ask your IT team to remove it.
- Turn off reminders — the daily reminder can be disabled in settings, or muted at the browser level.
- Revoke access at Atlassian — you can revoke the extension's OAuth authorisation, or delete the API token you issued, in your Atlassian account settings at any time.
Erasing the extension's local data does not delete worklogs already recorded in Jira. To change or remove those, use Jira, or ask your Jira administrator.
Depending on where you live, you may have rights to access, correct, export or delete personal data held about you. Because no copy of your extension data is held by the developer, there is nothing to retrieve or erase on your behalf — the controls above do it directly on your device. Data already recorded in Jira is held by your Jira site's operator, not by this extension. If you are unsure who to ask, write to support@jira-time-logger.app.
8. How data is protected
- All network requests use HTTPS.
- Sign-in uses Atlassian's OAuth 2.0 authorisation-code flow with PKCE; the extension never sees your Atlassian password.
- Stored data is confined to the extension's own storage area, which other websites and other extensions cannot read.
- The site address you enter is validated as a genuine Atlassian Cloud host before any credential is sent to it.
- The extension loads no remote code. Everything it runs ships inside the reviewed package.
No system is perfectly secure. If you believe the extension has a security problem, please report it to support@jira-time-logger.app rather than disclosing it publicly.
9. This website
These pages are static. They set no cookies, run no analytics and load nothing from third parties. Standard web-server logs may record requests, including IP addresses, for security and operational purposes.
10. Changes to this notice
If the extension's handling of data changes, this notice is updated before the change ships and the effective date at the top is revised. Where an organisation distributes the extension to its staff, material changes are also announced through that channel.
11. Contact
Questions about this notice or about how the extension handles data: support@jira-time-logger.app.