Totesoft Documentation

Wake Privacy and Security

Status: customer-facing draft; publish only after the Wake logging and legacy-storage release gates are closed.

Hosting and data flow

Wake is an Atlassian Forge app for Jira Cloud. The reviewed manifest declares no external network egress and no Totesoft-hosted remote backend.

Wake requests Jira data as the current user. Depending on the selected filter and fields, it processes:

Wake does not intentionally create, update, transition, or delete Jira issues.

Field minimization

Wake requests configured fields plus a small helper set. It does not offer Description, Attachments, Comments, Worklogs, and similar heavy fields as gadget columns.

Configuration and storage

The active gadget UI submits its configuration through Atlassian’s dashboard gadget configuration mechanism.

The current backend also contains legacy Forge KVS handlers for a FRAME_CONFIG key and the manifest declares storage:app. No active caller was found in current main. Before publishing this page, Totesoft must either:

  1. remove the legacy handlers and scope after checking older installations; or
  2. replace this section with a precise description of the retained record, access path, retention, and deletion behavior.

Logs

Authorized Totesoft personnel with access to the Forge app environments can access Forge application logs for support, security, and operations.

The current code can log full JQL strings and truncated Jira error-response bodies. That content must be redacted before the preferred launch state. If it is not redacted, the public privacy notice must explicitly disclose it and the Marketplace answer to “Does the app log End-User Data?” must be Yes.

Even after redaction, if logs retain issue keys, filter IDs, or other customer identifiers, the answer remains Yes, with an explanation that the app logs limited diagnostic metadata but not selected issue-field values.

CSV files

Paid/trial CSV files are created from loaded issues in the user’s browser and downloaded directly to the device. They are not sent to a Totesoft server. The customer controls the downloaded file after creation.

External sharing

The reviewed implementation does not send Jira data to third-party analytics, advertising, monitoring, or AI services. Atlassian provides Jira Cloud, Forge execution, Marketplace licensing context, Forge logs, and any retained Forge hosted storage.

Security controls

Customer responsibilities

Customers are responsible for:

Security reports

Until Totesoft publishes a dedicated security address, send reports to info@totesoft.com with the subject Wake Security Report. Do not include customer production data or secrets in the initial message.