Northstack Apps / Nativelog
Nativelog — Privacy Policy
The short version. Nativelog does not keep a copy of your hours. Every entry it creates is a native Jira worklog, written as you, and it stays in your Jira site. The only thing Nativelog stores is the timer you currently have running, and that record is deleted the moment the timer stops. The app runs entirely on Atlassian infrastructure and sends nothing to any third party.
Who we are
Nativelog is developed by Northstack Apps. For anything in this policy, contact [email protected].
For the purposes of the GDPR, the customer who installs Nativelog into their Jira site is the data controller. Northstack Apps acts as a data processor for the small amount of data described below.
Where the app runs
Nativelog is an Atlassian Forge app. It runs inside Atlassian's own cloud infrastructure and is eligible for Atlassian's Runs on Atlassian programme, which means app data is stored on Atlassian-operated infrastructure in the same way your Jira data is. There is no Northstack Apps server involved in running the app, and no data is transferred to one.
What Nativelog stores
Exactly one kind of record, and only while a timer is running:
| Data | Why | How long |
|---|---|---|
| Your Atlassian account ID | To keep your running timer separate from anyone else's | Until the timer stops or is discarded |
| The work item ID the timer is running on | To know where to log the time when you stop | Until the timer stops or is discarded |
| The instant the timer started | To calculate the duration | Until the timer stops or is discarded |
When you stop a timer, that record becomes a native Jira worklog and the stored record is deleted. No logged hour is ever kept in Nativelog's own storage.
What Nativelog reads
To show your timesheet, Nativelog reads worklogs, work items and project data from your Jira site through Atlassian's official APIs, using your own permissions — it can never see anything in Jira that you could not see yourself. This data is read at the moment you open a screen, used to draw that screen, and not retained afterwards.
Nativelog also asks Jira which permissions you hold on a work item, so it can tell you up front whether you are able to log work there.
What Nativelog writes
Native Jira worklogs, created, edited and deleted as you rather than as the app. That is the entire point of the product: your time appears under your name in Jira's own Work log tab and in reports, and it survives the app being uninstalled. Nativelog only ever edits or deletes worklogs whose author is you.
What Nativelog does not do
- No analytics, tracking pixels, or usage telemetry.
- No cookies beyond what Atlassian itself sets to run Jira.
- No advertising, and no selling or sharing of data with anyone.
- No third-party sub-processors. There is no service beyond Atlassian in the path.
- No AI or machine-learning training on your data.
- No copy of your worklog history in any database of ours, because there is no database of ours.
Data retention and deletion
A running-timer record is deleted when the timer stops or is discarded. If you uninstall Nativelog, any remaining running-timer records for your site are removed by Atlassian as part of the app's storage being torn down.
Worklogs are not deleted when you uninstall, because they are not ours to delete: they are ordinary Jira worklogs and they stay in your Jira site exactly as if they had been entered by hand. This is deliberate, and it is the main reason the product exists.
Your rights
Because Nativelog stores almost nothing, most requests are answered by Jira itself: your logged hours are Jira data, and your Jira administrator can export, correct or delete them through Atlassian's own tools. For the running-timer record, stopping or discarding the timer deletes it immediately.
For any request under the GDPR, LGPD, CCPA or similar legislation — access, correction, deletion, portability, or objection — write to [email protected] and we will respond within 30 days.
Security
Nativelog holds no credentials of its own. Every call to Jira is made through Atlassian's authenticated APIs on your behalf, and the app requests the narrowest set of permissions it can work with: read your user identity, read work items and worklogs, write worklogs, and use Forge storage for the running timer.
Beta programme
During the private beta, the same rules apply without exception. We do not read your worklog data, and we have no way to: the app runs in your site and reports nothing back to us. Feedback reaches us only when a participant sends it.
Changes to this policy
If this policy changes in a way that affects what is stored or who can see it, the date at the top changes and participants in the beta are told directly.