Planning Poker is built on Atlassian Forge and runs entirely on Atlassian's infrastructure. It does not use external servers and does not send customer data outside Atlassian's cloud.
Hosting and data storage
All app code (functions and resolvers) runs on Atlassian Forge, hosted by Atlassian.
All app data is stored in Atlassian Forge storage. Aioomi does not operate its own servers or databases.
Data is encrypted in transit and at rest by the Atlassian Forge platform.
Access control
The app uses Forge's scoped permissions and Atlassian's standard authentication and authorization for every request.
The app accesses only the Jira data needed for estimation (the issues you choose), acting on the user's behalf through Atlassian's API.
Data sharing
The app does not share data with third parties, does not use analytics or advertising trackers, and does not sell data.
Personal data
The app stores minimal personal data (Atlassian account IDs and optional display names) only to run estimation sessions.
The app integrates Atlassian's Personal Data Reporting, so that when an account is closed or changed, the associated data is erased or refreshed.
Shared responsibility and compliance
Security follows Atlassian's shared responsibility model for Forge apps. The app complies with Atlassian's Marketplace security requirements, including TLS 1.2 or higher for all traffic, encryption at rest, and keeping dependencies free of known critical or high vulnerabilities.
Reporting a vulnerability
If you discover a security issue, please email aioomi_at_support@aioomi.com. We will respond promptly and work to resolve valid issues.
Updates
We may update this Security Policy over time and will reflect any changes on this page.