bytera

Bytera Apps

Atlassian Marketplace apps that keep your knowledge alive and your teams in sync.

DocumentationPricingSupport
FEATURED
Pulse logoPulseContent Health for Confluence
DocumentationSecurity PolicyPrivacy PolicyTerms of Service
XPress logoXPressPDF Exporter for Confluence
DocumentationSecurity PolicyPrivacy PolicyTerms of Service
SyncUp logoSyncUpSprint Intelligence for Jira
DocumentationSecurity PolicyPrivacy PolicyTerms of Service
Spotlight logoSpotlightAI Charts & Reports for Jira
DocumentationSecurity PolicyPrivacy PolicyTerms of Service
BY PLATFORM Confluence JiraGET STARTEDTry it free on Marketplace ↗Book a demo
DocsPricingAbout
Book a demo
← Spotlight

Spotlight - Privacy Policy

Last updated: July 2026

1. Overview

Bytera ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how Spotlight, our Jira app listed on the Atlassian Marketplace, accesses, processes, and protects your data.

Bytera is the data controller and is fully responsible for the privacy, security, and integrity of any data processed by Spotlight. Atlassian is not responsible for our data practices.

2. Data We Access

Spotlight is a Jira app that turns plain-language descriptions into live charts, tables, and reports. To provide this functionality, Spotlight accesses the following data through Atlassian APIs:

2.1 Jira Data (Read-Only Access)

  • Issues & JQL search: Issue fields needed by the chart being rendered (status, assignee, priority, dates, story points, …) - fetched live at render time, aggregated in the viewer's browser, and discarded.
  • Boards & sprints: Board type and closed-sprint data - used for sprint velocity charts.
  • Projects & roles: Project names, keys, and role assignments - used for project access reviews (visible only to users who are project admins of those projects).
  • Jira Service Management data: SLA and request data, where an AI-composed report reads JSM endpoints - always with the viewing user's own permissions.
  • Groups: Group names - used by the admin permission settings for the shared gallery.

Important: Spotlight has read-only access to your Jira data and requests no write scopes at all. It cannot create, modify, or delete anything in your Jira instance.

2.2 User Context

  • Atlassian Account ID: Used to key your personal gallery, attribute shared spotlights to their author, and enforce per-user AI fair-use limits. We do not access or store profile details such as names or email addresses.

3. Data Processing

Important: Spotlight runs entirely within the Atlassian platform - including its AI. Drafting uses Atlassian-hosted models via the Forge LLMs platform. No data is sent to any external servers or third-party services.

3.1 AI Drafting

When you click "Draft with AI", Spotlight sends your description and light site context (project keys and names, status names) to an Atlassian-hosted model inside the Atlassian platform. Issue data is never sent to the model. The model returns a draft definition, which you review before saving. Bytera does not store or log the content of your prompts; only anonymous usage counters (call counts) are kept for fair use.

3.2 Rendering

Charts, tables, and reports are rendered in the viewing user's browser by fetching live data from Jira with that user's own permissions. Results are computed in-memory and never persisted. Two users viewing the same spotlight each see only what their own Jira permissions allow.

3.3 Forge Platform

Spotlight runs on Atlassian's Forge platform and uses Forge App Storage (Key-Value Store) to persist spotlight definitions and app settings - nothing else.

4. Data We Store

Data TypeWhereRetention
Private spotlight definitions (settings/JQL/plan + your description)Forge App Storage (within Atlassian cloud)Until you delete them or uninstall
Shared spotlight definitions (the same, plus the author's account ID)Forge App Storage (within Atlassian cloud)Until removed or uninstall
Sharing permission settings (Jira group names)Forge App StorageUntil app is uninstalled
AI usage counters (monthly call counts)Forge App StorageAuto-expire (~3 months)

We do not store your Jira issue data, chart results, or any personal data beyond the Atlassian account ID. AI prompts are not logged or stored - the description you save with a spotlight is stored only as part of that spotlight's definition, under your control.

5. How We Use Data

We use the data we access exclusively for:

  • Drafting spotlight definitions from your descriptions (core app functionality).
  • Rendering charts, tables, and reports live from Jira.
  • Operating the personal and team galleries and their permission settings.
  • Enforcing AI fair-use limits.

We do not sell, rent, share, or use your data for advertising, marketing, analytics, or any purpose other than providing Spotlight functionality. Your prompts and data are not used to train AI models by Bytera.

6. External Services

Spotlight does not use any external services. No data leaves the Atlassian platform. There are no external API calls, no third-party AI providers, no third-party integrations, and no data transmission outside of Atlassian's cloud infrastructure.

7. Data Security

We implement industry-standard security measures:

  • Forge Sandbox: Spotlight runs in Atlassian's secure Forge environment with tenant isolation and sandboxed execution.
  • No External Communication: Spotlight has no external backend - your data never leaves Atlassian's infrastructure.
  • Least Privilege: Read-only scopes only - no write, no admin, no delete permissions.
  • Viewer-Permission Rendering: Every render uses the viewing user's own Jira permissions - sharing a spotlight can never expose data the viewer could not already see.
  • Sandboxed report plans: AI-composed reports are validated against a strict allowlist - GET-only requests to Atlassian REST APIs, with hard budgets on steps and calls.

8. Data Sharing

We do not share your data with any third parties. Since Spotlight operates entirely within the Atlassian platform with no external services, there is no data transmission outside of Atlassian's cloud environment.

Within your site, spotlights you explicitly mark as "Shared with the team" publish their definition (settings, title, your description, your name as author) to users permitted to view the team gallery - never the underlying Jira data.

The only exception: We may disclose data when required by law, legal process, or to protect our rights or the safety of users.

9. Your Rights

In accordance with applicable data protection laws (including GDPR), you have the right to:

  • Access: Request information about what data we process.
  • Rectification: Request correction of inaccurate data. You can edit or delete your spotlights at any time inside the app.
  • Erasure: Request deletion of your data. Deleting a spotlight removes it immediately; uninstalling Spotlight removes all app data from Forge storage.
  • Data Portability: Request your data in a portable format.
  • Objection: Object to the processing of your data.

To exercise any of these rights, please contact us at support@bytera.tech.

10. Permissions Explained

Spotlight requests the following Atlassian API scopes and their justification:

PermissionWhy It's Needed
read:jira-workRead issues and run JQL searches for charts; Jira-admin check for settings
read:jira-userRead group membership for group-based sharing permissions
read:board-scope:jira-softwareIdentify Scrum boards for velocity charts
read:sprint:jira-softwareRead closed sprints for velocity charts
read:issue-details:jiraAccess issue fields used by chart metrics and groupings
read:jql:jiraValidate JQL queries with Jira's own parser before saving
read:project:jiraList projects and roles for access reviews and AI site context
storage:appSave spotlight definitions and settings in Forge storage

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of material changes by updating the "Last updated" date and, where appropriate, through our Atlassian Marketplace listing.

12. Contact

For any privacy-related questions, data requests, or security concerns:

  • Email: support@bytera.tech
  • Website: bytera.tech/contact
  • Marketplace: Bytera on Atlassian Marketplace
bytera

Building the Digital Era

Apps

  • Pulse
  • XPress
  • SyncUp
  • Spotlight
  • Atlassian Marketplace ↗

Company

  • About Us
  • Blog
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Trust Center

© 2026 Bytera. All rights reserved.