Bytera ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how Spotlight, our Jira app listed on the Atlassian Marketplace, accesses, processes, and protects your data.
Bytera is the data controller and is fully responsible for the privacy, security, and integrity of any data processed by Spotlight. Atlassian is not responsible for our data practices.
Spotlight is a Jira app that turns plain-language descriptions into live charts, tables, and reports. To provide this functionality, Spotlight accesses the following data through Atlassian APIs:
Important: Spotlight has read-only access to your Jira data and requests no write scopes at all. It cannot create, modify, or delete anything in your Jira instance.
Important: Spotlight runs entirely within the Atlassian platform - including its AI. Drafting uses Atlassian-hosted models via the Forge LLMs platform. No data is sent to any external servers or third-party services.
When you click "Draft with AI", Spotlight sends your description and light site context (project keys and names, status names) to an Atlassian-hosted model inside the Atlassian platform. Issue data is never sent to the model. The model returns a draft definition, which you review before saving. Bytera does not store or log the content of your prompts; only anonymous usage counters (call counts) are kept for fair use.
Charts, tables, and reports are rendered in the viewing user's browser by fetching live data from Jira with that user's own permissions. Results are computed in-memory and never persisted. Two users viewing the same spotlight each see only what their own Jira permissions allow.
Spotlight runs on Atlassian's Forge platform and uses Forge App Storage (Key-Value Store) to persist spotlight definitions and app settings - nothing else.
| Data Type | Where | Retention |
|---|---|---|
| Private spotlight definitions (settings/JQL/plan + your description) | Forge App Storage (within Atlassian cloud) | Until you delete them or uninstall |
| Shared spotlight definitions (the same, plus the author's account ID) | Forge App Storage (within Atlassian cloud) | Until removed or uninstall |
| Sharing permission settings (Jira group names) | Forge App Storage | Until app is uninstalled |
| AI usage counters (monthly call counts) | Forge App Storage | Auto-expire (~3 months) |
We do not store your Jira issue data, chart results, or any personal data beyond the Atlassian account ID. AI prompts are not logged or stored - the description you save with a spotlight is stored only as part of that spotlight's definition, under your control.
We use the data we access exclusively for:
We do not sell, rent, share, or use your data for advertising, marketing, analytics, or any purpose other than providing Spotlight functionality. Your prompts and data are not used to train AI models by Bytera.
Spotlight does not use any external services. No data leaves the Atlassian platform. There are no external API calls, no third-party AI providers, no third-party integrations, and no data transmission outside of Atlassian's cloud infrastructure.
We implement industry-standard security measures:
We do not share your data with any third parties. Since Spotlight operates entirely within the Atlassian platform with no external services, there is no data transmission outside of Atlassian's cloud environment.
Within your site, spotlights you explicitly mark as "Shared with the team" publish their definition (settings, title, your description, your name as author) to users permitted to view the team gallery - never the underlying Jira data.
The only exception: We may disclose data when required by law, legal process, or to protect our rights or the safety of users.
In accordance with applicable data protection laws (including GDPR), you have the right to:
To exercise any of these rights, please contact us at support@bytera.tech.
Spotlight requests the following Atlassian API scopes and their justification:
| Permission | Why It's Needed |
|---|---|
| read:jira-work | Read issues and run JQL searches for charts; Jira-admin check for settings |
| read:jira-user | Read group membership for group-based sharing permissions |
| read:board-scope:jira-software | Identify Scrum boards for velocity charts |
| read:sprint:jira-software | Read closed sprints for velocity charts |
| read:issue-details:jira | Access issue fields used by chart metrics and groupings |
| read:jql:jira | Validate JQL queries with Jira's own parser before saving |
| read:project:jira | List projects and roles for access reviews and AI site context |
| storage:app | Save spotlight definitions and settings in Forge storage |
We may update this Privacy Policy from time to time. We will notify users of material changes by updating the "Last updated" date and, where appropriate, through our Atlassian Marketplace listing.
For any privacy-related questions, data requests, or security concerns: