ASYNC logoASYNC by Phoebuz
  • Features
  • Intelligence
  • Pricing
  • Support
Get it Free

Privacy Policy

Effective date: March 1, 2026

1. Introduction

This Privacy Policy explains how Phoebuz ("we," "us," or "our"), operating at phoebuz.com, collects, uses, stores, and protects personal data when you use ASYNC, our engineering intelligence platform built on Atlassian Forge for Jira Cloud.

We are committed to protecting your privacy and processing your data in compliance with the General Data Protection Regulation (GDPR), the UK GDPR, and other applicable data protection legislation. By installing or using ASYNC, you acknowledge the practices described in this policy.

If you have any questions about this policy or our data practices, please contact us at info@phoebuz.com.

2. Data Controller

Phoebuz acts as a data processor on behalf of your organisation (the data controller) when processing data through ASYNC. For any data we process independently (e.g., account and billing information), Phoebuz acts as the data controller.

Contact details:

  • Company: Phoebuz
  • Website: phoebuz.com
  • Privacy inquiries: info@phoebuz.com

3. Data We Collect

ASYNC collects and processes the following categories of data from your connected services to provide engineering intelligence insights:

3.1 Jira Work Data

  • Issues (summaries, descriptions, statuses, assignees, priorities, labels)
  • Sprints (names, goals, start and end dates, velocity metrics)
  • Boards (board configurations, column mappings)

3.2 GitHub Data

  • Pull requests (titles, descriptions, authors, reviewers, status)
  • Commits (messages, authors, timestamps, file change metadata)
  • Code reviews (review comments, approval status)
  • CI/CD status (pipeline outcomes, build results)

3.3 Slack Data

  • Channel messages relevant to engineering workflows
  • Blocker and escalation signals (keyword-matched messages indicating blockers or impediments)

3.4 Zoom Data

  • Meeting metadata (titles, scheduled times, duration)
  • Recordings (where enabled by your organisation)
  • Attendee information (names, participation status)

3.5 Confluence Data

  • Pages (titles, content, authors)
  • Page updates (edit history, contributors)

3.6 Legal Basis for Processing

We process your data under the following legal bases as defined by GDPR Article 6:

Purpose Legal Basis
Providing ASYNC functionality and intelligence synthesis Performance of a contract (Art. 6(1)(b))
OAuth-based integration with third-party services Legitimate interest (Art. 6(1)(f))
AI/LLM processing for intelligence generation Legitimate interest (Art. 6(1)(f))
Compliance with legal obligations Legal obligation (Art. 6(1)(c))

4. OAuth Integrations

ASYNC connects to third-party services through secure OAuth 2.0 flows. Each integration uses organisation-scoped tokens, meaning ASYNC only accesses resources within the scope your organisation administrator has authorised.

  • GitHub OAuth — Authorises read access to repositories, pull requests, commits, reviews, and CI status within your GitHub organisation.
  • Slack OAuth — Authorises read access to specified channels for blocker and workflow signal detection within your Slack workspace.
  • Zoom OAuth — Authorises access to meeting metadata, recordings, and attendee lists within your Zoom organisation account.

OAuth tokens are encrypted and stored securely within Atlassian Forge Storage. You may revoke ASYNC's access at any time through the respective service's application management settings or through ASYNC's configuration panel in Jira.

5. Data Storage and Security

All data processed by ASYNC is stored in Atlassian Forge Storage, which provides:

  • Encryption at rest — All stored data is encrypted using industry-standard AES-256 encryption.
  • Hosted on Atlassian infrastructure — Data resides within Atlassian's cloud infrastructure and is subject to Atlassian's security policies and certifications (SOC 2 Type II, ISO 27001).
  • Tenant isolation — Each Jira Cloud site's data is logically isolated from other tenants within Forge Storage.
  • No separate databases — ASYNC does not operate or maintain its own external database servers. All persistent data lives within the Forge platform.

6. AI and LLM Processing

ASYNC may process your engineering data using large language models (LLMs) and artificial intelligence services to generate intelligence summaries, risk assessments, and actionable insights. The following AI providers may be used:

  • Atlassian Rovo — Atlassian's native AI service, integrated within the Forge platform.
  • Anthropic Claude — Accessed via api.anthropic.com.
  • OpenAI — Accessed via api.openai.com.
  • Google Generative AI — Accessed via generativelanguage.googleapis.com.

When data is sent to these providers for processing:

  • Only the minimum data necessary for generating the requested insight is transmitted.
  • Data is sent over encrypted connections (TLS 1.2 or higher).
  • We rely on each provider's data processing terms, which prohibit using customer data for model training unless separately agreed.
  • No raw data is permanently stored by these AI providers on our behalf beyond the duration required to generate a response.

7. External Connections

ASYNC communicates with the following external services from within the Atlassian Forge runtime environment:

Service Endpoint Purpose
GitHub api.github.com Pull requests, commits, reviews, CI status
Slack slack.com Channel messages, blocker signals
Zoom api.zoom.us Meeting metadata, recordings, attendees
Anthropic api.anthropic.com AI/LLM intelligence synthesis
OpenAI api.openai.com AI/LLM intelligence synthesis
Google AI generativelanguage.googleapis.com AI/LLM intelligence synthesis

All external connections are declared in the ASYNC Forge app manifest and are restricted to the endpoints listed above. No other outbound connections are made.

8. Data Retention

ASYNC retains processed engineering data according to configurable retention periods based on your user tier:

Tier Retention Period
Small Teams (0–10 users) 14 days
Growing Teams (11–250 users) 30 days
Enterprise (251+ users) 90 days

After the retention period expires, data is automatically and permanently deleted from Forge Storage. Your organisation administrator may also manually trigger data deletion at any time from within ASYNC's settings.

Upon app uninstallation, all data stored in Forge Storage for your Jira Cloud site is deleted in accordance with Atlassian's Forge app data lifecycle policies.

9. Your Rights Under GDPR

If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights under GDPR Articles 15 through 22:

  • Right of access (Art. 15) — You have the right to request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16) — You have the right to request correction of inaccurate personal data.
  • Right to erasure (Art. 17) — You have the right to request deletion of your personal data ("right to be forgotten"), subject to applicable legal obligations.
  • Right to restriction of processing (Art. 18) — You have the right to request that we restrict the processing of your personal data in certain circumstances.
  • Right to data portability (Art. 20) — You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
  • Right to object (Art. 21) — You have the right to object to the processing of your personal data based on legitimate interests.
  • Rights related to automated decision-making (Art. 22) — You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you.

To exercise any of these rights, please contact us at info@phoebuz.com. We will respond to your request within 30 days, as required by law. If your request is complex, we may extend this period by up to two additional months and will inform you of any such extension.

You also have the right to lodge a complaint with your local data protection supervisory authority if you believe we have not complied with applicable data protection laws.

10. Cookies and Tracking

ASYNC does not use cookies, local storage, or any browser-based tracking mechanisms. As a Forge app, ASYNC runs entirely within Jira Cloud's sandboxed iframe environment and does not have the ability to set cookies or access browser storage outside of that iframe.

We do not use any third-party analytics, advertising trackers, or pixel-based tracking within the ASYNC application.

11. International Data Transfers

Your data may be processed in regions outside of your country of residence, including countries outside the EEA. When data is transferred internationally:

  • Atlassian Forge infrastructure hosting adheres to Atlassian's data residency and transfer policies.
  • AI provider API calls may be routed to servers in the United States or other regions, subject to each provider's data processing agreements.
  • Where required, transfers are safeguarded by Standard Contractual Clauses (SCCs) or other appropriate mechanisms approved under GDPR Article 46.

12. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33.
  • Notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms, as required by GDPR Article 34.
  • Notify your organisation's administrator so they can take appropriate action.

13. Children's Privacy

ASYNC is a business-to-business product designed for use by organisations and their employees. We do not knowingly collect personal data from children under the age of 16. If you believe a child has provided us with personal data, please contact us at info@phoebuz.com and we will promptly delete that data.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or the functionality of ASYNC. When we make material changes:

  • We will update the "Effective date" at the top of this page.
  • We will provide notice through the ASYNC application or via email to your organisation's administrator.
  • Continued use of ASYNC after the updated policy takes effect constitutes acceptance of the revised terms.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:

  • Email: info@phoebuz.com
  • Website: phoebuz.com

We aim to resolve all privacy-related inquiries promptly and within the timeframes required by applicable data protection legislation.

ASYNC logoASYNC by Phoebuz

Engineering Intelligence Platform. Built on Atlassian Forge.

Legal

  • Privacy Policy
  • Terms of Service
  • Security
  • Data Processing

Support

  • Help Center
  • info@phoebuz.com
© 2026 Phoebuz. All rights reserved.