Ledgerstone privacy policy
Who we are
Ledgerstone is a read-only Jira permission and configuration audit app for Jira Cloud, published by VestaNabu LLC, 202 N Cedar Ave Ste 1, Owatonna, MN 55060, United States. Contact: support@vestanabu.com.
What the app does
Ledgerstone reads Jira configuration and shows Jira administrators where access is broader than intended: permission scheme grants to anonymous or all logged-in users, filters and dashboards shared publicly, project role assignments, group membership of administrative groups, and account counts. It never changes anything in Jira.
Data the app reads
Through Jira's REST API, using only read scopes: permission schemes, projects, project roles and their members, groups and their members, user profiles (display name, account type, active flag), saved filters and dashboards with their share settings, and the calling user's own permissions. Reads on the admin page happen as the viewing administrator; the weekly job reads as the app.
Data the app stores
Ledgerstone uses Atlassian Forge hosted storage, which lives inside Atlassian's infrastructure in the region of your Jira site. It stores:
- A weekly snapshot: counts per audit area, plus up to 25 flagged items per area (permission scheme names and flagged grants, filter and dashboard names with their share settings, project role assignments, administrative group names with member counts and counts of inactive members). Permission grants and role assignments to an individual person are stored as "A named user" or "A named app", without the name; filter and dashboard shares with an individual person are only counted.
- A history of the last 12 weekly runs, counts only.
The app stores no personal data: no names, account IDs or email addresses. People's names are shown only live on the admin page, read fresh from Jira as the viewing administrator, and are not kept. Data is deleted when the app is uninstalled, per Forge platform behaviour.
Data the app sends elsewhere
None. Ledgerstone makes no network calls outside Atlassian ("Runs on Atlassian"). There is no analytics, no telemetry, and no third-party service.
Logging
Operational logs (timings, HTTP statuses, error messages) are written to Forge's logging, visible only to the app developer, retained per Atlassian's Forge log retention. Logs do not contain user email addresses or account identifiers beyond what an error body from Jira may include.
Your rights and contact
Questions, access or deletion requests: support@vestanabu.com. Uninstalling the app removes its stored data.