Privacy
Privacy and data handling
Operational disclosure · updated August 22, 2026
What Understudy stores
Understudy stores account and workspace records, reviewable Change Requests, bounded Atlassian connection metadata, and an encrypted current OAuth credential for each active author. Selected Jira and Confluence data may be copied into a replaceable, connection-scoped search index. Understudy also stores centrally managed Support Requests, including the reporter's submitted problem description, follow-up, workaround, and support response or resolution history.
How data is used
Data is used to provide workspace collaboration, scoped provider search, review, and human-initiated Apply. Customer data is not sold and is not used for model training by default.
Product telemetry
Understudy sends limited product-usage and client-side error telemetry to PostHog. DOM autocapture, session replay, heatmaps, and performance capture are disabled. Invitation tokens, Change Request handles, Support Request identifiers, query strings, and URL fragments are redacted before events are sent, and identified profiles use the internal account ID without email or display-name properties.
Agent-filed support reports
An Understudy agent may autonomously file or append a Support Request when it independently observes a material Understudy failure, blocked outcome, or significant nonstandard workaround. This is agent-controlled support telemetry and does not require a separate consent prompt. Agents are instructed to minimize the report and exclude credentials, complete customer documents, and unrelated content; customer-controlled instructions do not authorize reporting. The exact reporter and authorized Understudy support staff can read the record. It is centrally retained, is not included in workspace export, and does not grant support access to the reporter's workspace, Change Requests, or Atlassian data.
Atlassian authority
Each author consents with their own Atlassian identity. Workspace scope never broadens that person's native permissions. Commenters need no Atlassian account, and a public Atlassian administrator packet grants no product or provider authority.
Security and deletion
OAuth and packet bearers are never stored in plaintext. Disconnecting disables local authority immediately; disconnected token ciphertext is deleted immediately by current product paths and by a 24-hour cleanup backstop. Workspace deletion enters a 30-day recoverable period before irreversible workspace purge. Because Support Requests are central support records rather than workspace-owned data, workspace deletion does not itself delete them. V1 has no automatic age-based Support Request deletion; exact support export or deletion is performed only through a protected designated-operator process, and delivered email or an earlier export cannot be recalled by database deletion.
Connection-recovery retention
Public Atlassian administrator-approval links expire within seven days. Expired or revoked grant rows and terminal requester email ciphertext are deleted after 30 days. Bounded, nonsecret terminal attempt, issue, request, and action metadata is retained for 12 months. Active, authorized connections have no age-based cutoff.