Privacy
Last updated 30 July 2026 · Applies to Group Blast Radius and any other Lintelworks app for Atlassian.
The short version: our apps run inside Atlassian's own infrastructure, read only what they need to answer your question, store nothing, and send nothing to us.
Where the app runs
Group Blast Radius is built on Atlassian Forge and runs entirely within Atlassian's cloud. We operate no servers that process your data. The app declares no external network access, so it is not technically capable of transmitting your data to us or to any third party — Forge blocks any request to a host that isn't declared, and we declare none.
What the app reads
Only what is needed to compute where a group is referenced, and only when you ask it to by selecting a group and running a report:
| Groups and users | Group names and identifiers, and the group members recorded as actors in configuration |
|---|---|
| Projects | Project names, keys, and the permission scheme each project uses |
| Permission schemes | Which schemes grant permissions to the group, and which permissions |
| Project roles | Whether the group is an actor in a project role |
| Notification schemes | Whether the group is notified, and on which events |
| Issue security schemes | Whether the group is a member of a security level |
| Filters and dashboards | Names of filters and dashboards shared with the group |
The app does not read issue content, comments, attachments, or any other work data.
A note on the permission names you'll see
At install time Atlassian will show a scope called manage:jira-configuration.
The name is Atlassian's, not ours, and it is the scope that covers reading
permission, notification and issue-security schemes. The app only ever issues read
requests. It contains no code that writes, creates, updates or deletes anything in
your site.
We would rather ask for something narrower, and we tested it. Atlassian's granular
read-only scopes work for permission schemes and project roles, but
read:notification-scheme:jira is rejected on the notification-scheme endpoint
we need, which would mean silently dropping the entire notification-schemes check. We are
not willing to quietly narrow what the app looks at in order to show you a friendlier
permission name — a report that misses something is worse than a scope that sounds broad.
So we ask for the broader scope, use it only to read, and tell you exactly why. If
Atlassian fixes that granular scope, we will switch and say so here.
What we store
Nothing. The app holds no database and uses no persistent storage. Each report is computed when you request it, rendered to your browser, and gone when you navigate away. There is nothing for us to retain, sell, breach, or hand over.
Analytics and tracking
The app contains no analytics, no tracking pixels, and sets no cookies. This website sets no cookies and runs no analytics either.
Atlassian independently reports aggregate installation counts to us as the app's publisher — how many sites have the app installed. That comes from Atlassian, not from the app, and contains no personal data.
Support correspondence
If you email us, we hold that email in order to reply to it. If you send us a screenshot or a log, we see whatever is in it — so send only what's needed. Ask us to delete the correspondence at any time and we will.
Sub-processors
App hosting: Atlassian (Forge). Email: Cloudflare (routing) and Google (mailbox). Website hosting: Vercel. No customer Jira data reaches any of these except Atlassian, where it already lives.
Your rights
Because we hold no customer data, there is generally nothing to access, export or erase. Where we do hold something — support correspondence — you can ask for a copy or its deletion by writing to hello@lintelworks.dev.
Changes
If this policy changes materially, the date at the top changes and the current version always lives at this address.
Who we are
Lintelworks is operated by a US limited liability company. For any privacy question, write to hello@lintelworks.dev.