Dossier privacy policy
In effect since August 26, 2026
This policy covers Dossier, the app that turns the work tracked in your Jira into a controlled document. It does not cover the rest of this site, which has its own privacy policy.
It is written to be understood, not to cover us.
Data controller: Vortex Labs, Uruguay. For anything on this page: info@vortexlabsia.com.
The short version
Dossier runs entirely inside Atlassian. It has no server of ours, no database of ours, and no address of ours to send anything to. Nothing you put into it reaches us, and nothing reaches anyone else either. We cannot read your issues, your documents or your template, because there is nowhere for them to arrive.
That is not a promise about our intentions. It is a property of how the app is built, and Atlassian verifies it on every release: Dossier carries the Runs on Atlassian badge, which is granted only to apps that keep all data inside Atlassian’s own infrastructure.
What Dossier reads
When you generate a document, and only then:
- The issues you chose, through the scope you picked on screen: their key, summary, status, assignee, priority, type, dates, description and any custom fields you added as columns.
- The name of whoever issued a version, asked of Jira at the moment of printing so the document can say who issued it. This is the display name your Atlassian account already shows to everyone in your Jira, and it is never kept.
It reads nothing else. It does not look at issues outside the scope you picked, and it never reads another Jira site.
What Dossier stores, and where
All of it lives in Atlassian’s storage for this app, inside your own Atlassian site. None of it is copied anywhere else.
- Your document setup: the title, the organisation name, the wording you chose for each label, and which columns the table carries.
- Your logo, if you upload one.
- Your Word template, if you upload one.
- The revision register: for each version issued, its number, its date, a reference to the Atlassian account that issued it, how many records it covered, and the content fingerprint.
That account reference is the one piece of personal data Dossier keeps, and it keeps it on purpose: a controlled document that cannot say who issued each version is not a controlled document. The name itself is never stored. It is asked of Jira each time the document is printed, which is what Atlassian recommends and what makes the next paragraph possible: the day someone exercises their right to be forgotten, Jira stops handing out their name, and a copy of ours would still be repeating it.
What Dossier writes
One thing: a new Jira issue in your project, with the finished document attached to it. Who can open that issue and its attachment is decided by your own Jira permissions, exactly like any other issue. We have no say in it and no access to it.
What Dossier never does
- It never sends anything to a server of ours, or to anyone else’s.
- It never uses an external service to build the document, convert it, or store it.
- It does not use artificial intelligence. Putting a cover page and a signature line on a report is plumbing, not intelligence.
- It sets no cookies and runs no analytics. It is a panel inside Jira, not a website.
- It does not sell, share or hand your data to anyone, because it never has it.
Deleting your data
- The template and the logo are removed from the app’s screen whenever you want.
- Everything else goes when the app goes: uninstalling Dossier from your Jira site deletes the storage that belongs to it, including the revision register.
- When an Atlassian account is closed or deleted, the reference to it disappears on its own. Once a week Dossier reports to Atlassian every account it still refers to, and erases the reference to the ones Atlassian reports as closed. The version, its date, how many records it covered and the fingerprint stay: what the document says about itself does not depend on who is still an employee.
- If you want that reference gone sooner, write to info@vortexlabsia.com.
Documents already attached to your Jira issues are yours and stay where you put them. Deleting those is done in Jira, the same as any other attachment.
Billing
Atlassian bills you and pays us. Your payment details are handled by Atlassian and we never see them. What reaches us is a transfer and a statement of how many licences were sold.
Changes to this policy
If what the app does with data changes, this page changes first, and the date at the top says since when. We do not make quiet changes.