Feed The Troll - Jira Cloud App
Privacy & Security Policy
This policy describes how Feed The Troll handles data within your Jira Cloud instance. Effective date: 26 August 2026.
Introduction & Scope
This Privacy and Security Policy governs data processed by Feed The Troll (the “App”), a Jira Cloud application developed by drinkits DEV and distributed via the Atlassian Marketplace.
This policy applies to all end-users, project members, and Jira System Administrators who interact with the App within their organisation’s Atlassian Jira Cloud instance.
What the App Does
Feed The Troll gamifies your team’s existing Jira workflow. When team members log time, transition issue statuses, leave comments, complete sprints, or send peer kudos, the App awards XP to a personal “troll” character. Trolls level up, evolve through five stages, and collectively shape a shared team village. No new workflow is imposed - the App observes activity that already occurs inside Jira.
Data Storage (Forge Infrastructure)
All App data is stored exclusively in Atlassian Forge SQL - a TiDB-compatible managed database that runs entirely within Atlassian’s infrastructure. There are no external servers, no cloud buckets, and no off-platform databases of any kind.
What Is Stored and Why
| Table | Contains | Retention |
|---|---|---|
trolls |
Troll profile per user per project: level, XP, lineage, cosmetics, privacy toggles, streak, last active date | Until app uninstall |
xp_events |
Log of XP-awarding actions: event type, XP awarded, quality multiplier, source issue key, timestamp | Until app uninstall |
daily_activity |
Daily XP and action count per user per project - used for the 30-day activity heatmap | Until app uninstall |
kudos |
Sender ID, recipient ID, project ID, optional message (max 280 chars), XP awarded, source issue key | Until app uninstall |
quest_progress |
Personal quest progress: quest ID, current count, target, completion status, timestamps | Until app uninstall |
inventory |
Cosmetic items earned via quests: item type, item ID, acquisition source | Until app uninstall |
team_quests |
Team quest progress per project per sprint - no personal data | Until app uninstall |
villages |
Shared village state per project: building levels, defense score, prosperity score - no personal data | Until app uninstall |
raid_history |
Sprint raid outcomes per project: outcome, defense score, XP bonus, building affected - no personal data | Until app uninstall |
project_settings |
Feature toggle configuration per project; stores the account ID of the last administrator who changed settings | Until app uninstall |
global_settings |
Instance-wide settings (rollout strategy, Global Harmony Mode); stores admin account ID of last modifier | Until app uninstall |
loot_boxes |
Tavern Loot Drops offered to a user in a project: tier, contents, opened state, timestamps | Until app uninstall |
guilds |
Team Village name, configuration, and progression mode; stores the account ID of the admin who created or last changed it | Until deleted by an admin, or app uninstall |
guild_project_bindings |
Which Jira projects belong to which Team Village - project and village IDs only | Until deleted by an admin, or app uninstall |
troll_profiles, active_troll_profiles |
Traveling Troll profile per user per Team Village: level, XP, appearance, streak, and which profile is currently active | Until app uninstall; archiving retires a profile without deleting it |
troll_profile_sources |
Which project trolls were merged into a Traveling Troll, so the merge can be explained back to the user | Until app uninstall |
troll_profile_xp_events, troll_profile_quest_progress |
The Traveling Troll equivalents of the XP log and quest progress above | Until app uninstall |
global_license_projects |
Which projects the free plan currently covers - project IDs only | Until changed, or app uninstall |
product_metric_events |
Installation ID, activation metric name, and timestamp used only to prevent duplicate counter emission | Until app uninstall |
On Uninstall
When the App is uninstalled from a Jira instance, the Forge platform automatically deletes all associated Forge SQL data. No data remains on any infrastructure we control.
What Data We Process
The App processes the minimum data necessary to deliver the gamification experience. The following describes precisely what is read from Jira and what is derived and stored.
Data Read from Jira (Not Stored)
To detect XP-awarding events, the App receives event notifications from Jira containing:
- Jira Account ID - the Atlassian-assigned opaque identifier for the user who performed the action (e.g.
5f7a3b...). This is not a name or email address. - Project ID - to associate the event with the correct village.
- Event type and timestamp - what happened (e.g. a worklog was created) and when.
- Issue key - the Jira issue identifier (e.g.
PROJ-42) stored alongside the XP event for the activity log. - Sprint completion data - percentage of sprint goal achieved, used to calculate quality multipliers for the sprint-complete XP event.
Jira API Scopes Requested
The App declares the following Forge permission scopes in its manifest. No other scopes are requested.
The App does not request write access to Jira issues, attachments, users, or any other Jira content. All write operations are limited to the App’s own Forge SQL storage.
User-Controlled Visibility
Each user controls what teammates can see via five privacy toggles in the Gear tab of the My Troll issue panel. A save applies to every troll that person owns, not only the project in view. These settings do not affect data storage - they only govern what is displayed to other users within the App.
| Setting | Default | Governs visibility of |
|---|---|---|
| Show in Village | ON | Your troll appearing in the shared team village scene |
| Show Level | ON | Your level on the village leaderboard |
| Show Streak | OFF | Your consecutive active-day streak count |
| Show XP | OFF | Your total accumulated XP |
| Allow Toasts | ON | Whether others can send you a Toast (kudos) |
Admin-Controlled Visibility
A Jira System Administrator can also set Who sees trolls to Only your team. Then the troll is shown only to people who hold Jira’s View Development Tools permission, hiding it from anyone without that permission (such as external or portal customers) across the issue panel and the Team Village. This is a display control only - it does not change what data is stored. It is off by default.
GDPR & Data Rights
For organisations with users in the European Union or European Economic Area, this section describes the GDPR framework governing the App.
Controller and Processor Roles
Your organisation (the Jira Cloud customer) is the Data Controller: you determine the purpose and means of processing personal data by choosing to install and configure the App within your Jira instance.
drinkits DEV acts as a Data Processor operating through Atlassian’s Forge platform. We process only the data necessary to deliver the App’s stated functionality, in accordance with your instructions as expressed through the App’s configuration.
Individual Data Rights
The following rights are available to data subjects. Because the App stores only Atlassian Account IDs (not names or email addresses), identity verification is handled via Atlassian’s existing authentication.
■ Right to Access
View your troll profile, XP history, quest progress, and activity heatmap directly in the App, from the My Troll issue panel. Contact us for a complete data export.
■ Right to Erasure
Atlassian’s standard User Deletion APIs propagate to Forge SQL, removing your records when your Atlassian account is deleted. You may also contact us directly to request erasure of your troll data only.
■ Right to Portability
Contact us via the support portal to request a structured export of your personal troll data in a machine-readable format.
■ Right to Restrict
Use the five privacy toggles in the Gear tab of the My Troll issue panel to restrict the visibility of your data to teammates. For full processing restriction, contact us or ask your Jira System Administrator to remove your troll profile.
Data Retention
Data is retained for as long as the App is installed and active in your Jira instance. There is no automatic expiry of individual records during an active installation. Upon uninstall, all Forge SQL data is deleted automatically by the Atlassian platform with no further action required from you.
International Transfers
The App does not transfer data across borders independently. Any geographic placement of data is determined by Atlassian’s infrastructure and your organisation’s Jira Cloud region selection, and is governed by Atlassian’s Data Processing Addendum and Standard Contractual Clauses where applicable.
CCPA (California)
We do not sell personal information as defined under the California Consumer Privacy Act. California residents have the right to know what data is collected (this policy), to request deletion (contact us or uninstall the App), and to opt out of sale (not applicable - no sale occurs).
Contact Us
For any privacy or security question, request, or concern related to Feed The Troll, contact us through one of the following channels:
| Channel | Details |
|---|---|
| [email protected] | |
| Support Portal | drinkits.atlassian.net/servicedesk - preferred for formal data subject requests |
| Response time | Target initial response within 1 business day; formal data subject requests are completed within the period required by applicable law |
| Security disclosures | Mark your support ticket or email as Security Issue. Critical reports are triaged within 24 hours, contained as quickly as possible, and followed by written status updates. |
Policy Updates
We will update this policy when the App’s data practices change. Material changes will be announced via the Atlassian Marketplace changelog. The effective date at the top of this page will reflect the most recent revision.