This policy covers FlowDeck, the Jira Cloud app by Altimeter Apps, and this website (altimeterapps.com). The short version: FlowDeck runs and stores its data entirely inside Atlassian's cloud, sends nothing anywhere else, and this website sets no cookies and runs no analytics. Effective 2026-08-16.
FlowDeck renders dashboard gadgets from the status history of work items in the Jira projects your teams configure. To do that, it reads from your Jira site through Atlassian's API:
Its access is exactly two Atlassian-granted permissions, consented to by your Jira admin at installation: read:jira-work (read work items) and storage:app (the app's own storage). It requests nothing else — no write access to your Jira data, no user or account permissions.
For each configured project, FlowDeck stores in Atlassian's Forge app storage (inside your Atlassian cloud infrastructure, in your product's region):
It does not store work item content — no summaries, descriptions, comments, attachments or custom fields — and no personal data: no names, account ids or email addresses of the people who made the changes.
For Atlassian data residency purposes, all data FlowDeck stores is in-scope: it lives in Forge hosted storage and in Jira dashboard properties (gadget settings), and follows your Jira product's region — hosting, pinning and migration between supported locations are handled by the Atlassian platform. This covers stored data only: the Forge platform log lines the app writes (project keys, numeric work item ids, counts, error text) are out of scope for data residency and are described under "What the developer can access" below.
FlowDeck is built on Atlassian Forge: all computation and all storage run on Atlassian's own infrastructure. The app declares no external connections and makes no network calls outside Atlassian — no data leaves the Atlassian platform. Altimeter Apps operates no servers and never receives a copy of your Jira data. Data is never sold, shared or disclosed to anyone.
One small edge, disclosed for completeness: Jira requires each gadget to declare a thumbnail image for its gadget picker, and FlowDeck's two are served from this website. Opening the picker therefore fetches those two images the way visiting this site would — Cloudflare sees the same technical connection data (such as your IP address and browser type), and none of your Jira data is in the request.
One stance worth stating plainly: FlowDeck computes with the app's own access over all work items in a configured project, including items an individual dashboard viewer may not have permission to open. What viewers see is aggregates only — durations, counts and percentiles; no work item keys, ids or per-item values are displayed or sent to the browser. Before a gadget shows a project's numbers it checks, as the viewing user, that their Jira account can browse that project — one read of that user's own permission answer for the one project, made on every view and never stored — and shows nothing if the answer is no. Within a project you can browse, the aggregates still include work items an issue security level hides from you. Details: how FlowDeck computes its numbers.
The only thing Altimeter Apps can see about the app's operation is Atlassian's invocation logs and operational metrics for the app, which Atlassian retains for 30 days. Log lines record project keys, gadget state markers, counts and timings, error messages, and occasionally the numeric id of a work item whose history could not be read — never work item content and never user information.
altimeterapps.com is a static site: it sets no cookies, runs no analytics or trackers, and has no forms or accounts. It is served by Cloudflare; like any host, Cloudflare processes technical connection data (such as IP addresses) to deliver the site.
If you write to support@altimeterapps.com, your message and address are used to answer you, and for nothing else — no marketing, no lists, no sharing.
Altimeter Apps is a trading name used by Leonid Ristanovski, an individual based in North Macedonia. Contact: support@altimeterapps.com
If this policy changes materially, the change and its date will be noted on this page.
2026-08-17: added the section above identifying who operates Altimeter Apps. No change to what the app reads, stores, or sends.
2026-08-24: added two clarifications — that Jira's gadget picker fetches FlowDeck's thumbnail images from this website, and that all stored data is in-scope for Atlassian data residency. No change to what the app reads, stores, or sends.
2026-09-14: in "What the app stores", "no user data" now reads "no personal data" — the same exclusions (no names, account ids or email addresses), in clearer words. No change to what the app reads, stores, or sends.
2026-09-16: in "What the app stores", clarified that the data-residency statement covers stored data only and that the Forge platform log lines the app writes (project keys, numeric work item ids, counts, error text) are out of scope for Atlassian data residency. No change to what the app reads, stores, or sends.
2026-09-20: added the viewer permission check above. No change to what the app stores or sends; one new read, as the viewing user, of that user's own permission for the configured project.