Afterbrief postmortems in Jira

Privacy policy

Last updated 2026-10-03. This policy explains how personal data is handled by Afterbrief (the app, for Jira and Confluence), the optional Afterbrief Relay (which brings Slack messages into the app) and this website, as required by the EU General Data Protection Regulation (GDPR) and Spain's Organic Law 3/2018 (LOPDGDD).

In short

Who we are

Controller Lekawski, S.L.U.
Tax ID (NIF) B27640481
Address Paseo de Reding 43, 1º Izq, 29016 Málaga, Spain
Contact for privacy support@afterbrief.pro

We have not appointed a data protection officer; write to the address above about anything in this policy.

Two roles

The app

Afterbrief is built on Atlassian Forge and runs only on Atlassian's compute and storage; it makes no calls to any service outside Atlassian. Incident details, timeline entries, postmortem text, links to corrective actions and settings are held in your Atlassian site's storage for the app or on your Jira work items, under Atlassian's data residency for your site. Uninstalling removes the app's storage after Atlassian's retention period; the work items, comments and Confluence pages it created are yours and stay.

Jira comment text is never copied into the timeline: the timeline keeps a reference and reads the comment with each viewer's own permissions, so a comment restricted or deleted later disappears from it too.

Draft with AI

On paid plans and during a trial, Draft with AI sends to an AI model through Forge LLMs, operated by Atlassian: the work item's summary and description, the incident's times and severity, its timeline including people's Jira display names, its corrective actions, and the postmortem text already written. Only content the person pressing the button can see is sent; email addresses and account ids are not. The draft is shown to that person and stored only if they save it. We receive counts (how many drafts, how many tokens), never content.

What we process, why, on what basis, for how long

Data Purpose Legal basis Kept
Licence and installation data Atlassian provides for your site (site address, plan, licence state, contact on the licence) Providing, licensing and billing the app Contract (Art. 6(1)(b) GDPR) For the life of the licence, and as long as tax and accounting law requires after it
App logs and metrics from Atlassian (ids, counts and errors, never incident content) Operating, securing and fixing the app Legitimate interest in a working, secure service (Art. 6(1)(f)) As Atlassian retains them for developers, at most a few weeks
Relay data (below) Delivering Slack messages to your site On your behalf, as processor (Art. 28) Until you disconnect or ask us to delete it; backups 14 days
Emails you send us Answering you Contract or legitimate interest (Art. 6(1)(b), (f)) As long as needed to resolve the matter, then up to 3 years for our records
Website visit statistics (Plausible, see below): no cookies, IP address not stored Understanding and improving this website Legitimate interest (Art. 6(1)(f)) Daily visitor hash 24 hours; aggregate statistics afterwards

We do not sell personal data, use it for advertising, train AI models on it, or make automated decisions about you.

The relay (only if you connect Slack)

The relay runs at relay.afterbrief.pro, hosted by us with Hetzner Online GmbH in the European Union. It stores:

Messages in linked channels or threads are held in memory for a few seconds to be batched, sent to your site and discarded; if your site cannot be reached they are discarded after ten minutes. If your workspace grants the app access to email addresses, the relay sends an author's email along with their messages so the app can match them to their Jira account. The relay keeps it in memory for up to six hours, so it does not ask Slack again for every message, and never writes it to storage; the app keeps only which Jira account a Slack user is, never the email. The relay's logs carry ids and counts, not message text. You can disconnect at any time by removing the Afterbrief app from Slack; ask us and we delete your relay records.

This website

afterbrief.pro sets no cookies, stores nothing on your device, loads nothing from other websites and keeps no access logs.

Visit statistics (Plausible)

To learn which pages are read and how people find them, we count visits with Plausible Analytics, an open-source tool we run ourselves on our server at Hetzner in the European Union. No third party receives this data.

Who receives data

Recipient Role Where
Atlassian Runs the app, its storage and Forge LLMs; provides us licence and operational data Under Atlassian's data residency and transfer safeguards
Hetzner Online GmbH Hosts the relay, this website and our Plausible statistics European Union
Our email provider Delivers email to our addresses Email sent to us may pass through the provider's servers

Where a recipient processes data outside the European Economic Area, it does so under the safeguards the GDPR requires, such as the European Commission's standard contractual clauses or an adequacy decision.

Your rights

You can ask us for access to your personal data, its correction or deletion, restriction of or objection to its processing, and its portability, and withdraw any consent you gave. Write to support@afterbrief.pro; we answer within one month. For data held in your Atlassian site, your site admin and Atlassian are the right place to start.

You also have the right to complain to the Spanish Data Protection Agency (Agencia Española de Protección de Datos, aepd.es) or to the authority where you live or work.

Changes

We will update this page when any of this changes and change the date at the top.