Privacy policy

Effective 30 September 2026

Summary

  • The app sends nothing to us. Markdown Mode for Jira runs entirely on Atlassian's platform (Atlassian Forge, "Runs on Atlassian"). Descriptions are converted in your browser and saved through Jira. The app has no server of its own and transfers no data outside Atlassian.
  • This website sets no cookies and uses no analytics, tracking, external fonts or content delivery networks.
  • We only receive personal data if you contact us through the support form or by email, or — for paid licences — when Atlassian shares licence contacts with us.

Controller

The controller under the EU General Data Protection Regulation (GDPR) is:
Alper Balkaya, Heinrich-Bongers-Straße 33, 47137 Duisburg, Germany
Email: support@webhostdev.de

We have not appointed a data protection officer, as the law does not require one for a business of our size.

The Jira app

What happens: When you open the description of a Jira issue in the app, it is converted between Jira's document format and Markdown inside your browser. When you save, the result is written through Jira's own interfaces — exactly like an edit without the app.

What we receive: nothing. The app has no backend functions, no app storage and no connections outside Atlassian. We have no access to your Jira content or your users' data. The app remembers your preferred view (editor, split or preview) and the split position in your browser's local storage; this stays on your device.

Your Jira data: your organisation (the Atlassian customer) is the controller of the content in its Jira site; Atlassian processes it under your organisation's agreement with Atlassian (Atlassian privacy policy). As we neither receive nor store Jira content, we are not a processor for it.

Information Atlassian provides to us as the app vendor: through Atlassian's developer tools we can see which Jira sites have installed the app. We use this only to operate and support the app (Art. 6(1)(f) GDPR — our legitimate interest in maintaining the app).

Feedback button: the app's feedback dialog does not send anything. It opens our support page in a new tab with your message filled in; data is only transmitted when you press Send there (see "Support form").

Licences and billing

If you buy or evaluate a paid licence, Atlassian handles ordering, payment and licensing as the Marketplace provider under its own terms and privacy policy. Atlassian shares licence and transaction information with us, including your organisation's name and the name and email address of the technical and billing contacts. We use it to manage licences, provide support and meet our accounting and tax obligations (Art. 6(1)(b), (c) and (f) GDPR) and keep it for the duration of the licence and afterwards as long as German commercial and tax law requires.

This website

Hosting: this website is hosted by ALL-INKL.COM – Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. All data is stored in Germany.

Server logs: when you visit the website, the server records technical access data: date and time, requested page, status code, amount of data transferred, referring page, browser and operating system, and your IP address. We use this only to deliver the website and keep it secure (Art. 6(1)(f) GDPR — our legitimate interest in a working and secure website). Logs are deleted after 190 days.

No cookies, no tracking: the website sets no cookies, uses no browser storage and loads nothing from third parties.

Support form

What we collect: your message; optionally your email address, if you would like a reply; and — if you came from the app and did not remove them — technical details: app version, view mode, whether the description was read-only, and your browser's user agent.

Abuse protection: we do not store your IP address. We store a pseudonymous hash of it (combined with a secret key and the date) to limit the number of messages per hour, and delete that hash after 24 hours.

Where it goes: your message is stored in a database at our host in Germany. A copy of the message and the technical details — without your email address — is created as an issue in our private GitHub repository, which we use to track support requests (see "Recipients and transfers outside the EU").

Purpose and legal basis: to answer your request and fix problems. For requests about a licence or a purchase the legal basis is Art. 6(1)(b) GDPR, otherwise Art. 6(1)(f) GDPR (our legitimate interest in answering enquiries and improving the app). Providing data is voluntary; without an email address we cannot reply.

Recipients and transfers outside the EU

  • ALL-INKL.COM (hosting, Germany).
  • GitHub, Inc. (support tracking, USA) receives the copy of support requests described above. GitHub is certified under the EU-U.S. Data Privacy Framework, for which the European Commission has adopted an adequacy decision (Art. 45 GDPR).
  • Atlassian (Marketplace, licensing and the platform the app runs on), under its own responsibility.
  • Public authorities, only where we are legally required to disclose data.

We do not sell data and do not use it for advertising.

Retention

Support requests are deleted 12 months after the request has been answered, unless we have to keep them longer by law. IP hashes are deleted after 24 hours, server logs after 190 days. Licence data: see "Licences and billing".

Your rights

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20), and you can withdraw any consent at any time with effect for the future (Art. 7(3)).

Right to object (Art. 21 GDPR): where we process data on the basis of legitimate interests, you can object at any time on grounds relating to your particular situation. We will then stop unless we have compelling legitimate grounds or need the data for legal claims.

To exercise your rights, email support@webhostdev.de. For data in your Jira site, please contact your organisation's Jira administrator.

Supervisory authority

You can lodge a complaint with any data protection supervisory authority. The authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, www.ldi.nrw.de.

We do not use automated decision-making or profiling. The website is only served over HTTPS.

Changes

We update this policy when the app, the website or the law changes. The current version is always available on this page; see the date at the top.