Effective 15 September 2026. This policy covers every app published on the Atlassian Marketplace by Two Little Moons Consulting (ABN 49 732 400 198, Australia), referred to as "we" or "us": Honest Timesheets for Jira, Pivot Reports for Jira, Tickbox Checklists for Jira, Mailpost for Jira, Agile Gadgets for Jira, Git Links for Jira, Stencil Issue Templates for Jira, Status Clock: Time in Status & SLA for Jira, Countersign: Approvals & Sign-off for Jira, Ditto: Bulk & Deep Clone for Jira, and Slide Rule: Calculated Fields for Jira.
Six apps also publish a policy of their own, itemising every category of data that app stores rather than describing the set: Honest Timesheets, Stencil Issue Templates, Status Clock, Countersign, Ditto and Slide Rule. Where an app has one, it is the more specific statement and this page is the umbrella; the two do not disagree, and neither grants us anything the other does not.
All apps run on Atlassian's Forge platform, inside Atlassian's infrastructure. We operate no servers of our own and never receive a copy of your Jira data. Every call an app makes to Jira is made as the person using it, so Jira's own permissions always apply.
Each app reads only what its feature needs: issues, worklogs, sprints, versions, comments, the fields you choose, and the account ID, display name and timezone of the Jira users involved. Apps that write to Jira (worklogs, comments, transitions, checklists) do so only when you ask them to, as you.
Where an app keeps state, it keeps it in Forge's hosted storage for your site, which Atlassian encrypts and isolates per site. Examples: saved reports and gadget settings (Pivot Reports, Agile Gadgets), checklist templates (Checklists), email templates and a per-issue send log (Mailpost), timers, approval state and history, project settings such as working patterns, holidays, approver lists, worklog attribute definitions, rounding, reminder settings and charge-out rates, personal working patterns, workplans, in-app notices, saved report definitions and a mirror of worklog attributes keyed by worklog id (Honest Timesheets), a cache of commit, branch and pull-request metadata plus repository connection settings (Git Links), clone job records and the field values planned for each copy (Ditto), and calculated-field definitions plus, per work item, the most recent result and the field values the formula read to produce it (Slide Rule). Checklist and timesheet summaries are also stored on the issue as Jira issue properties so they can be searched with JQL. Removing an app from your site deletes its Forge storage; issue properties can be removed by a Jira administrator.
Nine of the eleven apps make no network call outside Atlassian at all — Honest Timesheets, Pivot Reports, Tickbox Checklists, Agile Gadgets, Stencil Issue Templates, Status Clock, Countersign, Ditto and Slide Rule. Atlassian's own forge eligibility check reports each of those production builds as eligible for the "Runs on Atlassian" programme, and reports the other two as not eligible, which is what the rest of this section is about. Mailpost for Jira can, only when a site administrator switches on a bring-your-own email provider (off by default), send outbound email through Postmark (api.postmarkapp.com) using a key the administrator supplies, and accept inbound mail from that provider; with it off the app makes no outbound request. Git Links for Jira connects, only when a site administrator configures it, to the Git hosting provider you choose (GitHub, GitHub Enterprise, GitLab, Bitbucket Cloud or Azure DevOps) and sends that provider the issue keys, branch names and pull-request details needed to index and create branches and pull requests. Provider access tokens are stored with Forge's secret storage and are never shown, logged or sent anywhere else.
Forge keeps invocation logs for troubleshooting. They contain timestamps, error messages and HTTP status codes, not issue content, names or email addresses. Site administrators control whether log access is shared with us.
Because we hold no copy of your data, there is nothing for us to export or delete beyond what removing the app already deletes. For any question or request, email support@twolittlemoons.com.
We will update this page and the effective date if an app's data handling changes. Any new stored data or external service will be announced in that app's release notes before it ships.