Showdown — Privacy Policy
Effective date: 03/09/2026
Last updated: 03/09/2026
This privacy policy describes how Showdown - Planning Poker for Jira Sprint Estimation ("Showdown", "we", "us", "the app") handles your data. Showdown is an Atlassian Marketplace app by Taskhooker Pty Ltd (Australia), distributed via the Atlassian Forge platform. By installing Showdown, you agree to this policy.
Summary in plain English
- All data stays inside Atlassian's infrastructure. Showdown is pure Forge with zero external egress — no session data, vote, or work item detail is ever transmitted to any third party or outside Atlassian's infrastructure.
- We don't operate any servers. Showdown runs on Atlassian Forge — Atlassian hosts every function call and storage write, on your own Atlassian site.
- The app stores what an estimation session needs and nothing more: session settings, snapshots of the selected work items' keys, summaries and types, votes, the participant roster, bucket assignments and finals — all in Forge Key-Value Store, encrypted at rest by Atlassian. No emails, no page or work item content beyond that, no analytics.
- Taskhooker cannot access your data. Forge storage is tied to your Atlassian Cloud site; the vendor has no path to read it.
1. Data we access
When you create or run a session, the app reads from your Jira site — always through Atlassian's own APIs inside the Forge runtime:
- Work item data for the items you select (by quick-pick or JQL): key, summary, type, description, status, priority, labels and the current estimate, so the room can show context while voting. Reference panels read existing estimates from the estimate field.
- Basic user identity of participants: Atlassian account id and display name, so the room can show who has joined and who has voted.
Finals are written to the estimate field as the facilitator (Forge asUser()), so Jira's own permissions apply to every save — the app can never write to a work item the facilitator couldn't edit themselves.
2. Data we store
Showdown stores session data in Forge Key-Value Store, hosted and encrypted by Atlassian on your own site:
- Session settings — mode, scale, estimate field, options such as auto-reveal.
- Work item snapshots — the keys, summaries and types of the work items selected for the session.
- Votes — the scale value chosen, the voter's Atlassian account id and display name, and a timestamp.
- Participant roster — account id, display name and spectator flag for each person who joined.
- Bucket assignments and finals for bucket-sizing sessions and saved rounds.
That is the complete list. The app stores no email addresses, no passwords or tokens, and no work item content beyond the snapshots above. Up to 100 sessions are kept per site; each session covers at most 50 work items.
Forge Key-Value Store data is encrypted at rest by Atlassian and tied to your Atlassian Cloud site. Taskhooker operates as a tenant inside this storage and cannot access your site's data.
Data residency: Forge storage follows Atlassian's data residency commitments. If your Atlassian site is pinned to a specific data region, Showdown's storage stays in that region.
3. Data we share with third parties
None. The app makes no external network calls of any kind. It has no analytics provider, no error-reporting service, no AI vendor, no marketing tools, and no integrations with anything outside Atlassian Forge. The only APIs the app contacts are Atlassian's own Jira REST APIs, via Forge's internal runtime — Atlassian-operated endpoints, not external services.
3a. Account actions and data changes
The app's only writes to Jira content are the estimate values the facilitator deliberately saves, written to the chosen number field (Story Points by default) as the facilitator's own user. It changes no other fields, no accounts, no projects and no permissions.
4. Data we do NOT collect
- Email addresses
- Work item content beyond the snapshots described above (no comments, no attachments)
- Passwords, API tokens or credentials of any kind
- Behavioural or telemetry data about how you use Showdown
- IP addresses or geolocation
- Cookies (Showdown runs inside Atlassian's product frame — Atlassian's cookies apply, not ours; the app itself sets none)
5. Data retention
Session data persists until the session is deleted. Deleting a session deletes its votes, roster and bucket assignments. The app keeps at most 100 sessions per site. Finals saved to Jira live in Jira, like any other field value, under your site's own retention.
On uninstall: Atlassian removes the app's Forge storage per the Forge platform's data lifecycle policy.
6. Your rights
You have the right to:
- Access the data Showdown stores — sessions and their votes are visible in the app itself
- Delete any session (which deletes its votes, roster and buckets), or all app data by uninstalling Showdown
For requests under GDPR, CCPA or similar regulations, contact us via the Taskhooker support portal and we will process the request manually.
7. Children's privacy
Showdown is a business tool for Atlassian Cloud organisations. It is not intended for, marketed to, or used by individuals under 18. We do not knowingly collect data about minors.
8. Changes to this policy
We may update this policy when materially new features ship. The "Last updated" date at the top reflects the most recent change. Material changes will be communicated via the Marketplace listing and any in-app notice we deem appropriate.
9. Contact
For privacy questions:
- Support portal: taskhooker.atlassian.net/servicedesk/customer/portal/1
- Website: https://showdown.taskhooker.com
- Vendor: Taskhooker Pty Ltd, Melbourne, Australia — taskhooker.com