Vantelia

Retrospectives for Jira
Privacy & Security

What the app stores, what it deletes and when, who can see what, and why each Atlassian permission is requested.

The app runs entirely on Atlassian's infrastructure. It sends no retro content, personal data or votes to us or to any third party. We operate no servers and keep no copy of your data; we only see what you choose to send us in a support request.

Provider: Vantelia

Contact: soporte@vantelia.es

Last updated: 30 September 2026

What the app stores

In Atlassian's Forge hosted storage, inside your own Atlassian cloud instance:

What is deleted, and when

When a retro ends, the app deletes the per-card edit codes, every per-voter vote record, the retro's secret and its presence records, and checks that the codes, vote records and secret are gone before marking the retro as ended. From then on, the app holds nothing that attributes an anonymous card to the person who wrote it.

Who can see what

WhoWhat the app guarantees
Other participants and moderatorsIn an anonymous retro they never see who wrote someone else's card; during the Write step each person sees only their own. While people write and vote, the app shows no counts and sends no update for each card or vote; cards are revealed in random order and carry no time. They do see who is present. One residual signal: a retro holds at most 300 cards, so someone who fills it to the limit can notice when others add one. In a named retro, authors and card counts are shown by design.
People outside the retroA retro opens only for its moderators and the people it was shared with (or the whole project, if its moderators chose that), and only for people Jira lets see the project. A linked Jira issue shows only to people Jira lets see it.
Site administratorsThe app does not disclose who wrote another person's anonymous card through any screen or API. During the Write step, each person can see and edit their own cards. Forge storage is readable only by the app's own code.
Vantelia, the app's developerWe have no servers and no copy of your data, but the app's code runs in your instance. While an anonymous retro is open, that code can match a card to its writer — that is how it shows you, and only you, your own cards while you write. It never shows that link to anyone else and never logs it, and the data that makes it possible is deleted when the retro ends.
Atlassian's platformWe make no claim about backups or copies kept by Atlassian's infrastructure.
Anyone, by inferenceIn a small team, writing style or content can give an author away. No app can prevent that.

What the app does not do

Why each permission is requested

PermissionWhy it is needed
storage:appStores retros, cards, per-card codes and per-voter records (both deleted when a retro ends), actions and short-lived presence, in Forge hosted storage inside your instance.
read:jira-workReads the summary and status of issues linked to actions, and finds an action's issue by its entity property, so a lost answer from Jira is reconciled instead of retried automatically. If a person confirms an issue was not created and it was, a duplicate can still result.
write:jira-workCreates an action's issue, from the person's browser and as that person, so Jira applies their own permissions.
read:jira-userChecks that each person can see the project and each linked issue before showing them, and reads display names for a named retro's export.
read:project:jiraRequired with the board permission to list a project's boards.
read:board-scope:jira-softwareLists the project's boards to find its sprints.
read:sprint:jira-softwareLists sprints, so a retro can be tagged with the sprint it looks back on.

Where the data lives, and for how long

In Atlassian's Forge hosted storage, within the Atlassian cloud environment of your own instance and subject to its data residency. Ended retros stay until the app is uninstalled. On uninstall, Atlassian soft deletes the app's data and keeps it for 28 days before permanent deletion; within 21 days a reinstallation can be relinked to it, only at your request.

Legal basis and your rights

Where the GDPR applies, your Atlassian instance administrator is the data controller for the data described above. It is created and kept inside your own instance and we do not receive a copy of it; our position is that we act as neither a data controller nor a data processor in respect of it.

What the app offers today: during the Write step, before cards are revealed, each person can edit or delete their own cards; any participant can export a retro's results from the Discuss step on; ending a retro deletes its authorship data as described above. Ended retros cannot yet be edited or deleted one by one from the app; uninstalling the app removes all of its data, subject to Atlassian's retention. For anything else, contact soporte@vantelia.es.

Support data

If you contact support, we receive whatever you choose to include. Please keep card text out of support requests.

Changes

Material changes will be reflected here and the "Last updated" date revised.