FieldLock for Jira · last updated 22 August 2026
FieldLock is an Atlassian Forge app. It runs entirely inside Atlassian's cloud infrastructure and has no external backend, no analytics and no third-party services. No data from your Jira instance is transmitted to us or to anyone else, and we cannot read it.
All app data is written to Atlassian-hosted storage (Forge key–value storage and Forge SQL) that belongs to your installation of the app, in the Atlassian region of your instance.
| Data | Why |
|---|---|
| Approved value of the protected field, per issue | the app is the source of truth for the field; Jira holds a copy for display and JQL |
| Project settings (protection on/off, mode, which field, who approves) | configuration set by your project administrator |
| Log entries: issue and project identifiers, field identifier, event type, value before and after, the Atlassian account ID of the person who acted, timestamp and the reason they typed | the audit trail that is the point of the app; append-only, chained with SHA-256 |
| A random signing key created once per installation | seals exported proof documents; never leaves app storage, is never shown or logged |
Personal data is limited to Atlassian account identifiers and whatever a user chooses to type into the reason field. Display names are read from Jira only at the moment a proof document is generated, and are not stored.
Nothing. We have no server, no database and no telemetry in this product. We cannot see your issues, your field values or your log. If you contact support we only see what you write to us in that email.
Atlassian, as the cloud provider, processes the data according to its own terms and privacy policy. Forge application logs (the technical log our code writes, visible to us through Atlassian's developer tooling for a short retention period) contain issue identifiers, event types and values of the protected field — they never contain reason texts, display names or the signing key.
App data lives as long as the app is installed. Uninstalling the app removes the app's storage, including the log — export a proof document first if you need to keep the audit trail. You can export at any time from the FieldLock panel; an active licence is not required for that.
Your organisation is the controller of the data in your Jira instance. FieldLock processes that data only inside your instance, on your instruction (your project settings and your users' actions), without transferring it anywhere. We do not act as an independent controller of your issue data. Data subject requests concerning content in your Jira instance are handled by you as the controller; we will assist where the app is involved.
If this policy changes, the date at the top changes and the previous statement is superseded. Material changes will be noted in the app's Marketplace listing.
Contact: support@aphexcoding.tech. FieldLock is published by Yzukar, an Atlassian Marketplace Partner registered in Poland; full legal and postal details are in our Marketplace partner profile and available on request.