Privacy Policy for OutSync

Learn exactly what data OutSync stores, how its optional Google Calendar sync works, and what leaves Atlassian infrastructure (and what never does).

Data Storage and Processing

OutSync is built on the Atlassian Forge platform and is delivered as two separate Forge apps (one for Confluence and one for Jira), each with its own isolated storage.

Leave requests, employee records, approver configuration, accrual policy settings, holiday region settings, and audit log entries are all stored in Atlassian’s own Forge-hosted storage for your site — never on a database or server we operate.

A leave request record contains: the employee’s Atlassian account ID, the team it belongs to, the leave type, the start/end dates and time zone, an optional free-text reason, its approval status, and who approved, rejected, cancelled, or revoked it and when. Employees who don’t have their own Atlassian account (e.g. contractors an admin tracks leave for manually) are stored the same way, keyed by an identifier the admin chooses rather than an Atlassian account ID.

Google Calendar Sync (Optional)

OutSync can optionally sync approved leave to Google Calendar. This feature is off unless a site admin explicitly connects a Google account, and every other part of OutSync works identically whether it’s connected or not — a sync failure or a disconnected account never blocks a leave request from being submitted or approved.

What’s connected. One Google account per organization (an “org-level” connection, not each employee’s own), separately for the Jira app and the Confluence app if you use both. That account’s OAuth access token and refresh token are stored in the same Forge-hosted storage described above.

What OutSync creates. For each team, OutSync creates one shared Google Calendar under the connected account the first time a leave request for that team is approved. When a request is approved, OutSync creates a calendar event spanning the leave dates; if the approval is later revoked, the event is removed. Each event’s content is limited to the leave type and whether it’s a half day, identified by the employee’s display name (or their raw account ID if a display name can’t be resolved) — the free-text reason an employee enters is never included, since the calendar is visible to every team member who subscribes to it, not just the approver.

What OutSync does not access. The requested Google scope is limited to Calendar read/write on the one connected account — OutSync never reads any employee’s own personal Google Calendar, Contacts, Drive, Gmail, or any other Google data. It also never reads existing events on the connected account’s calendar beyond the ones it created itself.

The relay. Because Forge webtrigger URLs aren’t stable enough to register directly as a Google OAuth redirect target, the authorization flow passes through one small, stable relay endpoint we operate (a Cloudflare Worker). The relay’s only job is to verify a short-lived, single-use, cryptographically signed authorization token and forward Google’s redirect on to the right Forge webtrigger — it never receives, stores, or has access to your Google credentials, calendar data, or any Atlassian data. Its source code, like the rest of OutSync, doesn’t log request bodies, tokens, or any personal data.

Google API Services User Data Policy. OutSync’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. OutSync requests only the Google Calendar scope described above, uses the data solely to create and remove the leave-sync events described above, never uses it for advertising, never sells it, and never allows humans to read it except as needed for security, legal compliance, or with your explicit consent.

Data Access and Sharing

We do not share your data with third parties. The only external system OutSync ever communicates with is Google’s own Calendar API, and only for the specific, optional sync described above — nothing is sent to any other external service.

Accessing, Correcting, or Deleting Your Data

Employees can review, edit, and cancel their own pending leave requests directly from OutSync’s general access screen at any time — no request to an admin is needed for that.

For anything beyond your own pending requests (past decided requests, a manual-member record an admin created on your behalf, or full removal of your data from a team), contact your organization’s OutSync admin — they have full visibility into their team’s records and can correct or remove them directly from the admin settings screen. If your organization’s admin can’t resolve a request, or you have a question about data we haven’t addressed here, contact us via Contact.

OutSync doesn’t hold a separate copy of your data outside your organization’s own Forge-hosted storage described above, so an admin action (or, for full erasure, uninstalling the app) is what actually removes the underlying record — see “Persistent App Data” below for how long it’s retained after that.

Data Security Measures

  • Runs on Atlassian Forge; the Jira and Confluence apps each use their own isolated, Atlassian-hosted storage
  • Google OAuth tokens are stored in the same Atlassian-hosted storage as everything else — never in a plaintext config file or environment variable
  • Google Calendar sync is opt-in per organization and can be disconnected at any time from OutSync’s own settings screen, which immediately stops any further calendar access
  • The one external hop in the connection flow (the OAuth relay) verifies every request cryptographically and never persists any data it forwards

Persistent App Data

Forge-hosted storage retains leave requests, employee records, team configuration, audit log entries, and (if connected) Google OAuth tokens for as long as the app remains installed. Atlassian encrypts this storage on disk, scopes it per installation, and retains it for 28 days after uninstall under Atlassian’s documented storage lifecycle, after which it is deleted.

Updates to this Policy

This policy may be updated from time to time. Any changes will be published on this page.

By using OutSync, you agree to our End User License Agreement.

For more information about Atlassian’s privacy practices, see the Atlassian Privacy Policy. For Google’s, see the Google Privacy Policy.