Privacy Policy

Last updated: July 7, 2026

This Privacy Policy explains how Force1 (“Force1,” “we,” “us,” or “our”) collects, uses, stores, and protects information when you use our application and services (the “Service”), including when you connect your Atlassian Jira account to Force1. By using the Service, you agree to the practices described in this policy.

1. Information We Collect

We collect the following categories of information:

  • Account information. When you create a Force1 account, we collect your name, email address, and authentication credentials needed to sign you in.
  • Project and workspace content. Information you create in Force1, such as projects, requirements, epics, stories, and related planning content.
  • Jira integration data. When you connect Jira via Atlassian OAuth 2.0 (3LO), we access and process issue data (including epics, stories, and their fields) in the Jira site and project you authorize, in order to sync content between Force1 and Jira.
  • OAuth tokens. We store the OAuth refresh and access tokens issued by Atlassian, along with your Atlassian cloud ID and site URL, so we can perform the syncs you request without asking you to re-authenticate each time.
  • Usage and technical data. Standard log and product analytics data, such as IP address, browser type, and interactions with the Service, used to operate, secure, and improve Force1.

2. Atlassian Jira Integration

The Jira integration uses Atlassian OAuth 2.0 (3LO). When you connect a project, Force1 requests the following scopes:

  • read:jira-work — to read Jira projects, epics, stories, and issue fields you choose to sync.
  • write:jira-work — to create and update Jira issues that correspond to your Force1 epics and stories.
  • offline_access — to obtain a refresh token so syncs can run without you re-authorizing each session.

We only access Jira data in the specific site and project you authorize, and only to provide the sync features you initiate. We do not use your Jira data for advertising, and we do not sell it.

3. How We Use Information

We use the information we collect to:

  • Provide, maintain, and operate the Service;
  • Synchronize planning content between Force1 and your connected Jira site;
  • Authenticate you and secure your account;
  • Diagnose problems, prevent abuse, and improve the reliability and features of the Service;
  • Communicate with you about the Service.

4. How We Store and Protect Data

  • Encryption of tokens. OAuth refresh and access tokens are encrypted at rest using AES-256-GCM. Encrypted tokens are accessible only to trusted server-side processes and are never exposed to the browser.
  • Access controls. Project data is protected by row-level security so that only authorized members of a project can access its content. Encrypted credentials are read or written only by trusted server code.
  • Encryption in transit. All data is transmitted over encrypted connections (HTTPS/TLS).

5. Data Sharing and Disclosure

We do not sell your personal information. We share information only in these limited circumstances:

  • Service providers. With infrastructure and sub-processors (for example, hosting, database, and analytics providers) that process data on our behalf under appropriate confidentiality and data-protection obligations.
  • Atlassian. With Atlassian, as necessary to perform the Jira syncs you request through the OAuth integration.
  • Legal requirements. When required to comply with applicable law, regulation, legal process, or enforceable governmental request.

6. Data Retention

We retain your information for as long as your account is active or as needed to provide the Service. When you disconnect the Jira integration, we delete the stored OAuth tokens and connection metadata for that project. When you delete your account, we delete or anonymize your personal data, except where retention is required by law.

7. Your Rights and Choices

  • Disconnect Jira. You can revoke Force1’s access at any time by disconnecting the integration in your project settings, or by revoking access from your Atlassian account settings.
  • Access, correction, and deletion. Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data. Contact us to exercise these rights.

8. International Data Transfers

Your information may be processed and stored in countries other than your own. Where required, we use appropriate safeguards for cross-border transfers of personal data.

9. Children's Privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice.

11. Contact Us

If you have questions about this Privacy Policy or how we handle your data, contact us at .