Privacy Policy

Last updated: May 23, 2026

At Imani AI (“we”, “our”, or “the App”) provides AI-powered Jira story generation and agile workflow assistance for teams.

1. Information We Access

When authorized by a Jira administrator or user, the App may access:

  • Project description necessary to generate agile stories.
  • Jira user site ID required for authentication and usage tracking.

The App only accesses data necessary to perform the requested functionality.
The content is NOT used to improve Google and Imani AI products.

2. Data Minimization

We follow strict data minimization principles. We do NOT store Jira issue content.
Jira issue data submitted for AI generation is:

  • Processed temporarily in-memory
  • Sent securely to the AI generation provider
  • Used solely to generate the requested output
  • Discarded immediately after processing

We do not permanently store:

  • Jira issue descriptions
  • Generated stories
  • Acceptance criteria
  • Project documentation submitted for generation

3. Usage Tracking & Rate Limiting

To enforce application usage limits and maintain service reliability, we store limited operational metadata including:

  • Atlassian account site ID
  • Request timestamps
  • Request count totals

This information is used solely for:

  • Enforcing monthly usage quotas
  • Preventing abuse
  • Monitoring service reliability
  • Troubleshooting operational issues

4. AI Processing & Sub-processors

Current Sub-processors:

Google Gemini API: Used for AI-powered story and backlog generation. Processing occurs through Google’s Gemini models hosted on Google infrastructure.
Your data is governed by applicable Google privacy and security commitments, including:

  • Enterprise-grade security controls
  • Encryption in transit
  • Limited retention policies as provided by Google
  • Google Cloud infrastructure protections
  • The application currently utilizes Gemini Flash-class models for low-latency generation workloads.

Google Cloud Run: Used to host the backend API infrastructure.

5. Data Retention

We retain only minimal operational metadata necessary for:

  • Usage quota enforcement
  • Billing and operational monitoring
  • Security auditing

Operational metadata is retained only as long as reasonably necessary for these purposes. Temporary AI processing data is not retained after request completion.

6. Security Measures

We implement reasonable technical and organizational safeguards including:

  • HTTPS/TLS encryption
  • Secure cloud-hosted infrastructure from Google
  • Access-controlled production systems
  • Principle of least privilege access
  • Atlassian Forge security model integration where applicable

7. Atlassian Permissions

The App only requests Jira permissions necessary for its functionality. Users should review requested permissions during installation within Jira.

8. International Data Transfers

Depending on infrastructure availability and AI processing regions, data may be processed in data centers outside your country of residence.
By using the App, you acknowledge such processing may occur.

9. Children’s Privacy

The App is intended for business and professional use only and is not directed toward children under 13.

10. Changes to This Policy

We may update this Privacy Policy periodically. Updated versions will be posted with a revised effective date.

11. Cookies and Tracking

We use cookies and similar technologies to:

  • Remember your preferences and settings
  • Understand how you use our services
  • Improve your experience

You can control cookies through your browser settings. Note that disabling cookies may affect the functionality of our services.