Privacy Policy
Korbition ("we", "our", or "us") builds automation and integration software. This Privacy Policy explains how we process and protect information across all Korbition products and services. It is organised in two parts:
- Part A — Company-wide practices, which apply to every Korbition product; and
- Part B — Product disclosures, with one section per product describing exactly how that product handles data. Each product section can be linked to directly (for example,
korbition.com/privacy.html#rulekestra).
New products are added to Part B as they launch; the company-wide sections below always apply to them as well. This policy is part of Korbition's legal framework together with the Terms of Service and the EULA; Korbition's legal identity and provider details are published in the Impressum.
Part B: Rulekestra
1. About Korbition & this policy
Korbition operates a portfolio of software products, delivered as cloud services and as applications installed into third-party platforms such as Atlassian Jira. Korbition is the controller for the personal data described in this policy, except where a product processes content from your connected systems on your behalf and under your instructions — for example, the content of the Jira issues your rules act on. In those cases Korbition acts as a processor, and your use of the connected platform remains subject to that platform's own terms and privacy policy.
2. Information we process
Our products process data solely to deliver the functionality you configure:
- Account & authentication data: OAuth tokens, tenant IDs, and authorized credentials necessary to communicate with your connected platforms (e.g., Atlassian Jira, GitHub, GitLab, Slack, Microsoft Teams, Google Workspace). All credentials are encrypted at rest using industry-standard cryptography.
- Content processed at your direction: information contained in the issues, comments, events, pull/merge requests, or chat messages that trigger — or are targeted by — the automations, notifications, and integrations you configure. We process this content only to operate those configurations, never for our own purposes. How much of it is stored, and for how long, is product-specific: see the product sections in Part B.
- Telemetry & diagnostics: aggregated execution counts, latency, error status codes, and non-identifying operational metrics required to monitor system stability.
3. Use of third-party APIs (including Google API Services)
When connecting third-party services such as Google Workspace / Gmail:
- Our application accesses third-party APIs solely via user-approved OAuth 2.0 scopes (such as
gmail.sendfor automated email dispatch). - Google API Limited Use Disclosure: Korbition's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We do not read your inbox, store your private emails, or use your data for advertising or model training.
4. Data location, tenant isolation & security
Customer content is stored in our primary EU region (Frankfurt). Korbition enforces strict logical tenant isolation: each tenant's configurations, rules, and encrypted credentials reside in isolated partitions, and cross-tenant access is blocked at the data layer.
We implement robust technical and organizational security measures, including HTTPS/TLS 1.3 in transit, AES-256 encryption at rest, the principle of least privilege, and automated vulnerability scanning.
5. Data sharing & sub-processors
We do not sell, rent, or monetize your data. We share information only with the sub-processors listed below, and only as strictly necessary to deliver our services. Each is engaged under contractual confidentiality and data-processing terms appropriate to the data involved:
- Compute & container hosting: Fly.io, Inc. — application execution and backend compute (Frankfurt, EU primary region).
- Database & encrypted storage: Neon, Inc. (on AWS) — encrypted database storage (Frankfurt, EU primary region; AES-256 encrypted at rest).
- AI model inference: Amazon Web Services, Inc. — AI inference on Amazon Bedrock in the AWS EU (Ireland) region, reached via OpenRouter as a routing gateway. This is Korbition's default AI provider for metered AI features. Strict Zero Data Retention (ZDR) applies: no customer data, issue context, or smart values are ever retained or used for AI model training. AI providers receive data only when an AI feature is actually used — see the relevant product section in Part B.
- Edge & network protection: Cloudflare, Inc. — DNS, edge security, DDoS protection, and TLS termination.
This list is the single authoritative record of our sub-processors; all Korbition products use this shared infrastructure. We update it when providers change.
6. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete personal data we hold about you, and to object to or restrict certain processing. Much of the content our products handle lives in your connected platforms (for example, your Jira site) — the fastest route to review or remove it there is usually your own platform's admin tools, or uninstalling the relevant product (which triggers deletion on our side as well, see the product section). For data held directly by Korbition, contact [email protected]; we will verify your request and respond within the timelines applicable to your jurisdiction. If you are in the EU/EEA, you may also lodge a complaint with your local data-protection supervisory authority.
7. Changes to this policy & document history
When we make material changes to this policy, we update the date above and record the change below so you can see what changed and when.
| Date | Change |
|---|---|
| September 25, 2026 | Removed the bring-your-own-key (BYOK) AI option from Settings — AI features now always use Korbition's default metered provider (Amazon Bedrock in the AWS EU (Ireland) region via OpenRouter, Zero Data Retention). Added a contact form at /contact.html alongside the published mailboxes. |
| September 24, 2026 | Corrected the run-payload retention window (the most recent 250 runs, not 1,000). Clarified that the default AI provider (Amazon Bedrock in the AWS EU (Ireland) region via OpenRouter) is not used when a customer configures bring-your-own-key — BYOK sends prompts to the customer's chosen endpoint instead. |
| August 31, 2026 | Restructured into company-wide (Part A) and per-product (Part B) sections. Expanded the Rulekestra disclosure (Jira data access, storage & retention windows, AI features, Atlassian's role, uninstall behavior). Added the consolidated sub-processor list, a your-rights section, and this document history. AI inference sub-processor updated: production AI features run on Amazon Bedrock in the AWS EU (Ireland) region. |
| August 20, 2026 | Initial published version. |
8. Contact & security reports
For questions or requests regarding your data and privacy, use the contact form (topic: Privacy) or write to [email protected] or [email protected]. The form collects your name, email address, and message so we can reply; see Information we process.
To report a security vulnerability in our products, please contact [email protected]. We acknowledge reports within 2 business days, follow Atlassian's Security Bug Fix Policy timelines, and support coordinated disclosure.
Each Korbition product has its own section here, describing what it accesses, what it stores, and how long it keeps it. New products are added as they launch.
Rulekestra — rule automation for Jira
Rulekestra lets teams on Atlassian Jira Cloud and Jira Service Management build rules that react to Jira events and perform actions: editing and transitioning issues, commenting, notifying people in Jira, Slack, Microsoft Teams, or email, creating related Confluence pages, exporting data, and similar workflow automation. It is delivered through Atlassian Marketplace and runs on Atlassian's Forge platform.
Jira data it accesses, and why
- Issue and event content from the Jira events your rules listen to (issue created/updated, comments, worklogs, service-desk request events, and similar) — needed to evaluate rule conditions and build smart values.
- Project and user metadata used to resolve smart values and notification recipients: project keys, issue types, statuses, fields, user display names, and — only where your Jira grants the email-address scope — user email addresses, so notifications can address the right person.
- Attachments and files when a rule exports data or forwards a file to a destination you configured.
How rules execute
Rules run with the Jira permissions of the person who authored them, so Rulekestra cannot do anything in Jira that its author could not do themselves. When a rule is saved, we verify the author's permissions for each project the rule touches and record a project-scoped, expiring authorisation; when that authorisation cannot be established for an action, the action is withheld rather than performed. This is why a rule authored by someone who can only see two projects will never touch a third.
What we store, and for how long
Rulekestra stores only what it needs to run your rules: rule definitions, connection credentials (AES-256 encrypted at rest), and run records (also encrypted at rest), all hosted in the EU (Frankfurt). Retention windows:
- Execution records are kept for at most 90 days (and capped per tenant).
- The triggering event payloads behind recent runs are kept for the most recent 250 runs within that same window.
- Failed-action records are kept for 14 days.
- Paused approval continuations are kept for 30 days.
- Older records are evicted automatically.
AI features
Rulekestra's optional AI features — AI-assisted rule authoring, natural-language rule import, and JQL translation — send the text you supply plus limited Jira metadata (project, issue-type, and field context) to an AI inference provider. That is Amazon Bedrock in the AWS EU (Ireland) region, under the Zero Data Retention terms listed in Part A. Nothing is retained by Korbition after the response is produced, and no content is ever used to train models. AI features are entirely optional: authoring rules manually does not involve AI inference at all.
Notifications & connected destinations
When a rule sends a notification or export, the message or file content — which may include issue content — is transmitted to the destination you configured: a Jira user or watcher, a Slack channel or user, a Microsoft Teams chat, a Gmail address, a webhook URL, or a Confluence space. Those destinations are systems you control; their own terms and privacy policies govern your use of them. You can always see — and change — which destinations a rule uses in the rule editor.
Atlassian's role
Rulekestra runs on Atlassian's Forge platform, so some app communication flows through Atlassian infrastructure under Atlassian's developer terms, and Atlassian is an independent controller of your Atlassian account data (your Atlassian account profile, for example). That data is governed by Atlassian's privacy policy, not ours. Rulekestra only processes Jira content to the extent your rules and Jira's granted permissions require.
Uninstalling
When Rulekestra is uninstalled from your Jira site, all tenant data — rules, connection credentials, run history, and any cached content — is permanently purged from our systems. You can also request earlier deletion of your tenant's data at any time by contacting [email protected].
What Rulekestra never does
- It does not read or process your Jira data outside of the rules you configure and the diagnostics needed to operate the service.
- It does not use your content for advertising, or to train AI models.
- It does not sell, rent, or monetize your data.
- It does not access anything in Jira beyond the scopes granted at install — and those scopes are visible on the Marketplace listing before you install.