Privacy Policy

Last updated: August 26, 2026

This policy explains what data Abrega Inc., doing business as Audit Otter ("Abrega", "we", "us"), collects and how we handle it. It covers both this website (www.auditotter.com) and the Audit Otter application for Atlassian Jira and Confluence.

1. Who we are

Audit Otter is operated by Abrega Inc., doing business as Audit Otter. For anything in this policy, you can reach us at privacy@auditotter.com.

2. Our two roles

For this website and our own business records (such as the launch list), Abrega is the data controller: we decide what is collected and why. For your organization's compliance program data inside the Audit Otter application, your organization is the controller and Abrega processes that data on its behalf, only to provide the service. Requests concerning program data may therefore be routed through your organization's administrator.

3. What this website collects

3.1 Launch-list email address

If you submit your email address to receive launch updates, we store that address for one purpose: telling you when Audit Otter is available on the Atlassian Marketplace, and closely related launch news. We do not sell it, share it for advertising, or add it to unrelated mailing lists. The legal basis is your consent, which you can withdraw at any time by writing to privacy@auditotter.com; we will delete your address promptly.

3.2 Server logs

Our hosting infrastructure (Amazon Web Services CloudFront and S3) records standard access logs: requested URL, timestamp, IP address, browser user-agent, and response status. We use these only to operate the site, measure aggregate traffic, and investigate abuse. The legal basis is our legitimate interest in running a secure service. Logs are retained for up to 90 days.

3.3 What we deliberately do not collect

This website sets no cookies and uses no advertising trackers, no cross-site tracking, no fingerprinting, and no third-party analytics scripts. A theme preference, if you use the light/dark toggle, is stored only in your own browser and never sent to us.

4. What the Audit Otter application processes

4.1 What the app reads and writes in your Atlassian site

The app runs on Atlassian Forge inside your organization's Atlassian site, using narrowly scoped, Atlassian-reviewed permissions. It reads the data needed to collect compliance evidence: Jira work items, workflows, users, and audit logs; Confluence spaces, pages, and audit logs; and Jira Service Management requests, queues, and SLAs. Its only write access to your Atlassian content is publishing approved policy pages to Confluence. It cannot read content outside the granted scopes, and your team signs in with their existing Atlassian identity; the app keeps no separate user database and no passwords.

4.2 What we store in our backend

To provide the service, the app sends collected material to Abrega's backend, where we store your organization's program data:

4.3 Where and how it is protected

The backend runs on Amazon Web Services. Program data is stored in a PostgreSQL database with storage-level encryption enabled and in an encrypted, private object store for evidence artifacts; secrets live in AWS Secrets Manager. Data in transit is protected with TLS, and communication between your Atlassian site and our backend is authenticated with short-lived, signed Forge app tokens. Collection runs on an hourly schedule and on demand.

4.4 What we never do with program data

4.5 Retention, export, and deletion

Program data is retained while your organization uses the service. You can export it at any time; there is no proprietary lock-in. After the service ends, or on a verified deletion request from your organization's administrator, we delete program data promptly and at most within 30 days, except where law requires longer retention of specific records.

4.6 Subprocessors

We use Amazon Web Services for hosting and Atlassian as the platform the app runs on. The Marketplace listing and in-app documentation identify the then-current subprocessor list and hosting regions. Our Data Processing Agreement governs processing we do on your organization's behalf.

5. Your rights

Depending on where you live (including under the EU/UK GDPR and similar laws), you have the right to access personal data we hold about you, correct it, delete it, restrict or object to its processing, receive a portable copy, and withdraw consent at any time. Email privacy@auditotter.com. For personal data inside your organization's compliance program, we may refer the request to your organization, which controls that data. You also have the right to complain to your local data-protection authority.

6. Children

The website and application are business tools, not directed at children, and we do not knowingly collect personal data from anyone under 16.

7. Changes to this policy

If we change this policy, we will update this page and the date at the top. For material changes affecting launch-list subscribers or application customers, we will give notice by email or in-app before the change takes effect.

8. Contact

Privacy questions and rights requests: privacy@auditotter.com. Security reports: security@auditotter.com.