No server, no tracking, nothing sent to me.
Cascade for Jira is built and run by me, Ahmad Fiaz, as an independent project. Cascade shows your Jira Cloud work as a tree, with issue details, an Inbox and exports. It has no server, no analytics and no tracking, and it sends nothing to me.
Cascade works inside your own browser. It talks to your own Jira site, using the session you are already signed in with, and keeps what it stores in your browser. The one exception is a single install date that Chrome sync can copy to your Google account.
Last updated: September 23, 2026. This same policy is also published at cascadeforjira.netlify.app until that address is retired.
What Cascade reads
When you open the Cascade panel on a Jira Cloud page, Cascade reads your Jira data through Jira’s own REST API, from within the browser session you are already signed in with. It can only see what your Jira account can already see. Depending on what you open, that includes:
- Issue keys, summaries, types, statuses, assignees, parent links and dates, to build the tree.
- The full details of an issue you open: its fields, description, comments, attachments and change history.
- For the Inbox: issues updated in the last 30 days that you are assigned to, reported, watch or are mentioned in, with their comments and changes.
- Your own Jira account ID and display name, so Cascade can show what is yours and assign issues to you.
- The names and profile pictures of people who can see an issue, when you type @ to mention someone in a comment.
What Cascade can change in Jira
Cascade changes Jira only when you ask it to, and only with your own Jira permissions. It can:
- Move an issue to another status.
- Assign an issue to yourself.
- Post a comment or a reply, including @mentions.
- Watch or stop watching an issue.
You can move or assign up to 15 selected issues at once. Each change goes straight from your browser to your Jira site, just as if you had made it in Jira, and Jira records it under your name.
Where your data goes
Cascade has no server of its own, and it never sends your data to me.
- Its data requests go only to your own Jira site (
*.atlassian.net). - Pictures load the same way they do in Jira. Profile pictures come from Atlassian or Gravatar. Attachment images come from your Jira site through Atlassian’s media service. An image that an issue embeds from another website loads from that website.
- Links you click, such as Open in Jira, links inside an issue or the Pro waitlist link, open in a new tab.
- Exports (CSV download or copy to clipboard) are made in your browser and saved or pasted by you.
What Cascade stores in your browser
So it opens quickly and remembers where you were, Cascade stores some data in your browser. None of it is sent to me.
- Extension storage (
chrome.storage.local): cached issue lists, your Inbox with the comments and change previews it shows, what you had already seen, saved views, and small settings such as where the launcher sits. - Chrome sync storage (
chrome.storage.sync): one value, the date Cascade first ran in your browser. If Chrome sync is on, Chrome copies it to your Google account. Cascade keeps it so a future Pro version can recognise early users. - Your Jira site’s own browser storage: the cache of a whole-space load (IndexedDB), and your panel layout, filters and search for each view (localStorage). Chrome files these under your Jira site’s address, not under the extension.
Keeping and deleting data
- Cached Jira data is replaced each time Cascade reloads it. Data for views you no longer open stays until it is deleted as described below.
- Removing the extension deletes its extension storage on this device.
- Removing the extension does not delete what is in your Jira site’s own storage. To clear it, delete the site data for your atlassian.net address in Chrome’s settings. That may also sign you out of Jira.
- The install date in Chrome sync may remain in your Google account after you remove Cascade, so a reinstall can find it.
What I don’t do
- I don’t receive your Jira data, your Jira sign-in, or any record of how you use Cascade.
- I don’t use analytics, tracking, advertising or third-party SDKs in the extension.
- I don’t sell or share anyone’s data.
Cascade’s use of the data it handles complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.
Permissions and why
storage: Keep the cached data, Inbox, settings and install date described above.*.atlassian.net: Run Cascade on your Jira Cloud pages, and read and, when you ask, update your Jira data through your own session. Cascade runs only on pages at*.atlassian.net.
Cascade asks for no other permissions.
The Pro waitlist
Cascade links to a Pro waitlist page at cascadeforjira.netlify.app/pro/. Some of those links add which part of Cascade you came from (export, diffs or Inbox) to the address. Nothing else is passed on, and opening the page is up to you.
If you join, the form sends me your email address and any answers you choose to give, through Netlify, which hosts the page. I use them only to tell you when Pro is ready and, if you tick the box, to ask a couple of follow-up questions. No newsletter, no sharing. Email me any time and I will delete your entry.
Changes to this policy
If this policy changes, its “Last updated” date will change. I’ll note material changes in the extension’s Chrome Web Store listing.
Contact
Questions about privacy? Email me at ahmedfiazjan2@gmail.com.
This website
This part covers cascadeforjira.com itself. The website is separate from the extension: it never connects to your Jira site and never receives anything from the extension.
Hosting
The site runs as a Cloudflare Worker at cascadeforjira.com. To serve and protect the site, Cloudflare may process ordinary request data, such as your IP address and your browser’s user agent.
Analytics without cookies
The site sets no cookies and uses no browser storage. There are no forms, accounts or payments. To understand how the site is used, I rely on two simple kinds of measurement, described below.
I use Cloudflare Web Analytics. Cloudflare adds a small script to the pages, loaded from static.cloudflareinsights.com. It measures page views, the site that referred you, your browser, device type and operating system, your country, and how quickly the page loaded. It sets no cookies, uses no local storage and does not fingerprint you. It reports to this site’s own /cdn-cgi/rum address, and Cloudflare discards your IP address instead of storing it.
The site also counts two things itself: which page you viewed, and which Chrome Web Store button you clicked. With each count it keeps your country and, if you arrived from another website, that website’s name (such as google.com), never its full address. These counts are stored in Cloudflare Workers Analytics Engine, which keeps them for three months. They use no cookies and no identifiers, and your IP address is not stored with them.
Links
Chrome Web Store links carry fixed tags (utm_source, utm_medium, utm_campaign and utm_content) that tell the store the visit came from this website and which button was used. They pass on nothing from your own visit. The Chrome Web Store and other sites you open from here have their own privacy practices. Email links open your own email app.
Questions about this website go to the same address: ahmedfiazjan2@gmail.com.