Privacy Policy
Last updated: 17 July 2026
This Privacy Policy explains how Balm ("Balm", "the app", "we", "us") collects, uses, and protects your information when you use the Balm macOS and iOS app and website. By using Balm, you agree to the practices described below.
Information we collect
- Balm-specificAtlassian account access. Balm uses OAuth 2.0 to connect to your own Atlassian account. Authentication is handled by Atlassian, and Balm receives tokens that allow the app to read and write Jira data on your behalf.
- Balm-specificJira content. Your Jira issues, projects, comments, attachments, users, filters, notifications, and account permissions remain in Atlassian. Balm accesses them through Atlassian's API using the access you grant.
- Balm-specificDevice data. Sign-in tokens are stored in the system Keychain on your device. Preferences, saved filters, notification inbox data, and other app state may be cached locally so Balm can feel fast and work offline.
- Balm-specificRead-state sync. To keep read state consistent between your devices, Balm saves a small record of notification ids you have read as a hidden property on your own Atlassian user account. Other Jira users cannot see it.
- Balm-specificSystem notifications. If you enable notifications, they are generated by the app on your device.
How we use your information
- To provide the app's core features: viewing, searching, creating, editing, commenting on, and transitioning Jira issues through your Atlassian account.
- To manage sign-in, token refresh, app preferences, saved filters, notification read state, and local cache behavior.
- To generate notifications you have opted into.
- To maintain, secure, debug, and improve the app and website.
The sign-in service
Balm-specificBalm uses one small service at auth.balm.kylescudder.co.ukbecause Atlassian requires a client secret when exchanging sign-in codes for tokens, and that secret cannot ship inside the app.
During sign-in and token refresh, the service relays your authorization code or refresh token to Atlassian and returns the result to your device. It processes these values in transit only. It has no database, stores nothing, and does not log token contents.
How your information is shared
We do not sell your personal information. Information is shared only in the following circumstances:
- With service providers. We use Atlassian for authentication and Jira data, Apple services for app distribution and system features where applicable, GitHub for public support and issue tracking, and the Balm sign-in service only for OAuth token exchange and refresh.
- When required by law. We may disclose information if required to do so by law or valid legal process.
Data retention
Jira data remains in Atlassian according to your Atlassian workspace's settings, permissions, and retention policies. Local Balm data remains on your device until you sign out, delete the app, or remove it through platform storage controls. Revoking Balm's access disconnects the app from Atlassian and its hidden read-state property.
Security
We use reasonable safeguards to protect your information, including encrypted connections, Atlassian OAuth, system Keychain storage for tokens, local platform storage, and access controls. No method of transmission or storage is completely secure.
What Balm does not collect
- No analytics, telemetry, or crash reporting.
- No advertising identifiers or tracking across apps or websites.
- No sale of personal data.
- No hosted copy of your Jira issues, comments, attachments, or projects.
Your rights and controls
You may request access to, correction of, or deletion of your personal information. Your Jira content is controlled through Atlassian and your Atlassian workspace. Balm-specific controls include:
- Sign out in Balm's settings to remove tokens and cached app data from the device.
- Revoke Balm's access at id.atlassian.com Connected apps.
- Delete the app to remove its local storage from your device.
Children's privacy
Balm is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. Continued use of the app after changes take effect constitutes acceptance of the updated policy.
Contact us
If you have any questions about this Privacy Policy, contact us using thesupport page.