Stint Data Processing Agreement

Last updated: August 12, 2026

This Agreement describes how Aquarium Apps ("Processor") processes personal data on behalf of a customer ("Controller") through use of Stint, based on the practices already documented in the Stint Privacy Policy. By installing or using Stint, the Controller accepts this Agreement, consistent with Section 1 of the Stint Terms of Service.

1. Purpose and scope

Aquarium Apps processes personal data only as instructed by the Controller, through the Controller's use of Stint's documented features (time tracking, timers, approvals, reporting, and related settings). Aquarium Apps does not process personal data for any other purpose.

2. Roles of the parties

The customer using Stint acts as the data controller for personal data processed through the app. Aquarium Apps acts as a data processor, processing that data solely to provide the Stint service.

3. Categories of personal data

Stint processes the following categories of personal data on the Controller's behalf, all in the form of Jira account IDs rather than names, email addresses, or other profile data:

  • Account ID references. Jira account IDs are used as keys or foreign-key-style references throughout Stint's records - for example, the account ID that owns an approval record, the account ID of a reviewer, the account ID recorded as the actor on an audit log entry, and the account ID recorded as the creator of an import job.
  • Free-text fields. Some records include free-text fields the data subject or another user may populate with personal data at their discretion, such as a rejection reason on an approval, details captured in an audit log entry (which can include a nested rejection reason), and error messages generated during a Tempo import.
  • Worklog metadata property. The io.stint.metadata property Stint writes onto native Jira worklogs, recording who the time was logged for, who created it, and (for imports) who imported it - see the Privacy Policy's "Worklog metadata property" section for full detail.

4. Subprocessors

Aquarium Apps engages Atlassian as its subprocessor for all data Stint writes (Forge Storage and Forge SQL, a TiDB database hosted by Atlassian) - see the Privacy Policy's "How your data is stored" section for what's stored there. Aquarium Apps does not operate any servers, databases, or cloud functions of its own.

Conditional subprocessor - Tempo. If the Controller opts into Stint's optional Tempo import feature, Stint's own backend - not the Controller's browser - calls api.tempo.io server-side, using an API token the Controller supplies and that is stored in Forge Storage. Tempo is engaged as a subprocessor only when this optional feature is enabled by the Controller; it is not part of Stint's default data flow.

Stint's build also depends transitively on @sentry/node (via @forge/kvs and @forge/sql) and workbox-google-analytics (via build tooling). Neither package is imported or called anywhere in Stint's code, so neither is an active subprocessor.

5. Confidentiality

Aquarium Apps treats personal data processed through Stint as confidential and will not disclose it to third parties except as described in this Agreement or as required by law.

6. Security

Personal data processed through Stint resides entirely on Atlassian's Forge platform and is subject to Atlassian's own security measures and certifications. Aquarium Apps does not operate independent infrastructure and does not hold its own security certifications (e.g. SOC 2, ISO 27001) separate from Atlassian's. See atlassian.com/trust for Atlassian's security and compliance documentation.

7. Assistance with data subject requests

Stint provides an in-app flow for data subject access, export, and deletion requests: Settings → GDPR → Export my data / Delete my data. Aquarium Apps will assist the Controller with requests that cannot be fulfilled through this flow - contact support@aquariumapps.io. See Section 9 for the current scope of what the in-app deletion flow affects.

8. Personal data breach notification

In the event of a personal data breach affecting data processed through Stint, Aquarium Apps will notify the Controller without undue delay after becoming aware of the breach.

9. Deletion or return of data

When Stint is uninstalled, Atlassian's Forge platform soft-deletes all associated Forge Storage and Forge SQL records within 28 days (recoverable by reinstalling within 21 days) - see the Privacy Policy's Data Retention section for the full mechanics, including native Jira worklogs and the io.stint.metadata scrub.

The in-app deletion flow (Settings → GDPR → Delete my data) deletes the data subject's Forge Storage entries and approvals/audit_log rows in Forge SQL, redacts their account ID in the io.stint.metadata property on existing worklogs and in Tempo import logs, and nulls out the account ID recorded as an import job's creator - see the Privacy Policy's Deletion section for the equivalent user-facing description.

10. International data transfers

Because Aquarium Apps does not operate its own servers, data residency and any cross-border transfer safeguards for personal data processed through Stint are governed by Atlassian's infrastructure and terms, not by infrastructure Aquarium Apps controls.

11. Term

This Agreement applies for as long as the Controller has an active installation or subscription of Stint, consistent with the term of the Stint EULA, and ends on uninstall.

12. Audit rights, liability, and indemnification

Aquarium Apps does not grant the Controller a right to audit Aquarium Apps' systems or facilities. Aquarium Apps operates no independent infrastructure to audit - all data described in this Agreement resides on Atlassian's Forge platform, and Atlassian's own security and compliance documentation (see Section 6) is the relevant evidence for that infrastructure. Aquarium Apps will provide the Controller with written confirmation of its compliance with this Agreement upon reasonable request.

Aquarium Apps' liability arising out of or relating to this Agreement, including any indemnification obligation, is governed by the limitation of liability in Section 7 of the Stint Terms of Service - capped at the fees the Controller paid for Stint in the twelve months preceding the claim, excluding indirect, incidental, special, or consequential damages.

13. Governing law

This Agreement is governed by the laws of the United States.

14. Contact

Questions about this Agreement: support@aquariumapps.io. See also the Stint Support page.

Aquarium Apps is operated by Stargazers Consulting LLC.