# Permissions and privacy This is the section a security review reads, so it is written to be checked rather than to reassure. It covers the audience for the card, each Jira permission the app requests and what it is for, and the one piece of personal data that genuinely leaves Atlassian: the reporter's email address, which is what finds the record. --- ## In this section [Who can see the customer cardThe card is gated four times over before anyone sees it: agent access, a finished project, the viewer's own right to open the issue, and the audience the project chose.](https://help.gocapable.com/attio-for-jira/who-can-see-the-customer-card.html)[The Jira permissions this app asks forSix Jira permissions, one of them sensitive and one of them the only write the app makes. What each is for, and what happens while a new one is still waiting for approval.](https://help.gocapable.com/attio-for-jira/the-jira-permissions-this-app-asks-for.html)[What data leaves AtlassianEvery address the app is allowed to reach, what travels to each one, and which of them carry customer data. The reporter's email address goes to exactly one place: Attio.](https://help.gocapable.com/attio-for-jira/what-data-leaves-atlassian.html)[What is never sent, logged or storedThe negative half of the account: what no screen will print, what the logs do not contain, what storage holds and for how long, and what a reset clears and deliberately does not.](https://help.gocapable.com/attio-for-jira/what-is-never-sent-logged-or-stored.html) --- ## Related [Get started](https://help.gocapable.com/attio-for-jira/get-started.html) [Setting up](https://help.gocapable.com/attio-for-jira/setting-up.html) [Troubleshooting](https://help.gocapable.com/attio-for-jira/troubleshooting.html) --- _Written to be checked, not to reassure._