JirAI: Remote Development and privacy
JirAI supports Remote Development: the UI runs in JetBrains Client, while Jira requests and credentials stay on the host.
What runs where
- Client
The JirAI tool window, dialogs, editors and settings pages.
- Host
Jira requests, credentials, proxy handling and caches.
Data flow under Remote Development
The API token you type in the client's sign-in dialog travels to the host once, at sign-in, and is stored there; it is not stored on the client.
Files you attach are read on the client and streamed to the host, which uploads them to Jira; downloads travel the other way and are saved on the client.
All Jira requests are made by the host, so the host's proxy settings apply.
Your issue list filters are stored in the host project; the folder you last saved an attachment to is stored in the client.
JetBrains Marketplace installs JirAI on both sides as needed.
Privacy
JirAI has no telemetry, analytics, usage statistics, crash reporting or error submitter.
Requests that carry your credentials go only to the exact Jira site you signed in to; JirAI refuses any other host, including look-alike hosts, and does not follow redirects on those requests.
Avatars are loaded over HTTPS, without credentials, from the host that Jira names for them: Atlassian's avatar service or Gravatar.
Attachments and thumbnails are loaded from your Jira site.
JirAI bundles no third-party libraries; everything else it uses comes from the IDE.
Avatars and thumbnails are cached in memory for the current session only.
For what is stored where, see Where JirAI stores credentials.