Nexus · test management for Jira
Menu
Get started

Nexus privacy policy

Last updated 29 September 2026

This policy explains what information Nexus (the Jira app) and the website nexus.resync.nz handle, where it is kept, and who can see it. Nexus is made by Resync Consulting Limited, a New Zealand company ("Resync", "we", "us").

The short version

  • Nexus runs on Atlassian Forge, Atlassian's own cloud platform. Resync operates no servers of its own, and the information you put into Nexus is stored in your Jira site and in Forge storage inside Atlassian's cloud. Resync does not receive it.
  • Nexus Basic sends nothing outside Atlassian.
  • Nexus Pro sends requirement content to the AI provider your Jira administrator connects, with your own account and key, only when someone runs an AI action. Resync never sees that content.
  • Migrating from another test tool (Pro only): if your administrator connects Xray, Zephyr Scale or AIO Tests, Nexus reads test cases from that service into Jira. No Jira data is sent to it.
  • Nexus stores Atlassian account IDs for audit trails, but never names, email addresses or avatars.
  • We do not sell personal information, and we do not use your data to train AI models.

Who is responsible for what

For the information your organisation puts into Nexus (requirements, test cases, runs, test data, environments, releases and so on), your organisation is the data controller and Resync is a data processor acting on your organisation's instructions. If you are a user of Nexus at a company that installed it, your Jira administrator is usually the right first contact for questions about that data.

Resync is the controller only for the small amount of information we handle directly: emails you send us, and the account and licensing details Atlassian shares with app vendors (see below).

What Nexus stores, and where

Everything Nexus stores stays inside Atlassian's platform:

  • On your Jira issues. Test Case, Test Set and Test Execution are ordinary Jira issues. Test steps, Gherkin text and similar design data are stored as properties on those issues. They are your Jira data and follow your Jira permissions.
  • In Forge storage for your site. Run results and step results, test case version history, test data sets, environment and deployment records, releases and sign-offs, report snapshots, draft AI findings and drafts awaiting review, settings, and audit records of who changed what.
  • Identifiers, not profiles. Where Nexus records who did something, it stores the person's Atlassian account ID only. Names and avatars are looked up from Jira when a page is shown and are not stored by Nexus.
  • Keys. CI API keys are stored only as salted hashes and shown once. An AI provider key connected on Pro is kept in Forge's secret storage and is never sent back to the browser.

Forge storage is operated by Atlassian and follows Atlassian's data residency: where your Jira site's data is pinned to a region, Nexus's Forge storage follows it. Atlassian encrypts this data in transit and at rest.

Nexus follows your Jira permissions. It checks the viewing user's own Jira permissions, including issue-level security, before showing or changing anything.

Test data. Nexus's test data sets are meant for made-up (synthetic) values. Nexus scans data sets for likely real personal information, always refuses real card numbers, and masks values in sets marked sensitive. Please don't put real customer data into test data sets.

AI processing (Nexus Pro only)

Nexus Pro uses the AI account your Jira administrator connects: Anthropic, OpenAI, Google, Moonshot (Kimi) or xAI (Grok), with your own API key. A Jira administrator can turn AI off for the whole site, and a project administrator can turn it off for their project; while it is off, Nexus sends nothing to the provider for that site or project. When someone runs an AI action, Nexus sends that provider only what the action needs, such as the summary, description, acceptance criteria and approved findings of the requirements in that run, or the steps of the test case being worked on. Issue comments are sent only if your administrator turns that on. Test data values marked masked or sensitive are never sent.

If the person running the action leaves Use attachments on, Nexus also sends the text of the requirement's own Jira attachments they choose (PDF, Word, text, Markdown or CSV files) and, for providers that accept images, the chosen PNG or JPG images. These are the same kind of content as the requirement itself and go to the same provider. Nexus reads them from Jira for that one request and stores none of their content.

That content goes directly from Atlassian's Forge platform to the provider. Resync runs no server in between and never receives it. How the provider processes, stores and uses it is governed by your organisation's own agreement with that provider, including which region it is processed in. Nexus does not offer region-pinned AI processing.

Nothing is sent when nobody runs an AI action. Nexus Basic has no AI features and sends nothing outside Atlassian.

Every AI finding and every AI-drafted test is a draft: nothing is written to your Jira issues until a person accepts it. AI output is a suggestion, not an authoritative or binding quality decision.

Migrating from another test tool (Nexus Pro only)

If a Nexus Pro administrator connects Xray Cloud, Zephyr Scale Cloud or AIO Tests Cloud to migrate test cases, Nexus uses the API credentials they enter to read test cases from that service into your Jira site. The credentials are stored encrypted in the app's Forge storage on your site, used only for that migration, and deleted when it finishes (by default) or after 30 days. No Jira data is sent to those services.

What is read is the test content itself: titles, descriptions, preconditions, steps, folder names, labels, priority, status and custom field values, written into your Jira site as Nexus test cases. What is sent to the other service is only the credentials and which project to read. Vendor user accounts are not copied.

How long information is kept

  • While Nexus is installed, the app's own working history (run detail, report snapshots and similar records) is removed after 180 days by default. Your Jira administrator can set this per project, from 30 to 3,650 days. Findings still waiting for review are kept until someone reviews them.
  • Audit records are kept for 7 years by default, adjustable per project from 1 to 10 years, because they serve as audit and release evidence: deployments, environment events, releases and go/no-go sign-offs, test case change history, reviewed AI findings (who accepted, edited or rejected them), the administrator change log, and the history of requirements marked "Not testable". To save space, test case history entries older than a year keep who, when and what changed but drop their copy of the test steps (the newest entry for each test case is always kept whole).
  • Backups. Atlassian's site backup does not include app data, so a Jira administrator can export everything Nexus stores (Nexus Setup → Backup & Restore) and restore it later. A backup file never contains secrets such as API keys or your AI key, and it stays wherever your administrator saves it.
  • Your Jira issues are never deleted by Nexus. Test cases, sets, executions, their links and properties are your Jira data and stay in Jira if you uninstall the app.
  • After uninstall, Atlassian retains the app's Forge storage for a limited period under its platform retention policy and then deletes it permanently.

What Resync can see

Resync does not have access to the content of your Nexus data. We can see:

  • Operational logs from the Forge platform, which Nexus writes with status codes and internal identifiers only, never issue text, test content, findings or keys.
  • Installation and licence information that Atlassian shares with app vendors, such as your site address, edition, licence status and the technical and billing contacts you gave Atlassian. We use it to provide and license the app and to contact you about it.
  • Anything you send us yourself, such as a support email with a screenshot. If you send us content from your Jira site so we can help, we use it only to answer you and delete it when it is no longer needed.

Support and this website

When you email nexus-support@resync.co.nz or nexus@resync.co.nz, we keep the email and your contact details to answer you and to keep a record of the support we gave.

The website nexus.resync.nz has no sign-in and no advertising. It offers optional Google Analytics measurement so we can understand which public pages are useful. Analytics is not loaded unless you choose Allow analytics. Advertising storage, advertising user data, advertising personalisation and Google signals remain disabled. If you initially decline, no Google Analytics tag is loaded. If you later withdraw consent, measurement is disabled and Analytics cookies are removed; the already-downloaded script may remain in the page until you leave or reload it. Your choice is saved in your browser's local storage and can be changed with the Analytics choices control on the site.

When enabled, Google Analytics may process information such as the page visited, approximate location, browser, device and interaction timing under Google's terms. Do not enter personal or confidential information into public website URLs. Our web host also keeps standard server logs (such as IP address, browser and pages requested) for security and operation. The site's font is served by Google Fonts, so your browser requests it from Google.

Who else is involved

  • Atlassian hosts Nexus and its storage as the Forge platform provider, under Atlassian's own privacy policy and data processing terms.
  • The AI provider your organisation connects (Pro only) processes content under your organisation's agreement with it, as described above.
  • A test tool your administrator connects to migrate (Pro only): Nexus reads from it with the credentials your administrator entered; nothing from Jira is sent to it.
  • Google, when you opt in to website analytics, processes the limited website-use data described above and serves the site's fonts under Google's terms.
  • Our website hosting provider processes standard server logs to operate and secure the public website.

We do not share personal information with anyone else, except where the law requires it or as otherwise described in this notice.

International transfers

Resync is based in New Zealand. The European Commission recognises New Zealand as providing an adequate level of data protection. Data stored by Nexus stays in Atlassian's platform, and Atlassian's own transfer mechanisms apply to that hosting.

Your rights

Under the New Zealand Privacy Act 2020, and where it applies the EU and UK GDPR and similar laws, you can ask for access to personal information about you, ask for it to be corrected or deleted, and object to or restrict some uses of it.

For information inside Nexus, contact your organisation's Jira administrator first, because your organisation controls that data; we will help them respond. For information Resync holds directly, email nexus@resync.co.nz.

If you are not happy with our response, you can complain to the New Zealand Office of the Privacy Commissioner (privacy.org.nz) or to the data protection authority where you live.

Security

Nexus is built on Atlassian's security controls (encryption in transit and at rest, Atlassian's access controls) and uses the narrowest Jira permissions it needs, with no site administration access. To report a security concern, email nexus-support@resync.co.nz with "Security" in the subject line.

Changes to this policy

We will update this page when Nexus or our practices change, and change the date at the top. Significant changes will also be noted in the app's release notes.

Contact

Resync Consulting Limited, New Zealand Privacy questions: nexus@resync.co.nz Support: nexus-support@resync.co.nz