Privacy Policy

Space Access Audit for Confluence · Last updated 11 September 2026

In one sentence: the app reads permission data from your Confluence site, shows it to you, and stores nothing beyond two small configuration values inside Atlassian's own infrastructure — it has no external server, sends nothing to us, and we never see your data.

Who we are

Space Access Audit for Confluence ("the app") is published on the Atlassian Marketplace by Boundless Stream ("we", "us"). For any privacy question or request, contact support@boundlessstream.com.

Roles: your organisation is the data controller for the content and user data in your Confluence site. We act as a data processor for the limited processing described below. Atlassian is the platform provider on whose infrastructure the app runs and is a sub-processor. Where a Data Processing Addendum is required, our standard DPA is available on request.

What the app accesses

DataWhyWhere it goes
Space list: id, key, name, type, owner account idTo enumerate the spaces to audit and to label findings.Displayed to you. Not stored, not transmitted.
Permission assignments: operation, target type, and the principal they are granted toThis is the subject of the audit.Displayed to you; included in reports you export.
Principal identifiers: user account ids, group ids, access-class valuesTo identify who holds a permission.Displayed to you. Not stored, not transmitted.
Display names and group namesTo make the report readable.Displayed to you. Not stored, not transmitted.
Account attributes: guest / external collaborator / unlicensed / account typeTo classify principals correctly.Displayed to you. Not stored, not transmitted.

The app does not read or process page content, blog content, comments, attachments, email addresses or any free-text field. It reads only the permission metadata listed above.

What the app stores

Two configuration values, in Atlassian Forge storage scoped to your installation:

Neither value contains end-user personal data. Storage is provided by Atlassian and resides in the same region as the rest of the app; we cannot read it.

What the app writes

If you use the export feature, the app writes a CSV file as an attachment on a Confluence page that you choose. That file contains permission metadata, including principal identifiers and display names, because that is what an audit report is. It stays inside your own Confluence site, under your own controls, and you can delete it at any time. The app has no other write capability: it cannot change a permission, a space, a page or a user.

Data transfers

None. The app has no external server, no API key of its own, no analytics, no telemetry and no cookies. Every request it makes goes to your own Atlassian site's REST API through the Forge platform, and every byte it produces stays inside your site. We do not operate any endpoint that receives your data, and we do not sell or share data with third parties.

Legal basis and data protection rights

Where the GDPR or comparable law applies, processing is carried out on the instructions of your organisation (the controller) for the purpose of access governance, which is a legitimate interest of the controller. The personal data involved is limited to account identifiers, display names and access-state flags; it is not used for profiling, marketing or automated decision-making.

Individuals in the European Economic Area, the UK or Switzerland may have rights of access, rectification, erasure, restriction and objection. Because the data resides in your site and not with us, such requests are normally addressed by your Confluence administrator; deleting a user's account or removing their permissions in Confluence removes them from the next scan. If you believe we hold data about you, contact support@boundlessstream.com and we will respond within 30 days.

Retention and deletion

Data residency

Because the app runs entirely on Atlassian's Forge platform and stores nothing outside it, it inherits your site's data residency configuration. The app itself has no data residency settings to configure.

Children

The app is a business administration tool and is not directed at children.

Changes to this policy

We will update this page when the app's data handling changes, and will note the date at the top. Material changes will also be described in the app's release notes.