keelapps/AccessLens for Confluence/Privacy policy
Privacy policy — AccessLens for Confluence
The short version
AccessLens for Confluence (“AccessLens”, “the app”) is published by Keelapps. It is read-only: it declares no write scope of any kind and cannot change a permission, a restriction, a page or a comment. Everything it stores lives in Atlassian-hosted Forge storage inside your own Atlassian site. The app declares no external network permissions, which Atlassian enforces at the platform level, so there is no Keelapps server, no analytics, no telemetry and no third party.
What the app reads
AccessLens's entire function is to read the permission state of your site and present it back to you. It reads:
- Spaces — id, key, name, type and status.
- Space permissions — which principal (user, group or access class) holds which operation on which space, and, on sites using role-based space permissions, the role assignments that carry the same information.
- Pages — id, title and parent id, so restricted pages can be named and their inheritance chain walked. Page content is never read.
- Page restrictions — which users and groups a page's view or edit is restricted to.
- Groups and their members — group id, group name, and the account ids and display names of members, so a group-level answer can be turned into a person-level one.
What the app stores
All data lives in Atlassian-hosted Forge storage inside your own Atlassian site. The app has no servers of its own and makes no calls to any external service.
| Data | What it contains | Why |
|---|---|---|
| Snapshots | for each space, its identifiers and its permission grants; for each restricted page, its id, title, parent id and the users and groups named in its restrictions; for each group referenced by a grant, its name and the account ids and display names of its members | a point-in-time record is what makes an access review evidence rather than an opinion |
| Access reviews | the review's title, the snapshot it is pinned to, and for each space the decision, any free-text note, the deciding account id and a server-side UTC timestamp, together with any superseded decisions | a sign-off has to name who signed and when |
| Settings | scan cadence, shard size, page-restriction mode and budget, and the snapshot retention limit | so a large site can be scanned within a budget you chose |
Personal data stored: Atlassian account ids and display names. No email addresses, no page content, no attachments.
What the app writes to Confluence
Nothing. AccessLens declares no write scopes at all. It cannot change a permission, a restriction, a page or a comment even if it were asked to.
What the app never does
- No data leaves your Atlassian site. There are no external calls, no analytics, no telemetry, and no third-party services. The app declares no external permissions, which Forge enforces at the platform level.
- CSV exports are assembled in your own browser from data delivered over the Forge bridge. They never pass through any server.
- Application logs record snapshot ids, space keys, shard progress, HTTP status codes and error reasons. They never record display names, account ids, page titles, or permission content.
- The vendor has no access to your data. Forge storage is reachable only by the app itself, running inside Atlassian's infrastructure.
Retention and deletion
Snapshots and reviews persist in Forge storage for as long as the app is installed, or until an administrator deletes them from the app's own interface. AccessLens deliberately never deletes a snapshot automatically — at the retention limit it refuses to take a new one rather than evicting an old one, because an audit record destroyed without being asked for is worse than a refused scan.
Uninstalling the app removes its storage in accordance with Atlassian's Forge data lifecycle.
Data residency
Because everything is stored in Forge hosted storage, data residency follows your Atlassian site's data residency configuration automatically.
Sub-processors
None. Atlassian hosts everything; there is no other party involved.
Changes
Material changes to what is read, stored or where will be reflected here and in the Marketplace listing before they ship.
Contact
support@keelapps.atlassian.net — for questions about this policy, and for data access, correction or deletion requests.