keelapps

keelapps/AccessLens for Confluence/Privacy policy

Privacy policy — AccessLens for Confluence

Effective date:

The short version

AccessLens for Confluence (“AccessLens”, “the app”) is published by Keelapps. It is read-only: it declares no write scope of any kind and cannot change a permission, a restriction, a page or a comment. Everything it stores lives in Atlassian-hosted Forge storage inside your own Atlassian site. The app declares no external network permissions, which Atlassian enforces at the platform level, so there is no Keelapps server, no analytics, no telemetry and no third party.

What the app reads

AccessLens's entire function is to read the permission state of your site and present it back to you. It reads:

What the app stores

All data lives in Atlassian-hosted Forge storage inside your own Atlassian site. The app has no servers of its own and makes no calls to any external service.

DataWhat it containsWhy
Snapshots for each space, its identifiers and its permission grants; for each restricted page, its id, title, parent id and the users and groups named in its restrictions; for each group referenced by a grant, its name and the account ids and display names of its members a point-in-time record is what makes an access review evidence rather than an opinion
Access reviews the review's title, the snapshot it is pinned to, and for each space the decision, any free-text note, the deciding account id and a server-side UTC timestamp, together with any superseded decisions a sign-off has to name who signed and when
Settings scan cadence, shard size, page-restriction mode and budget, and the snapshot retention limit so a large site can be scanned within a budget you chose

Personal data stored: Atlassian account ids and display names. No email addresses, no page content, no attachments.

What the app writes to Confluence

Nothing. AccessLens declares no write scopes at all. It cannot change a permission, a restriction, a page or a comment even if it were asked to.

What the app never does

Retention and deletion

Snapshots and reviews persist in Forge storage for as long as the app is installed, or until an administrator deletes them from the app's own interface. AccessLens deliberately never deletes a snapshot automatically — at the retention limit it refuses to take a new one rather than evicting an old one, because an audit record destroyed without being asked for is worse than a refused scan.

Uninstalling the app removes its storage in accordance with Atlassian's Forge data lifecycle.

Data residency

Because everything is stored in Forge hosted storage, data residency follows your Atlassian site's data residency configuration automatically.

Sub-processors

None. Atlassian hosts everything; there is no other party involved.

Changes

Material changes to what is read, stored or where will be reflected here and in the Marketplace listing before they ship.

Contact

support@keelapps.atlassian.net — for questions about this policy, and for data access, correction or deletion requests.