keelapps

keelapps/Curator/Privacy policy

Privacy policy — Curator for Confluence

Effective date:

The short version

Curator for Confluence (“Curator”, “the app”) is published by Keelapps. It is a bulk page and label governance tool: it previews a change, applies it, and can take it back. Curator does not send your data anywhere. It runs entirely on Atlassian Forge, inside Atlassian's infrastructure, and the app declares no external network permissions — which Atlassian enforces at the platform level. There is no Keelapps server, no analytics, no telemetry and no third party.

What the app stores

Everything is stored in Forge app storage (Atlassian-hosted) inside your own Atlassian site.

DataExamplesWhy
Previews a frozen list of the pages a change would affect — page id, page title, space id, parent page id, status (current or archived) and version number for each — plus the filter that selected them, the operation and its parameters, the account id of the person who built the preview, and any free-text note they typed a preview has to describe the same pages the run will touch
Undo journals for every page a run changed, the exact inverse of that change (the labels to put back, or the parent page and space id to move it back to) and the guard values the undo checks before acting — the parent and space the page was left in the undo is the product
Operation history one record per run and per undo: the operation, a description of it, the selection it ran over, the space key, the acting person's account id and display name, start and finish timestamps, counts of pages succeeded, skipped and failed, whether it can still be undone, the free-text note, and up to 100 per-page failures with the page id and the reason history is what makes a bulk change auditable, so it deliberately names people
The label catalogue every shared label on the site — name, id, prefix — with its derived usage count and the time that count was taken so the label panel opens without re-counting the site
Operational data job checkpoint cursors (how far a long run has got) and a small record of which API routes this site accepts so an interrupted batch resumes instead of starting again

Personal data is limited to Atlassian account ids and the display names of the people who build previews and run operations. Personal labels — the favourites Confluence stores with a my prefix — are never listed and never stored.

What the app writes to Confluence

Curator writes only what the operation you previewed and confirmed says it will write:

Curator never writes page content of its own. One honest caveat: when a move cannot use the position-only endpoint, the app falls back to Confluence's page update, which requires the page body to be sent — so the app reads the page and writes the same body back unchanged, and that fallback does create a new page version, stamped with the version message Curator: move. Whether a label change also causes Confluence to record a new version is Confluence's own behaviour rather than something Curator asks for; we have not measured it on a live site, and this page will say so plainly once we have.

Curator never changes page or space permissions, never deletes pages, and never touches attachments or comments.

What the app never does

Retention and deletion

Data residency

Whatever your Atlassian site's residency is. Because everything is stored in Forge hosted storage, data residency follows your Atlassian site's configuration automatically, and Curator introduces no additional residency considerations.

Sub-processors

None. Atlassian hosts everything; there is no other party involved.

Changes

Material changes to what is stored or where will be reflected here and in the Marketplace listing before they ship.

Contact

support@keelapps.atlassian.net — for questions about this policy, and for data access, correction or deletion requests.