keelapps/Curator/Privacy policy
Privacy policy — Curator for Confluence
The short version
Curator for Confluence (“Curator”, “the app”) is published by Keelapps. It is a bulk page and label governance tool: it previews a change, applies it, and can take it back. Curator does not send your data anywhere. It runs entirely on Atlassian Forge, inside Atlassian's infrastructure, and the app declares no external network permissions — which Atlassian enforces at the platform level. There is no Keelapps server, no analytics, no telemetry and no third party.
What the app stores
Everything is stored in Forge app storage (Atlassian-hosted) inside your own Atlassian site.
| Data | Examples | Why |
|---|---|---|
| Previews | a frozen list of the pages a change would affect — page id, page title, space id, parent page id, status (current or archived) and version number for each — plus the filter that selected them, the operation and its parameters, the account id of the person who built the preview, and any free-text note they typed | a preview has to describe the same pages the run will touch |
| Undo journals | for every page a run changed, the exact inverse of that change (the labels to put back, or the parent page and space id to move it back to) and the guard values the undo checks before acting — the parent and space the page was left in | the undo is the product |
| Operation history | one record per run and per undo: the operation, a description of it, the selection it ran over, the space key, the acting person's account id and display name, start and finish timestamps, counts of pages succeeded, skipped and failed, whether it can still be undone, the free-text note, and up to 100 per-page failures with the page id and the reason | history is what makes a bulk change auditable, so it deliberately names people |
| The label catalogue | every shared label on the site — name, id, prefix — with its derived usage count and the time that count was taken | so the label panel opens without re-counting the site |
| Operational data | job checkpoint cursors (how far a long run has got) and a small record of which API routes this site accepts | so an interrupted batch resumes instead of starting again |
Personal data is limited to Atlassian account ids and the display names of the
people who build previews and run operations. Personal labels — the favourites
Confluence stores with a my prefix — are never listed and never
stored.
What the app writes to Confluence
Curator writes only what the operation you previewed and confirmed says it will write:
- Labels, attached to or detached from pages.
- A page's parent, when you move pages. Moves prefer the endpoint that changes only the page's position.
- Archived status, when you archive pages.
Curator never writes page content of its own. One honest caveat: when a move cannot
use the position-only endpoint, the app falls back to Confluence's page update,
which requires the page body to be sent — so the app reads the page and
writes the same body back unchanged, and that fallback does create a new
page version, stamped with the version message Curator: move.
Whether a label change also causes Confluence to record a new version is
Confluence's own behaviour rather than something Curator asks for; we have not
measured it on a live site, and this page will say so plainly once we have.
Curator never changes page or space permissions, never deletes pages, and never touches attachments or comments.
What the app never does
- No data leaves your Atlassian site. The app declares no external permissions, so it cannot make an outbound call even by accident. There is no analytics, no telemetry and no third-party service.
- The vendor has no access to your data. Forge storage is reachable only by the app itself, running inside Atlassian's infrastructure. Support requests are answered from what you tell us, not from your data.
- The app requests no scope beyond the eight listed in its documentation, and none of them reads page content.
Retention and deletion
- Operation history is capped at 2,000 entries per site; beyond that the oldest are dropped.
- Previews stop being runnable 24 hours after they were built, because a day-old preview no longer describes the site. Discarding a preview deletes it and its page list.
- Previews, operation records and undo journals persist until they are discarded or the app is uninstalled. There is no background sweeper — we state that plainly rather than implying an automatic expiry that does not exist.
- Uninstalling the app removes its storage in accordance with Atlassian's Forge data lifecycle. Nothing Curator wrote to your pages — labels, moves, archived status — is undone by uninstalling: those are your content, and the undo journal that could take them back goes away with the app. Undo what you want undone before you uninstall.
Data residency
Whatever your Atlassian site's residency is. Because everything is stored in Forge hosted storage, data residency follows your Atlassian site's configuration automatically, and Curator introduces no additional residency considerations.
Sub-processors
None. Atlassian hosts everything; there is no other party involved.
Changes
Material changes to what is stored or where will be reflected here and in the Marketplace listing before they ship.
Contact
support@keelapps.atlassian.net — for questions about this policy, and for data access, correction or deletion requests.