Privacy Policy
Access Snapshot for Confluence · Effective 8 October 2026
The short version. This app runs entirely inside Atlassian's infrastructure. It reads permission and restriction data from your Confluence site in order to produce a report, and it sends nothing anywhere. We have no servers, no database and no copy of your data, and the app has no technical ability to transmit data outside Atlassian — it declares no external network access at all.
Who we are
On Record Labs is an independent software studio based in Brazil. We publish Access Snapshot for Confluence on the Atlassian Marketplace. This policy covers that app and nothing else.
Privacy questions: privacy@onrecordlabs.com
Security reports: security@onrecordlabs.com
Everything else: support@onrecordlabs.com
What the app does
The app produces a dated record of who can reach which spaces and which restricted pages in a Confluence Cloud site. A Confluence administrator generates the report on demand, views it on screen, and may export it as CSV or PDF.
The report runs with the access of the administrator who requests it. The app does not see anything that administrator could not already see.
What the app reads
While a report is being generated, the app reads the following from your Confluence site, through Atlassian's own APIs:
- space keys, names and types;
- space permissions: which principals hold which operations;
- group names and group identifiers;
- page titles, page hierarchy, and the read and edit restrictions on pages;
- display names and account identifiers of users who appear in a permission or a restriction, and of the administrator generating the report.
Email addresses are never read, stored or displayed. The app resolves people by account identifier and display name only.
This reading happens while the report is being produced. The report itself is held in your browser and in the file you choose to export. It is not persisted by the app.
What the app stores
One record, in Atlassian's own app storage, inside your site. It contains only:
- the date and time of the last report;
- how long it took, including per-phase timings, and how many spaces, pages and groups were covered;
- which categories of gap were declared, as short codes;
-
one sentence of provenance, which includes the display name of the
administrator who generated it — for example
Report generated by A. Admin on 8 October 2026…
That sentence is shown on screen so the next person to open the app can see when the last report was produced and by whom.
No page titles, no group names, no permission data and no page content are stored. An earlier development build did store some of these; it was removed before release.
Logs
The app writes an operational log entry when a report starts and when it finishes, so that failures can be diagnosed. These entries contain counts, durations and gap category codes. They contain no names, no page titles and no account identifiers. The logs are held by Atlassian's platform and are not sent anywhere else.
Exported files
CSV and PDF files are produced in your own browser and saved wherever you choose. They are never uploaded anywhere. Once exported, a file contains permission data about your site, and keeping it safe is in your hands.
Third parties
None. The app has no sub-processors, no analytics, no error-reporting service and no advertising. It sets no cookies of its own. It declares no external domains, which means it cannot reach any service outside Atlassian even if it tried — a property Atlassian verifies from the app's manifest rather than taking our word for it.
Where the data lives
The app uses Atlassian's hosted compute and storage exclusively, so data stays in the same region as your Confluence site and follows Atlassian's data residency for that site. There is nothing to configure.
Keeping and deleting
The single stored record is overwritten each time a new report is generated. When the app is uninstalled, Atlassian removes the app's stored data as part of its own storage lifecycle: the data is first marked deleted and then purged after a retention period defined by Atlassian, during which a recovery request would be possible. That retention is Atlassian's platform behaviour, not ours — we hold no copy and have nothing to delete on our side.
Your rights
Because we never receive your data, requests to access, correct, export or delete personal data are answered by your own Confluence administrator and by Atlassian, who hold it. If you believe this app has caused personal data to be handled incorrectly, write to us at the contact address above and we will investigate. We answer from privacy@onrecordlabs.com.
Changes to this policy
If the app ever starts handling data differently, this page is updated before that version is released, and the effective date at the top changes. Previous versions are visible in the page's public history.