This policy describes how the Definitive Pages app for Confluence Cloud ("the app") protects your data, and how to report a security problem. The app is provided by e360 ("we", "us"). How the app handles data is also covered in the privacy policy.
Summary
- The app runs entirely on Atlassian's Forge platform and in your browser, and is eligible for Atlassian's Runs on Atlassian program.
- Your files are read in your browser and sent only to your own Confluence site. The app makes no network requests outside Atlassian, we run no servers of our own, and we cannot access your content.
- It acts as the signed-in person, so it can only read and change what that person can in Confluence.
Hosting and infrastructure
The app is hosted by Atlassian on its Forge platform; see the Atlassian Trust Center for Atlassian's controls and certifications. The app's screens run inside Atlassian's sandboxed app frame, under a content security policy that blocks outside scripts and connections. The app declares no external domains, remote back ends or web triggers, so there is no route for data to leave Atlassian.
Data the app handles
- The files you choose (Markdown, AsciiDoc, HTML or Jupyter notebooks, as a folder or .zip) are read in your browser and written to Confluence as pages, attachments and labels.
- Import details in Confluence: on each import's top page, a map of which file became which page; on each imported page, a note of its source file. Both are ordinary Confluence content properties.
- A list of recent imports in the app's Forge storage: each import's top page ID, number of pages and time, with only the 50 most recent kept.
- In your browser: the last space you used, and whether you've answered the request for a Marketplace review.
The app stores no names, email addresses or Atlassian account IDs.
Access control
- Your permissions apply. Every read and write of Confluence content is made as the signed-in person, so they can only import into spaces and under pages they can edit. Titles and spaces in the recent-imports list are read with each person's own permissions, so nobody sees imports in spaces they can't open.
- Only the permissions it needs. Reading spaces, pages and their details (for the space and parent pickers, and to check the pages an import created); creating and updating pages, attachments and labels (to write the import); searching (for the parent page picker); app storage (for the recent-imports list); and deleting pages, used only to move a page to Confluence's trash when its source file was removed and you chose that option. Trashed pages can be restored.
- Imported content can't run code. Files are converted to Confluence's own page format. Scripts, styles, forms and embedded objects in HTML are dropped, and only their text is kept.
Authentication
Atlassian handles sign-in. The app has no accounts or passwords of its own, and never asks for API tokens or personal access tokens.
Logging
In production the app writes nothing to its logs, so no file content or personal data ever reaches them.
Secure development
- Every release is checked by automated tests of conversion, importing and re-importing on a test site.
- Test-only code is disabled in production, and each production build is checked for Runs on Atlassian eligibility.
- Dependencies are kept up to date and checked for known vulnerabilities.
- We follow Atlassian's security requirements for cloud apps.
Reporting a vulnerability
If you find a security problem in the app, email support@definitivepages.com with "Security" in the subject. Please include the steps to reproduce it and don't share the details publicly until it's fixed. We acknowledge reports within one business day, keep you updated, and fix confirmed issues within the timeframes Atlassian sets for Marketplace apps.
Security incidents
If a security incident affects your data, we will notify you and Atlassian without undue delay, explain what happened and what we are doing about it, and follow up when it's resolved.
Retention and deletion
Imported pages are ordinary Confluence content: delete or archive them as usual, and their import details go with them. The recent-imports list drops older entries automatically. When the app is uninstalled, Atlassian handles the app's stored data under its Forge data retention policies, and your pages stay.
Contact
Security contact: support@definitivepages.com