← Back

Privacy Policy

Last updated: February 26, 2026

1. Introduction

This Privacy Policy explains how CodeDoc AI for Confluence ("the App"), developed by Janek Behrens ("we", "us", "our"), handles data when installed on your Atlassian Confluence Cloud instance. We are committed to protecting your privacy and being transparent about our data practices.

2. Bring Your Own Key (BYOK) Model

CodeDoc AI operates on a Bring Your Own Key principle. You provide your own API keys for AI services (Anthropic, OpenAI, or Google AI) and access tokens for Git hosting providers (GitHub, GitLab, Bitbucket, or Azure DevOps). The App uses these credentials solely to perform the functions you initiate. We do not have access to your API keys or tokens — they are stored in your Confluence instance's encrypted Forge storage and are never transmitted to us.

3. Data We Access

The App accesses the following data solely to provide its functionality:

4. Data We Store

The App stores the following data using Atlassian Forge Storage (hosted and managed by Atlassian within your Confluence Cloud instance):

We do not store your source code or the generated documentation content. Source code is read, processed, and discarded within a single job execution. Generated documentation is written directly to Confluence.

5. Data We Do NOT Collect

6. Third-Party Data Transmission

When you run a documentation job, the App transmits data to the following third-party services using your own credentials:

Important: Each third-party provider has its own data handling and retention policies. We have no control over how your Git provider or AI provider processes, stores, or retains data sent to them. You are responsible for reviewing and accepting the terms and privacy policies of the services you connect.

We do not send data to any services beyond those you explicitly configure. No data is transmitted to our own servers or any other third party.

7. Data Processing Location

The App's backend logic runs entirely within the Atlassian Forge runtime environment as part of the Atlassian Forge platform. Data is processed on Atlassian's infrastructure. Outbound connections are made only to the Git and AI providers you configure, using Forge's allowlisted external fetch mechanism.

8. Data Retention

9. GDPR Compliance

The App does not collect or process personal data. Configuration data stored in Forge Storage does not contain PII. Since we do not collect personal data, GDPR data subject requests (access, rectification, erasure, portability) are not directly applicable to the App's own storage.

However, if your source code or generated documentation contains personal data, please note that this data is transmitted to your AI provider as part of the generation process. Review your AI provider's GDPR compliance and data processing agreement before processing code that contains personal data.

If you have any GDPR-related concerns, please contact us at the email address below.

10. Security

The App follows Atlassian Forge security best practices:

For comprehensive details, see our Security Statement.

11. Children's Privacy

The App is a business productivity tool and is not directed at children under 16. We do not knowingly collect data from children.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be reflected in the "Last updated" date above. Continued use of the App after changes constitutes acceptance of the updated policy.

13. Contact

For questions or concerns about this Privacy Policy, contact us at:
Email: support@janekbehrens.de