Privacy Policy
Epic Progress for Confluence · Last updated: October 4, 2026
1. Introduction
This Privacy Policy explains how Epic Progress for Confluence ("the App"), developed by Janek Behrens ("we", "us", "our"), handles data when installed on your Atlassian Confluence Cloud site and, optionally, connected to Jira on the same site. The App shows progress bars on Confluence pages. It reads Jira and Confluence data with the permissions of the person viewing or editing the page and never creates, changes or deletes Jira work items or Confluence pages.
2. Data We Access
The App reads the following data live, only to show its macros, and does not keep it unless stated in section 3:
- Jira work items: keys, titles (summaries), status and status category, work item type, parent, due date, story point estimates and whether a work item is flagged. For the optional list of open work items, also the assignee's display name.
- Jira structure: projects (keys and names), releases (names, dates, released or not), saved filters (names), fields and work item types (to find the story point fields and the epic level), and Jira's check of a JQL search entered in the macro settings.
- Confluence: titles and labels of the pages in the chosen scope (Page Progress), space names (space picker), whether the current user may view the page (checked before a snapshot is shown) and whether they may edit it (to publish or remove a snapshot), and, when someone changes the admin switch, whether that person is a Confluence administrator (the operations Confluence allows them; nothing of it is stored). Once a day, the App itself checks whether a page with a published snapshot still exists (see section 7).
Work item descriptions, comments and attachments, and the content of Confluence pages, are never read. Assignee display names are shown live in the list of open work items and are never stored by the App.
3. Data We Store
The App stores only the following, using Atlassian Forge storage, which is hosted and managed by Atlassian for your site:
- Published snapshots, when an editor of a page clicks "Publish snapshot" and, unless the macro settings turn it off, again when an editor opens the page and the snapshot is older than 15 minutes (read with that editor's own Jira permissions; reading a snapshot never causes a Jira request, and "View live" reads Jira with the reader's own permissions). Automatic updates refresh the numbers of what an editor published; new epics, work items or names appear only when an editor updates the snapshot by hand. A snapshot holds the counts behind the bar (done, in progress, to do, flagged, without estimate), the keys and the name of what the macro measures (the epic, the project, release or saved filter, or the epics of a list), with the date and time of publishing. If the editor chose Progress and work items, also statuses, due and release dates, and up to 25 open work items (key, title, status). Each snapshot is stored under the ID of its page and macro, together with a fingerprint of the macro settings it was published for.
- Notes of the automatic update: per snapshot, when it was last checked without changes, and a claim of one minute while an update runs (a random ID, a time and, after a removal, a removal mark), so that only one runs at a time and a removal always wins (no person).
- "Last opened" note: for each macro with a published snapshot, the day it was last opened (a date only, no person). The daily cleanup deletes snapshots whose macro nobody opened for 120 days (section 7).
- App setting: whether published snapshots are allowed on the site (the admin switch).
- Anonymous daily usage counters: per day and site, how often features were used (for example "a macro was opened" or "a snapshot was published"), and whether page views saw an active subscription. No IDs, names, page or Jira content.
- Non-personal cache: the IDs of the site's story point fields (site configuration, refreshed every 6 hours).
A snapshot contains no person fields: no assignees and no account IDs, not even of the person who published it, and no JQL text. Titles and names, however, are free text written by your team: if your team writes personal data into the title of an epic or work item, or into the name of a project, release or filter, a snapshot contains it as written, with Progress only as well as with Progress and work items. The person who publishes decides what to share, and editors of the page can remove a snapshot at any time (“Remove snapshot”).
The macro settings (for example the chosen epic, project, release or filter, a JQL search, labels, titles, notes and manual values) are stored by Confluence itself as part of the page, not by the App, and follow Confluence's own page history and deletion rules.
4. Data We Do NOT Collect
- We do not run any servers. There is no developer-operated backend or database.
- We do not store account IDs, email addresses or avatars of anyone, nor person fields such as assignees (titles in snapshots are kept as your team wrote them, see section 3).
- We do not use cookies, tracking pixels, analytics platforms or advertising networks.
- We do not send any data to external services. The App makes no network calls outside the Atlassian platform.
- We do not read work item descriptions, comments, attachments or page content.
Technical logs and usage counts: Like most Forge apps, the App writes technical log lines (for example "a snapshot was published" or "Jira did not answer") and, once a day, the anonymous usage counters listed above to Atlassian's app logging, which Atlassian makes available to us as the app vendor. Log lines may contain identifiers from your site, namely project keys and page IDs, as well as macro types, counts, HTTP statuses and error codes, but never content, names, email addresses, account IDs, page or work item titles, or JQL text (a JQL search is described only by a hash and its length). We use them only to find errors and to see which features are used.
5. Data Processing Location and Data Residency
All processing occurs within the Atlassian Forge runtime environment under the Runs on Atlassian program. No data is transmitted to servers operated by us or any third party outside the Atlassian platform.
Everything listed in section 3 is stored in Forge hosted storage, which supports Atlassian's data residency: it is held in the same location as your Confluence site, the App's required product, and moves with it when an admin moves the site's data to another location. The technical logs in section 4 are handled by Atlassian's app logging and are not part of the App's stored data.
6. Third-Party Services
The App does not integrate with or send data to any third-party service. It calls no AI service, no analytics service and no advertising network.
7. Data Retention and Deletion
- Published snapshots are kept until a newer snapshot replaces them or an editor clicks "Remove snapshot", which deletes them at once (it needs edit permission on the page only, no Jira access and no active subscription). When an editor opens the published page with "Publish a snapshot" turned off in the macro settings, the snapshot is removed. When their page is moved to the trash or deleted, a daily cleanup deletes them within 24 hours; if the page is restored before that, the snapshot stays. The same cleanup deletes them within 24 hours after an admin blocks the App from the page with an app access rule, and deletes snapshots whose macro nobody opened for 120 days, for example because the macro was removed from the page, the page is no longer read, or view restrictions keep the App itself from reading it.
- Notes of the automatic update are deleted together with their snapshot; a claim left over is deleted by the daily cleanup.
- "Last opened" notes are deleted together with their snapshot, or by the daily cleanup once the macro has no snapshot any more.
- Anonymous daily usage counters are deleted after 8 days.
- The app setting and the story point field cache are kept while the App is installed.
- When the App deletes data, it is removed from Forge storage at once and the App can no longer read it. Atlassian keeps a soft-deleted copy for recovery from accidental deletion until the end of its retention period.
- After you uninstall the App, Atlassian keeps the App's storage, published snapshots included, for 28 days and then deletes it (Data lifecycle for Forge-hosted storage). During that time the App cannot read it. Within 21 days of the uninstall, you can ask us to have Atlassian restore it to a new installation of the App.
8. Personal Data and GDPR
The App stores no personal data of its own about users: no account IDs, email addresses or person fields such as assignees, in snapshots, settings and counters alike. Assignee display names are shown live from Jira and never stored. Titles and names in snapshots are kept as your team wrote them in Jira (section 3); if they contain personal data, editors can remove the snapshot at any time, and Confluence admins can turn snapshots off. Data held by Jira and Confluence themselves, including the macro settings on a page, remains entirely within your Atlassian site and under Atlassian's controls; GDPR data-subject requests relating to it should be directed to your admin or Atlassian. For App-specific concerns, contact us below. After you uninstall the App, Atlassian deletes all App-related data from Forge storage after 28 days (section 7).
9. Security
- Runs in a sandboxed Forge environment with no egress to external networks outside the Atlassian platform.
- Uses minimal API scopes with no write access to Jira or Confluence, plus app storage.
- Reads Jira and Confluence with the permissions of the person viewing the page, so each reader sees only what Jira and Confluence allow them to see.
- Stores no credentials, tokens or secrets; there are none.
See our Security Policy for full details.
10. Children's Privacy
The App is a business productivity tool and is not directed at children under 16. We do not knowingly collect data from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be reflected in the "Last updated" date above. Continued use of the App after changes constitutes acceptance of the updated policy.
12. Contact
For questions about this Privacy Policy, contact us at:
Email: support@janekbehrens.de