Specvane for Confluence: Privacy Policy
Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company
This policy explains what information the Specvane app for Confluence Cloud (the "App") processes, where it is kept, and your rights. It covers only the App. Atlassian's products are governed by Atlassian's own privacy policy.
1. Summary
- The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). It has no servers of its own and sends no data to Great Work or to any third party. It does not fetch URLs and never calls the APIs described in your specs.
- The App stores nothing. It has no app storage at all.
- OpenAPI and Swagger files are ordinary page attachments. The App reads them through Confluence's API, as the person viewing the page, with that person's Confluence permissions.
- Great Work LLC cannot see your Confluence content or your specs.
2. What the App processes
| Data | Why | Where it lives |
|---|---|---|
OpenAPI/Swagger files attached to the page (and other attachments they reference with $ref) | Downloaded and rendered as documentation in the viewer's browser | Your Confluence site, as normal attachments. The App keeps no copies |
| Specs you paste or upload in the macro editor | Saved as a page attachment (or a new version of one) so they live in Confluence with history | Your Confluence site |
| Macro settings (file name, version, layout, display toggles, tag filters) | Stored by Confluence in the page like any other macro setting | Your Confluence site |
| Parameter values and request bodies you type into the request builder | Turned into a code snippet in your browser so you can copy it | Your browser only, discarded when you leave the page |
| PDF/Word export | When a page is exported, the App's export function reads the spec as the exporting user and returns document content to Confluence | Your Confluence site (the export file) |
| License status | Checked on each use so unlicensed sites see a notice | Provided by Atlassian, not stored |
The App does not collect names, email addresses, IP addresses, passwords, API tokens, payment
information or analytics. Credentials in request snippets are placeholders such as $TOKEN;
the App never asks for real ones. It sets no cookies and loads no third-party scripts. Links in
spec descriptions open only when you click them.
3. Where data is processed
All processing happens in your browser and on Atlassian's Forge platform, subject to Atlassian's data residency settings. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors for the App.
4. Support requests
If you contact us (help desk or hello@greatwork.company), we receive what you send: your name, email address, site URL and the content of your message. We use it only to answer you, keep it for up to 24 months after the request is closed, and never sell it. Please do not send us specs that contain secrets; a short excerpt or the spec check output is usually enough.
5. Your rights
Because the App stores no personal data, uninstalling it is all that is needed to stop all processing. For support records you can ask us for access, correction or deletion at hello@greatwork.company. We respond within 30 days. EU/UK and California residents have the rights given by GDPR/UK GDPR and the CCPA/CPRA; we honor them for every customer.
6. Security
The App uses only the Confluence scopes it needs (read attachments, download attachments, upload attachments for the paste feature, read page titles). Every request runs as the signed-in user, so the App can never show someone a spec on a page they cannot open. Security issues: hello@greatwork.company (subject "Security"). We follow Atlassian's vulnerability fix timelines.
7. Children
The App is a business tool and is not directed to children under 16.
8. Changes
We will post changes here and update the effective date. Material changes are announced in the Marketplace release notes at least 30 days ahead.