Spillproof for Confluence and Jira: Privacy Policy
Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company
This policy explains what information the Spillproof app for Confluence Cloud and Jira Cloud (the "App") processes, where it is kept, and your rights. It covers only the App, not Atlassian's products, which are governed by Atlassian's own privacy policy.
1. Summary
- The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). It has no servers of its own and sends no data to Great Work or to any third party. It uses no AI service.
- It reads Confluence and Jira content to look for sensitive data, in memory, inside Atlassian.
- It never stores a value it finds. For each finding it keeps a masked preview (for example "Visa ending 4242") and a keyed fingerprint (an HMAC-SHA256 digest with a random key created for your site and kept in your site's app storage) so it can recognise the same value again.
- Great Work LLC cannot see your content, your findings or your settings.
2. What the App processes
| Data | Why | Where it lives |
|---|---|---|
| Titles and bodies of Confluence pages, blog posts and comments; Jira summaries, descriptions, environment, text custom fields and comments | To look for sensitive data | Read in memory while scanning; not stored |
| Each finding: product, space or project key and name, page or issue id, key, title and link, where in the item it was found (for example "Comment by Dana"), the author's Atlassian account id, the type of data, severity, confidence, the masked preview, the keyed fingerprint, how many times it appears, first and last seen times, status and who changed it | To show findings to admins and reviewers, track fixes, and notify people if you turn that on | Forge SQL for your site, until uninstall |
| Values marked "not sensitive": masked preview, fingerprint, type, reason, who and when | So the same value is not reported again | Forge SQL for your site, until removed or uninstall |
| Scan jobs: product, which spaces or projects, progress counters, times, who started it | To run and show full scans | Forge SQL for your site, until uninstall |
| Settings: enabled detectors, custom patterns, exclusions, reviewer and digest recipient account ids, digest target | To apply your admins' choices | Forge app storage |
| The site's fingerprint key | To compute fingerprints | Forge app storage, never shown or exported |
The App does not collect email addresses, IP addresses, passwords for your account, API tokens, payment information or analytics. It sets no cookies and loads no third-party scripts.
3. Optional features that write to your site
Only when an admin turns them on: an email to the author of a finding and a weekly digest, sent by your own Jira through its issue notification feature (masked values only); a weekly digest written to a Confluence page your admin picks; a Jira issue property holding the number of open findings (searchable with JQL) and a Jira label. When a reviewer clicks Redact or Restrict page, the App edits that page, comment or issue, or its restrictions, as that reviewer.
4. Where data is stored
All App data is stored by Atlassian in Forge storage (Forge SQL and Forge app storage) for your site, subject to Atlassian's data residency settings. When the App is used in both Confluence and Jira, all of its data is stored in your Confluence site's data residency location (Confluence is the App's required product), per Atlassian's multi-app rules. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors.
5. Who can see what
- Confluence and Jira admins, and reviewers they name in the App's settings, see the findings dashboard and exports.
- Anyone who can see a page or issue can open "Sensitive data check" on it and see the masked findings for that page or issue only.
- Great Work LLC: no access. If you open a support request, we see only what you send us.
- Atlassian: as the platform operator, under Atlassian's privacy policy.
6. Retention and deletion
Findings stay (open, fixed or ignored) so you have an audit trail, until the App is uninstalled. Findings for deleted pages and issues are closed automatically. Uninstalling the App removes its Forge storage according to Atlassian's Forge data deletion process. Emails, labels, issue properties and digest page versions already written are ordinary Jira and Confluence content and are not removed.
7. Support requests
If you contact support through our help desk or by email, we process what you send (name, email, message, attachments) only to answer you, keep it up to 24 months, and delete it sooner on request. Please do not send us the sensitive values the App found.
8. Your rights
Depending on where you live (for example EU/UK GDPR or US state privacy laws), you may have the right to access, correct, delete or port personal data and to object to processing. For data in your Atlassian site, your organization (the Atlassian customer) is the controller and Atlassian processes it on your behalf; your admins can uninstall the App. For support data, Great Work LLC is the controller: email hello@greatwork.company. We respond within 30 days.
9. Security
The App uses only Atlassian-hosted compute and storage, never stores found values, keeps admin features in admin-only pages, checks that a person can see a page or issue before showing its findings, and performs edits as the reviewer so Confluence and Jira permissions apply. Report vulnerabilities to hello@greatwork.company.
10. Children
The App is a business tool and is not directed to children under 16.
11. Changes
We will post changes here and update the effective date. Material changes will also be announced in the App's Marketplace release notes.
12. Contact
Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company