Privacy policy: Quicksloth Q&A for Confluence
Last updated: 9 October 2026
In short: the app runs entirely on Atlassian Forge. It has no servers of its own and does not send data outside Atlassian. Your questions, answers and comments are saved in your Confluence site; a search index and the votes are saved in a database that Atlassian hosts for your installation. We do not receive copies of your content. What does reach us is listed in section 4.
1. Who we are
The app is made by Quicksloth, the brand name of Alfredo Onori, an independent software developer based in Italy ("we", "us"). Contact: support@quicksloth.dev.
This policy covers the app "Quicksloth Q&A for Confluence" for Confluence Cloud. Our website and support email are covered by the website privacy notice. Atlassian, which runs Confluence and the Forge platform, processes data under its own terms and the Atlassian privacy policy.
2. What the app stores and where
In your Confluence site
These are saved through Confluence's own interfaces, with the permissions of the person using the app, and follow your Confluence site's settings and data residency:
- Questions and answers, saved as Confluence content created by the app: title, text, author, dates.
- Comments, saved as standard Confluence comments.
- Topics, saved as Confluence labels on the questions.
In the app's Forge SQL database
Atlassian hosts one database for each installation of the app, on Atlassian's infrastructure. Forge hosted storage follows the data residency location of your Confluence site. The database holds:
- A search index of questions and answers: content ID, space ID and key, question title, a plain-text copy of the question and answer text (including the display text of any @mentions and the addresses of links), the Atlassian account ID of the author, dates, score, number of answers, accepted answer and status (current or trashed). Comments are not copied.
- Votes: for each vote, the content ID, the Atlassian account ID of the person who voted, the value (up or down) and the date.
- Topics: question ID, topic and space ID, to filter by topic.
The app stores no email addresses and no passwords or tokens. Names appear only where users type them, for example in an @mention.
3. How the app uses the data
- Only to provide its features: showing questions, answers, comments, votes and accepted answers, and filtering, sorting and searching the lists.
- Before any list is shown, the app checks with Confluence, as the person viewing it, which questions that person may see.
- When a question or answer is edited, trashed, restored or deleted in Confluence, Confluence sends the app an event and the app updates its database as the app itself (without a user).
- The app makes no requests outside Atlassian: it has no permission to contact external addresses. It uses no analytics, advertising, tracking or AI services.
For this content your organization decides how Confluence and the app are used. The app processes the content only inside Atlassian's platform, on your organization's behalf.
4. What reaches us
- App logs
- The app writes short technical log lines on the Forge platform, which Atlassian makes available to us to fix problems. We designed them to contain content IDs, HTTP status codes, counts and error messages, and no question, answer or comment text, names or email addresses. When Confluence rejects a request, the first 500 characters of Confluence's error response are logged. Logs are available to us for 30 days. Atlassian shares them with us by default; a site admin can turn off our access to your site's logs in Atlassian Administration.
- Information from Atlassian about your installation and license
- Atlassian gives us information about installations and licenses: for example the site address, app version, license type and status, user tier and, for paid licenses, the organization name and the names and email addresses of the technical and billing contacts. We use it only to manage licenses, to give support and to contact those people about important changes to the app. We do not use it for marketing and do not sell or share it.
- Platform usage metrics
- Atlassian shows us aggregate usage of the app (such as the number of function calls, their duration and errors) to monitor the app and its costs.
- Support requests
- If you email us, we receive what you send. See the website privacy notice.
We do not access your Confluence content or the app's database directly, and we do not share data with any third party other than Atlassian.
Legal basis and transfers. For the data that reaches us (logs, installation and license information, usage metrics and support emails) we are the controller. Legal basis: performing the license agreement with your organization (GDPR Article 6(1)(b)) and our legitimate interest in keeping the app working, secure and supported (Article 6(1)(f)). Atlassian may process data outside the European Economic Area, including in the United States, under safeguards recognised by the GDPR such as the EU Standard Contractual Clauses or the EU-US Data Privacy Framework (see Atlassian's privacy policy). Our email provider, Migadu, is based in Switzerland, which the European Commission recognises as providing adequate data protection.
5. How long data is kept
- Content in Confluence (questions, answers, comments, topics) is part of your Confluence site and stays there until someone deletes it with Confluence's tools, under your site's own retention settings. Uninstalling the app does not ask us to delete it, and after uninstalling the app can no longer reach it.
- Forge SQL database: kept while the app is installed. When a question or answer is deleted in Confluence, the app removes its index entry, its votes and, for a question, its topics; a trashed item is kept but hidden until it is restored or deleted. When the app is uninstalled, Atlassian marks the database for deletion and deletes it after its retention period; if requested within 21 days, it can be relinked to a new installation. See Atlassian's hosted storage data lifecycle.
- App logs: available to us for 30 days.
- Installation and license information: kept while it is needed to manage the license and give support, and longer only where the law requires it.
6. Security
- Data is stored and processed on Atlassian's Forge platform and in your Confluence site; we run no servers and keep no copies.
- Every action a person takes runs with that person's own Confluence permissions. Votes and accepted answers are checked on the server side, never trusted from the browser.
- To report a security issue, email security@quicksloth.dev.
7. Your rights and requests
Your organization's Confluence admins control the content in your site and can help with most requests about it. You can also write to us at support@quicksloth.dev. Under the GDPR you can ask for access, correction, deletion, restriction or portability of your personal data and object to its use. You can complain to a data protection authority; in Italy this is the Garante per la protezione dei dati personali.
8. Changes to this policy
If the app starts storing or using data in a different way, we will update this policy before releasing that version and change the date at the top. Significant changes will also be mentioned in the release notes of the app on the Atlassian Marketplace.