Privacy policy: Quicksloth Q&A for Confluence

Last updated: 9 October 2026

In short: the app runs entirely on Atlassian Forge. It has no servers of its own and does not send data outside Atlassian. Your questions, answers and comments are saved in your Confluence site; a search index and the votes are saved in a database that Atlassian hosts for your installation. We do not receive copies of your content. What does reach us is listed in section 4.

1. Who we are

The app is made by Quicksloth, the brand name of Alfredo Onori, an independent software developer based in Italy ("we", "us"). Contact: support@quicksloth.dev.

This policy covers the app "Quicksloth Q&A for Confluence" for Confluence Cloud. Our website and support email are covered by the website privacy notice. Atlassian, which runs Confluence and the Forge platform, processes data under its own terms and the Atlassian privacy policy.

2. What the app stores and where

In your Confluence site

These are saved through Confluence's own interfaces, with the permissions of the person using the app, and follow your Confluence site's settings and data residency:

In the app's Forge SQL database

Atlassian hosts one database for each installation of the app, on Atlassian's infrastructure. Forge hosted storage follows the data residency location of your Confluence site. The database holds:

The app stores no email addresses and no passwords or tokens. Names appear only where users type them, for example in an @mention.

3. How the app uses the data

For this content your organization decides how Confluence and the app are used. The app processes the content only inside Atlassian's platform, on your organization's behalf.

4. What reaches us

App logs
The app writes short technical log lines on the Forge platform, which Atlassian makes available to us to fix problems. We designed them to contain content IDs, HTTP status codes, counts and error messages, and no question, answer or comment text, names or email addresses. When Confluence rejects a request, the first 500 characters of Confluence's error response are logged. Logs are available to us for 30 days. Atlassian shares them with us by default; a site admin can turn off our access to your site's logs in Atlassian Administration.
Information from Atlassian about your installation and license
Atlassian gives us information about installations and licenses: for example the site address, app version, license type and status, user tier and, for paid licenses, the organization name and the names and email addresses of the technical and billing contacts. We use it only to manage licenses, to give support and to contact those people about important changes to the app. We do not use it for marketing and do not sell or share it.
Platform usage metrics
Atlassian shows us aggregate usage of the app (such as the number of function calls, their duration and errors) to monitor the app and its costs.
Support requests
If you email us, we receive what you send. See the website privacy notice.

We do not access your Confluence content or the app's database directly, and we do not share data with any third party other than Atlassian.

Legal basis and transfers. For the data that reaches us (logs, installation and license information, usage metrics and support emails) we are the controller. Legal basis: performing the license agreement with your organization (GDPR Article 6(1)(b)) and our legitimate interest in keeping the app working, secure and supported (Article 6(1)(f)). Atlassian may process data outside the European Economic Area, including in the United States, under safeguards recognised by the GDPR such as the EU Standard Contractual Clauses or the EU-US Data Privacy Framework (see Atlassian's privacy policy). Our email provider, Migadu, is based in Switzerland, which the European Commission recognises as providing adequate data protection.

5. How long data is kept

6. Security

7. Your rights and requests

Your organization's Confluence admins control the content in your site and can help with most requests about it. You can also write to us at support@quicksloth.dev. Under the GDPR you can ask for access, correction, deletion, restriction or portability of your personal data and object to its use. You can complain to a data protection authority; in Italy this is the Garante per la protezione dei dati personali.

8. Changes to this policy

If the app starts storing or using data in a different way, we will update this policy before releasing that version and change the date at the top. Significant changes will also be mentioned in the release notes of the app on the Atlassian Marketplace.