Privacy policy
This policy explains how ERD Studio for Confluence (the "app") handles data. The app is made by Liam Wynne, a sole trader in Australia (ABN 94 885 368 933), referred to here as "we" or "us". We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
In short: the app runs entirely on Atlassian Forge. It reads diagram files from the GitHub repositories your organisation chooses, stores what it needs in Atlassian's Forge storage for your site, and sends data to nobody except GitHub. We don't sell data, use it for advertising, or run analytics or tracking.
Where the app runs
The app is an Atlassian Forge app. Its code runs on Atlassian's infrastructure, and everything it stores is kept in Forge storage for your Confluence site, in the region Atlassian hosts your site's app data. We run no servers or databases of our own for the app. Atlassian's handling of that infrastructure is covered by the Atlassian Privacy Policy.
What the app accesses
| Data | Why |
|---|---|
Files in the .erd-studio/ folder of GitHub repositories your organisation installed our GitHub App on |
To render the diagram a page editor chose. The app reads only .json domain files, layers.json
and logical-models/*.yml under .erd-studio/. |
| Repository, branch and file names in those repositories | To fill the dropdowns in the macro settings for page editors. |
| Your Atlassian account ID, and whether you're a site admin or can edit the current page | To check permissions before an admin changes the GitHub connection or an editor previews a diagram. Atlassian provides this with each request. We don't store it. |
| The Confluence admin's GitHub identity (username and avatar), during the one-time "Find installations" step | To ask GitHub which installations that person can access, so one company can't connect another company's installation. The GitHub sign-in token is held by Atlassian Forge's built-in authentication, not by us. |
The app doesn't read Confluence page content, attachments or comments, other than the macro's own settings.
What the app stores
All of it is in Forge storage for your site:
| Data | How long |
|---|---|
| The linked GitHub installation ID and the GitHub account (organisation) name | Until an admin disconnects GitHub or uninstalls the app |
| Short-lived GitHub installation access tokens, in Forge's encrypted secret storage | Less than one hour each |
| A cache of each rendered diagram, keyed by repository, file and commit | Replaced when the branch moves to a new commit. Deleted when the app is uninstalled |
The macro's settings (repository, branch, file and height) are saved in the Confluence page itself, like any other macro. Anything a reader does while viewing a diagram, such as moving tables, stays in their browser and isn't saved.
Who we share data with
- GitHub (GitHub, Inc.), to read your repository files. The app calls only
api.github.comandgithub.com, using access your organisation granted by installing our GitHub App, limited to the repositories you selected and to read-only access. On the admin page, the connected GitHub account's avatar image loads straight fromavatars.githubusercontent.com. See the GitHub Privacy Statement. - Atlassian, which hosts the app and provides its storage, logging and billing.
We share data with nobody else, unless the law requires it.
What we can see
We don't routinely look at your data. Atlassian gives us operational logs and error reports for the app, which can include identifiers such as your site URL, repository or file names, and Atlassian account IDs. We use them only to run and support the app. Atlassian provides licensing and billing information (such as your site and the licence status) through the Marketplace. If you email us for support, we keep that correspondence to help you.
Deleting data
- Disconnect GitHub on the app's admin page to delete the stored installation link.
- Uninstall the app from Confluence. Atlassian deletes the app's Forge storage for your site according to Forge's data retention rules.
- Revoke access on GitHub by uninstalling the "ERD Studio for Confluence" GitHub App from your organisation. The app can then no longer read anything.
Security
GitHub access tokens are narrowed to one repository and read-only, expire within an hour, are kept in encrypted storage, and never reach the browser. The GitHub App's private key is an encrypted Forge variable. Every backend function checks licence and permissions itself. To report a security issue, email liam@w2solutions.ai.
Your rights and contact
You can ask us about, or ask us to correct or delete, personal information we hold about you by emailing liam@w2solutions.ai. If you're unhappy with our response, you can contact the Office of the Australian Information Commissioner. If you're in the EU or UK, you also have rights under the GDPR, and you can contact us at the same address.
Changes
If we change this policy, we'll update the date at the top. If a change materially affects how the app handles your data, we'll also note it on the app's Marketplace listing.