Privacy policy
Runbooks for Confluence and Jira is developed and maintained by an individual developer, Ram Sundaram. Write to support@apps.sundar.am with any privacy question.
What the app does
The app turns a Confluence page carrying a structured checklist into a versioned procedure, runs it as a tracked checklist from a Jira or Jira Service Management work item, detects when the source page has changed since a run started, and reports procedures nobody has run or reviewed in a while.
Where your data is stored
The app is built on Atlassian Forge and keeps all of its data in Forge's own hosted storage inside your Atlassian site. It has no servers of its own, makes no calls to any address outside Atlassian, and holds no copy of your data anywhere else.
Data residency follows Atlassian's programme. Forge's data residency page states: "Every persistent Forge hosted storage capability is data residency-enabled: the Key-Value Store, the Custom Entity Store, Forge SQL, and the Forge Object Store." Your data stays in the location Atlassian pins for your site, and moves with it if Atlassian migrates it.
What personal data the app collects, and why
| What | Why | Where it is kept |
|---|---|---|
| Your Atlassian account ID | To record who started a run, who marked a step done, skipped or failed, and who marked a procedure reviewed. This is the audit trail of who did what and when. | On each run event, and in a register of every account ID the app has stored |
| Notes you type against a step | So a responder can record what they observed while running a procedure. | On the run event for that step, up to 2,000 characters |
| A salted one-way hash of your account ID | To recognise a repeated request, so that clicking a button twice does not start two runs. Because the app keeps the salt, the hash still counts as personal data, and it is erased along with your account ID. | In short-lived records that prevent duplicate actions |
| The content of your procedure pages (titles, steps, instructions) | This is the procedure itself: the app exists to store and version it. | In procedure and procedure-version records |
| Jira and Jira Service Management work item IDs and keys | To attach a run to its work item and to check you may see and act on it. | On the run record |
The app does not collect your name, email address, IP address, or any device or location information.
What the app logs
Operational logs record identifiers, version numbers, error codes, and how far behind the app's page-capture process is running. They never contain your step notes or the text of your procedures.
Notes are free text, and anyone could type another person's name or details into one. The app does not scan notes for that, so please leave other people's personal details out of them.
Who can see your data
Only people who can already view the Confluence page and edit the Jira or Jira Service Management work item can see the procedure, its runs, and the notes on them. The app checks this on every read and every action, and never shows data to someone who could not already see it in Confluence or Jira. The app's Rovo agent is held to the same checks: it can find, start or report on only the procedures and runs you yourself may see.
How long data is kept
- Records that exist only to prevent duplicate actions are deleted automatically after seven days.
- The app reports the account IDs it stores to Atlassian's personal data reporting service, on the cycle Atlassian sets, as every Forge app storing account IDs must.
- If your Atlassian account is closed, the app erases your data over the following few days. It replaces your account ID on run events with the word "erased", clears the notes you wrote, deletes the records carrying your salted hash, and then removes its own register entry once it has confirmed nothing is left. This normally completes within about three days.
- Procedure history is otherwise kept for as long as the app is installed, since the app exists to keep a version history of your procedures and a record of every run. A run's history is the audit record and is not deleted on a schedule; it is anonymised as above if the person who acted is later erased.
If you uninstall the app
Removing the app from Confluence, with or without the optional Jira part, starts an erase of notes and account IDs within the time Atlassian allows for this step, about 55 seconds. Removing only the Jira part while keeping Confluence erases nothing, since your procedures and their history stay in use on Confluence. Whatever that erase does not reach is soft-deleted by Atlassian on its own systems and kept for the retention period Atlassian sets; the app does not control that later retention.
If your site reinstalls within 21 days, Atlassian may relink it to its earlier hosted data. Anything already erased stays erased. The app's register entry for your account resumes the next time you take an ordinary action in the app, and not before. An account already closed through the personal data reporting cycle stays closed.
Your rights
You can ask to see, correct or delete the personal data the app holds about you by writing to support@apps.sundar.am. Most of what the app stores is either your organisation's own procedure content or an audit trail your organisation may need to keep, so some requests may need to go through your Atlassian site administrator. Closing your Atlassian account, or your organisation uninstalling the app, erases your personal data as described above.
Changes to this policy
If this policy changes, the new version will be published at this address with a new "last updated" date.
Contact
Ram Sundaram, developer of Runbooks for Confluence and Jira.
support@apps.sundar.am