Privacy policy: Restriction Manager for Confluence

Last updated: 2026-09-30

This policy explains what data the Restriction Manager for Confluence app ("the app") handles, where it is kept and for how long. The app is made by Zach Whritenour, doing business as Keyward Labs ("we", "us"), 307A Awdry Way, Manassas Park, VA 20111, USA. Contact: privacy@keywardlabs.com.

Summary

What the app reads

To do its job, the app reads the following from your Confluence site through Atlassian's APIs:

What the app stores

The app stores the following in Atlassian's Forge hosted storage, which belongs to your site's installation of the app:

Data Contents Kept for
Space settings Whether inheritance is on, the inheritance mode, the account ID of the person who last saved the settings, and when Until changed, or until the app is uninstalled
Activity log For each change the app made: page ID, page title, the reason, and the users (account IDs) and groups allowed to edit before and after 90 days
Background job records Progress of bulk actions and audits: counts, error messages, and the account IDs of the people who started or cancelled them 30 days
Audit results For each restricted page: page ID, title, parent page ID, and the users (account IDs) and groups allowed to view and edit Until the next audit of that space replaces them, or until the app is uninstalled

Audit results and the activity log are shown only to admins of the space they belong to.

When a space admin applies restrictions to existing pages or fixes pages from the audit, the app may act as that admin, through Atlassian's user impersonation for apps, for one purpose only: to add itself to the edit restrictions of pages someone restricted without it. It can only do what that admin is allowed to do, and the activity log records each such page.

Personal data

Atlassian account IDs are personal data. As Atlassian requires, the app reports the account IDs it stores to Atlassian every week. When Atlassian tells the app that an account has been closed, the app erases that account ID from everything it stores.

Where data is kept

All stored data stays in Atlassian's cloud, in Forge hosted storage for your site. It is covered by Atlassian's security, encryption and data residency controls for Forge apps. We have no separate copy of it.

Diagnostic logs

When the app runs, it writes short diagnostic log lines: page IDs, space keys, timings and what the app did. They contain no names, page content or account IDs. Atlassian makes these logs available to us so we can support you. Your site admin can switch log sharing off at any time.

Who we share data with

We don't sell data or share it with anyone. The only processor is Atlassian, which hosts and runs the app as part of Forge (Atlassian's privacy policy). If you contact us for support, we use what you send us only to help you.

When you uninstall the app

When the app is uninstalled, Atlassian deletes its stored data. If the app is reinstalled within 21 days, Atlassian can reconnect the old data. After that, the data is disposed of under Atlassian's data retention policy.

Page restrictions the app has set stay on your pages after you uninstall it. They are ordinary Confluence restrictions, and you can change them in Confluence as usual.

Your rights

You can ask us about the data the app holds, or ask for it to be corrected or deleted, at privacy@keywardlabs.com. Most requests are quicker to handle yourself: space admins can change settings in the app, and uninstalling the app deletes its data. We answer requests within 30 days.

Changes to this policy

If we change this policy, we will update the date at the top and post the new version at https://keywardlabs.com/restriction-manager/privacy. Material changes will also be noted in the app's release notes.