Link Steward for Confluence / Release 1.0

Link Steward privacy notice

Effective for release 1.0. Provider: Mikhail Eshchenko. Privacy contact: support@misheno.com. Provider identity is also available in the Atlassian Marketplace profile.

Processing to provide the app

Link Steward reads published Confluence pages, their link destinations, page identifiers, titles, owners and the current user's access permissions. It uses this information to check destinations, show accessible results, maintain owner queues and perform replacements explicitly requested by a user with the required permissions.

Page bodies, titles, link URLs, owner names, email addresses and account IDs are not saved in Link Steward's KVS records or application logs. They are processed transiently in Forge and the user's app view. A signed replacement preview contains the requested old/new URLs, the requesting account ID and page snapshot hashes; it is held in the user's app view, expires after ten minutes and is not stored in KVS.

The app stores page and space identifiers, hashes of links, classifications, HTTP status codes, work states, timestamps, run status and settings in Forge KVS. Settings include the site origin and enabled/excluded domain names. A reminder record may contain the identifier of the app's last comment. An installation secret signs replacement previews. No analytics, advertising, tracking pixels or external identity provider are included.

External requests

External checking is disabled until a space administrator enables exact public hostnames. A check sends the link path and query to that destination through HTTPS without Confluence cookies, user credentials or authorization headers. Each redirect is checked against the same domain and address policy. Obvious credential-bearing parameters are rejected, but an administrator must still consider what information their URLs contain.

Cloudflare's public DNS-over-HTTPS service receives enabled hostnames to resolve public IP addresses. The DNS request does not include the page title, owner, link path or query. The destination website and DNS service operate under their own terms and privacy policies. The app's public-address check is an additional control; it is not a guarantee of DNS pinning through Forge's outbound proxy.

Native reminders, when enabled, create Confluence comments mentioning the current page owner. Confluence handles notification delivery and watcher preferences. These comments remain page content until removed using the permissions and controls available in Confluence.

Retention, access and deletion

Scan results and work-state records expire after 30 days; settings remain until a space administrator deletes them. A reminder suppression record lasts seven days. An administrator can clear a space's app data from Settings even if the subscription is inactive. CSV exports are files downloaded and controlled by the exporting user.

After uninstall, Forge applies Atlassian's storage retention and recovery process. Uninstalling the app does not guarantee immediate deletion from platform backups. See Forge hosted storage data lifecycle.

Access to results is rechecked through the current Confluence user. Page ownership is read when the queue is displayed. The provider may access diagnostic logs made available under Atlassian's app support controls; application diagnostics contain error stages and codes, not URL contents or page bodies. Information a customer voluntarily sends to support is separate from automatic app storage and should be limited to what is needed to resolve the request.

Platform and privacy requests

Forge provides app compute, storage, identity and tenant isolation. External checking sends data outside Atlassian, so this product does not claim Runs on Atlassian eligibility or that all processing stays in a selected data residency region. Requests about customer-controlled Confluence content should also be directed to that customer's administrator. For a privacy request to the provider, identify the installation and the request without sending passwords or access tokens.