Privacy policies/Markdown Toolkit for Confluence

Markdown Toolkit for Confluence — Privacy policy

What this app stores inside your Atlassian tenant, what it only reads in memory, who it shares data with, and how everything is deleted.

Last updated: 28 August 2026 · App: Markdown Toolkit for Confluence · Vendor: SynapseOasis

This policy explains what data Markdown Toolkit for Confluence collects, how it is processed and stored, and the choices available to you. Markdown Toolkit for Confluence exports Confluence content as Markdown — single pages, page trees or entire spaces — and provides an in-page macro that renders Markdown with code highlighting, Mermaid diagrams and math expressions. It also imports a Markdown archive back as Confluence pages, which is the only thing it writes: the pages and attachments an import creates, underneath a page you created yourself in that same run. It cannot delete Confluence content.

Markdown Toolkit for Confluence is built on Atlassian Forge. It runs inside Atlassian's infrastructure and stores its data in your own Atlassian tenant. It makes no outbound network calls to any external service.

1. Data we collect

The data falls into two categories: configuration and results held in app storage, and Atlassian data that is read and processed in memory but not retained.

App storage (persisted inside your Atlassian tenant)

  • Macro content is not stored by the app. The Markdown you type into a Markdown macro is Forge macro configuration, which Confluence keeps with the page itself — the same place a built-in macro's settings live. The app reads it when it draws the macro and writes nothing of its own; it is covered by your Confluence data handling, not ours, and it goes with the page when the page goes.
  • Export jobs — a manifest of what a job covers and the converted page content held in chunks while the job runs and until you download, reset or discard it.
  • Import jobs — the Markdown and the files you upload, held in chunks only while the job runs, plus a record of which page each file became so the hierarchy survives between batches. Both are released when the job finishes.

Transient data (read and processed in memory, not retained)

  • page and space content, titles, labels and attachments read from Confluence during an export
  • the Markdown files and attachments you upload for an import, and the pages and attachments created from them
  • space and page metadata needed to name the files and rebuild the hierarchy

Transient data is read through the standard Atlassian REST APIs, used to produce the result you asked for, and then discarded.

2. Personal data

  • An export processes the content you select, and an import processes the files you upload. During a job, that content — including any personal data your pages happen to contain — is held in app storage inside your tenant until the job finishes and its data is cleared.
  • Macro content is stored as written by the page author.
  • Your Atlassian account ID is stored while an export or an import runs, as the key that keeps your job separate from anyone else's. The record is removed when the job is cleared. The app does not collect email addresses, display names, passwords, authentication tokens, API keys or payment data.
  • Once a day the app sends Atlassian the account ID on each job record it holds, through Atlassian's Personal Data Reporting API, and Atlassian answers with the accounts that have been closed. Nothing else tells an app that a person left. A closed account's job records are deleted, and the account ID on a job record is the only thing about that person the app has to clean up.

3. Storage and retention

All persisted data is stored in Forge app storage (key-value store), provisioned for your installation and located in the Atlassian cloud region of your site. SynapseOasis operates no servers, no databases and no logs outside Atlassian, and has no standing access to your data.

Configuration is retained for the life of the installation. Job data and results are retained until you delete or reset them, until they are replaced by a newer run, or until the app is uninstalled.

4. Data sharing

  • SynapseOasis does not share your data with third parties.
  • There is no sale or transfer of data to third parties.
  • There are no analytics, tracking or telemetry calls to external services.
  • The app makes no outbound network calls at all.
  • All data stays within Atlassian.

5. Security

The app runs inside the Atlassian Forge sandbox and is subject to Atlassian's platform security controls. It requests only the scopes it needs:

  • read:confluence-content.all
  • read:confluence-content.summary
  • read:space:confluence
  • read:page:confluence
  • read:attachment:confluence
  • write:confluence-content
  • write:confluence-file
  • storage:app
  • report:personal-data

Where the app acts on behalf of a user, Atlassian's permission model applies, so it cannot show a user data they could not already see. Administrative functions are restricted to users holding the corresponding Atlassian administration permission. All stored input is validated and size-capped before it is written.

6. Data deletion and retention

Deletion is controlled by the Atlassian platform, not by SynapseOasis. This section describes what actually happens, because the difference matters for a data protection assessment.

  • While the app is installed, you can delete data through the app's own screens, and that deletion is immediate.
  • When you uninstall the app, it runs an uninstall handler that clears its storage. Independently of that, Atlassian detaches the installation's data: it becomes inaccessible to the app, to your users and to us, right away.
  • After uninstalling, Atlassian keeps the detached data for a limited period before destroying it, under Atlassian's own data retention policy. Atlassian's Forge documentation describes the storage as soft deleted on uninstall and retained for 28 days, and separately notes that a re-link request must reach Atlassian within 21 days for previous data to be restored to a new installation. That restore only happens if you ask us to raise the request, with your consent. We never initiate it.
  • Atlassian's backups follow Atlassian's own schedule and are outside any app's control.

The practical consequences: we cannot delete this data faster than Atlassian's process allows, and we cannot read it after an uninstall. If you need specific data gone on a specific date, delete it inside the app before you uninstall.

Atlassian documents this in Data lifecycle for Forge-hosted storage. The retention periods are Atlassian's to change, so treat Atlassian's documentation as the current source rather than this page.

7. GDPR

  • Data minimisation — only the configuration and results needed for the app's function are stored; everything else is processed in memory and discarded.
  • Purpose limitation — data is used solely to provide the app's functionality inside your tenant, and is never sold or transferred to third parties.
  • Data residency — all persisted data remains in your Atlassian tenant on Forge infrastructure, in the Atlassian cloud region of your site.
  • Right to erasure — data can be deleted through the app while it is installed. On uninstall it is detached immediately and then destroyed by Atlassian under Atlassian’s retention policy, as described in the section above.
  • Sub-processors — SynapseOasis uses no sub-processors for app data. Atlassian is the infrastructure provider and processes the data under your existing agreement with Atlassian.

8. Contact

9. Changes to this policy

We may update this policy from time to time. When we do, we revise the last-updated date at the top of this page. We encourage you to review it periodically to stay informed about how Markdown Toolkit for Confluence handles your data.