← Docgrity home

Docgrity Privacy Policy & Data Statement

Last updated: 5 September 2026

Who we are

Docgrity is published by Ujjavala Singh ("we"). Contact: see the support details on our Atlassian Marketplace listing or GitHub profile.

The short version

What data the app processes

DataWhere it livesPurpose
Page text, titles, version historyForge SQL (your site's Forge storage, Atlassian-hosted)scanning for duplicates/contradictions/open questions
Text embeddings of page contentForge SQLcandidate-pair selection
Findings, evidence quotes, audit logForge SQLthe product
Contributor account IDs and display namesForge SQLpotential-owner inference (labelled potential)
Your AI provider API keyForge KVS secret storagecalling your AI provider; never logged, never shown in the UI, never stored in SQL
Provider/model choice, thresholdsForge KVSconfiguration

All of the above is stored in Atlassian's Forge platform storage, scoped to your installation, and is deleted by Atlassian when you uninstall the app, per the Forge data lifecycle.

What leaves Atlassian

Only requests to the AI provider you configured, containing the page text being analysed. Egress is platform-enforced (Forge manifest allowlist) to:

Only the one provider you select is ever called. Review your chosen provider's data-use terms (e.g. API-tier no-training commitments) — your key, your terms.

What we collect

Nothing. We have no backend, no telemetry endpoint, and no access to your site, content, findings, or keys.

App logs

Like all Forge apps, diagnostic logs (errors and operational messages emitted by the app's functions) are collected by the Atlassian Forge platform, and we can read them to troubleshoot issues. These logs are engineered to never contain page content, personal data, or API keys — provider error messages are truncated and keys are never logged. Site admins can disable our log access, or view and download the logs at any time from admin.atlassian.com.

Permissions (Confluence scopes)

Security measures

Data subject rights & retention

Docgrity stores no personal data outside your Atlassian site. Contributor names/IDs mirrored into findings are removed when findings are deleted or the app is uninstalled. In line with Atlassian's Forge user privacy guidelines, a scheduled job runs weekly inside your installation to keep this data accurate: stored display names are refreshed from the current Atlassian profile, and all stored personal data for an account is automatically erased when that Atlassian account is closed or its data is erased. For rights requests concerning Confluence data itself, contact your Atlassian admin; for the AI provider, see that provider's policy.

Changes

We will update this page and the "last updated" date when practices change.