Privacy Policy: Specpane: OpenAPI Viewer for Confluence
Effective date: September 29, 2026
This policy explains what information the Specpane: OpenAPI Viewer for Confluence app (the "App") handles, where it goes, and how long it's kept. The App is provided by Brain Static Threads ("we", "us").
Summary
- The App runs entirely on Atlassian Forge, Atlassian's hosted app platform. We run no servers of our own, and we can't access your Confluence content or the App's stored data.
- The App reads API specification files you choose to display, and stores only what it needs to show them.
- The App contacts only GitHub, GitLab and Bitbucket, and only when a page uses a Git source.
- We don't sell data, show ads, or use tracking or analytics of our own.
Information the App handles
| Information | Why | Where it's kept | How long |
|---|---|---|---|
| API spec files attached to Confluence pages | To display them | Not stored. Read when the page is viewed, using the viewer's own Confluence permissions. | Not retained |
| API spec files from Git repositories | To display them | Forge storage, as a short-lived cache for files up to 200 KB | 5 minutes |
| Git connection details (name, provider, allowed spaces, creation date, and for Bitbucket API tokens the account email) | So admins can manage connections | Forge storage | Until an admin deletes the connection or the App is uninstalled |
| Git access tokens | To read files from private repositories | Encrypted Forge secret storage. Never sent to the browser. | Until an admin deletes the connection or the App is uninstalled |
| Macro settings (spec source, repository, path, display options) | To remember how each viewer is set up | Saved by Confluence as part of the page | As long as the page exists |
| Error logs | To diagnose failures | Atlassian's Forge logging. Logs record errors, never spec contents or tokens. | Per Atlassian's log retention |
The App receives Atlassian account IDs and site details as part of the Forge platform context, but doesn't store them.
Third parties
- Atlassian hosts the App and its storage on Forge. Atlassian's privacy policy applies to its handling of data. Forge storage follows your organization's Atlassian data residency settings.
- GitHub, GitLab and Atlassian Bitbucket. When a viewer uses a Git source, the App's backend requests the configured file from the provider's API. The request includes the repository, branch and file path, plus the access token if a connection is used. Each provider's own privacy policy applies to those requests.
No other third parties receive data from the App.
Our access to your data
We can't browse your Confluence content or the App's Forge storage. If your administrators allow log sharing for the App (an Atlassian Administration setting), we can see the App's error logs to help with support. Admins can turn log sharing off at any time.
Security
- Access tokens are stored as Forge secrets and read only by the App's backend.
- Only Confluence administrators can create, change or delete Git connections.
- Connections can be limited to specific spaces, and the limit is enforced on the server.
- Attachments are read as the viewing user, so the App never shows a file that user couldn't open.
Deleting data
- Git connections and tokens: deleted immediately when an admin deletes the connection.
- Cached specs: expire after 5 minutes.
- Everything else: when the App is uninstalled, Atlassian removes the App's stored data under Forge's data retention practices.
Your rights
Depending on where you live, you may have rights to access, correct or delete personal data. The only personal data the App stores is the optional Bitbucket account email on a Git connection, which your Confluence administrator can change or delete. For anything else, contact us at support@brainstaticthreads.com.
Data Processing Addendum
For customers subject to the GDPR or UK GDPR, our Data Processing Addendum sets out our obligations as a processor.
Children
The App is a business tool and isn't directed at children under 16.
Changes
We'll post updates to this policy at https://brainstaticthreads.com/specpane/privacy/ and change the effective date above. Significant changes will also be noted in the App's Marketplace release notes.
Contact
Brain Static Threads support@brainstaticthreads.com