Privacy Policy — Space Access

Last updated: 13 August 2026

Space Access is an app for Confluence Cloud that shows who can reach each space, exports that list, and removes a person or a group from several spaces at once. This page explains exactly what the app stores, where it stores it, and who can read it.

The short version

The app keeps no copy of your permissions and no copy of your people. It reads what it needs from Confluence at the moment a screen is drawn, shows it, and forgets it. The only thing it ever writes down is a log line of a bulk change you made yourself — and that line contains no names.

What the app stores

One thing, and only after you run a bulk change: a history record, held in Atlassian's own storage for your site. Each record contains:

The newest 200 records are kept; older ones are dropped automatically.

Technical error lines. When a call to Confluence fails, the app writes a short diagnostic line into Atlassian's own app logging for your site — for example "the group name lookup was refused (401)". These lines carry no names, no email addresses and no account IDs: identifiers are stripped out before anything is written, and the line is cut short. They exist so a failure can be explained to you, and they are held and deleted by Atlassian, not by us.

What the app never stores

Where the data lives

Everything stays inside Atlassian Forge storage, in the Atlassian cloud region of your own Confluence site. The app is built on Forge and declares no external network access at all, which means the platform physically prevents it from sending anything anywhere. There are no servers of ours involved at any point. Atlassian's own privacy commitments and data residency options apply: see Atlassian's Privacy Policy.

Who can see what

Keeping and deleting data

The newest 200 history records are kept while the app is installed; older ones are deleted automatically.

You do not have to ask us to delete anything. On the app's own screen, anyone who can review space permissions on your site can delete any single history record, or the whole history, at any time. It takes effect immediately and there is no copy to restore from. Because the history is the only thing the app stores, deleting it there is complete.

Uninstalling the app also works: Atlassian deletes the app's storage for your site as part of its normal uninstall process. Permissions that were already changed stay changed — that is a change to your Confluence site, not data of ours.

When an Atlassian account is closed

Once a week, on its own, the app tells Atlassian which account IDs still appear in its history and asks whether any of those accounts have been closed. When one has, the app removes that ID from every history record it appears in: the line then reads that the change was made by someone, with no ID left behind.

The line itself stays. It records what the app changed in your Confluence — which spaces, when, and what was refused — and that is your company's own audit trail, not one person's data. A closed account cannot become a way to erase the record of a change. Anyone who can review space permissions can still delete any record, or the whole log, from the app's own screen at any time.

Nothing on any screen starts this, and no administrator has to remember it. It runs whether anyone is watching or not.

Your rights

If you are in the European Union or the United Kingdom, the GDPR gives you the right to access, correct, export or delete your personal data. The company that installed the app is the data controller. In practice the app holds no personal profile data about you at all — only account identifiers inside your own company's change log — so the quickest route for any request is your own Confluence administrator, who can delete those records from the app's screen in seconds. You can also write to us directly at the address below.

For your legal team, the Data Processing Agreement sets out the same facts in the form the GDPR asks for (Article 28), and applies automatically from installation.

Changes

If this policy changes, the date at the top changes with it and the new version is published here before it takes effect.

Contact

Space Access is supplied by Kauê Natan Gonçalves Bidim, trading as Saoirse Software, in Ireland. Questions about this policy — or a request to see or delete data — go to support@saoirsesoftware.com.