Privacy Policy
Effective 24 August 2026
This policy covers the FolioCradle apps distributed for Atlassian products and this website. It is written to be read, not to be survived; where a section can honestly say "none," it says none.
1. The short version
Our apps run on Atlassian Forge, inside Atlassian's own infrastructure. We operate no servers. Your Confluence content is never transmitted to us or to any third party, and we store none of it. We use no analytics or tracking, in the apps or on this site.
2. Who we are
FolioCradle is operated by James Graham, a sole proprietor in California, USA ("we", "us"). Contact: support@foliocradle.com.
3. Content in your Atlassian site
To do their job, our apps read and write the pages you point them at. This happens entirely within Atlassian's infrastructure using Atlassian's own APIs. Specifically:
- We receive no content. The apps declare no external network permissions, which means the Forge platform blocks outbound network requests from them. There is no technical path by which your page content could reach us or a third party.
- We store no content. The apps use no database, key-value store, cache or file storage. Page content is held in memory only for the duration of a single request, then discarded.
- We keep no logs of your content. We have no logging infrastructure. Atlassian may retain platform-level operational logs under its own policies, which we do not control and cannot read your content through.
- Access is limited to yours. The apps act as the signed-in user, not as a privileged service account. Existing page and space restrictions apply unchanged: the app cannot read or edit anything you could not read or edit yourself.
4. Permissions the apps request
Atlassian shows these when you install. They are the minimum the functionality requires:
| Permission | Why |
|---|---|
read:page:confluence | Read the pages in scope so changes can be previewed. |
write:page:confluence | Write the changes you approve, and only those. |
read:space:confluence | Resolve a space key to the pages it contains. |
search:confluence | Resolve a CQL query when you scope a run that way. |
5. Information we do collect
We collect nothing automatically. The only personal information we hold is what you choose to send us:
- Support correspondence. If you email us, we keep your message and address in order to reply and to keep a record of the issue. We do not use it for marketing and we do not sell or share it.
- Marketplace records. If you purchase through the Atlassian Marketplace, Atlassian handles the transaction and provides us with limited licensing information (such as your organisation's name and licence status) so that we can support the account. Atlassian's handling of that data is governed by its own privacy policy. We never receive your payment details.
6. This website
This site serves static pages only. It sets no cookies, runs no analytics, and loads no fonts, scripts, or images from other domains. Our hosting provider processes standard server request data (such as IP address and user agent) for delivery and security, as any web host must.
7. Sub-processors
We use no sub-processors for customer content, because we never receive customer content. Our infrastructure providers are Atlassian (which hosts and runs the apps) and our website host. Email you send us is handled by our email provider.
8. Retention
Customer content: not retained, because it is never received. Support correspondence: kept while it is useful for support history, and deleted on request. Marketplace licensing records: kept while the licence is active and for a reasonable period afterwards for accounting purposes.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, or port personal information we hold about you, and to object to certain processing. Since the only such information is normally your support correspondence, these requests are easy to honour — email support@foliocradle.com and we will respond within 30 days. We do not sell personal information, and we do not "share" it for cross-context behavioural advertising as defined under California law.
10. Children
These are workplace administration tools. They are not directed at children and we do not knowingly collect information from anyone under 16.
11. Security
The strongest security property here is structural rather than procedural: data we never receive cannot be breached from us. Beyond that, the apps run within Atlassian Forge and inherit its platform security model, including its authentication, tenancy isolation and egress controls.
12. Changes
If this policy changes materially, we will update the effective date above and, where the change affects how customer data is handled, note it on this page.
13. Contact
Questions about this policy: support@foliocradle.com.