Data Access and Storage

This app runs entirely within the Atlassian Forge platform, leveraging Forge’s secure execution environment.

We do not store or transmit any user data outside of Atlassian infrastructure.

All access to Confluence content (such as diagrams and attachments) is performed securely through Atlassian’s REST APIs with the minimal required OAuth scopes.

We do not persist any personal or sensitive information on our own servers or any third-party services.

Permissions and Scopes

Our app requests the minimum required permissions to function as intended within the Atlassian ecosystem, including but not limited to Confluence and Jira.

Permission scopes are limited to:

We do not request administrative scopes, global access, or any elevated privileges unless explicitly required by a specific feature—and only with full user consent.

All permissions are defined transparently in the app manifest and enforced through Atlassian Forge’s secure runtime and API boundaries.

Data Handling and Privacy


The app is designed in compliance with Atlassian’s Data Security Policy, and follows the principles of GDPR and data minimization.

Vulnerability Management

We proactively monitor for vulnerabilities through:

We are committed to resolving security issues quickly and delivering updates through the Marketplace in a timely manner.

Reporting Security Issues

If you discover any security vulnerabilities or concerns, please contact us at:

📧 [experts@hktx.cn]

We will respond to all valid reports within 2 business days and prioritize critical issues immediately.