ARKRON

Loading

Arkron
Talk to Arkron

ConfiSense Privacy Policy

1. About this policy

Effective date: 1 October 2026

This policy explains what information ConfiSense handles, why, where it is kept, who can see it and how long it is kept.

ConfiSense is an app for Jira Cloud. It runs on Atlassian's Forge platform. Your organisation installs it from the Atlassian Marketplace.

This policy covers the ConfiSense app only. Atlassian's own products are covered by Atlassian's privacy policy.

In this policy, "your organisation" means the company that installed ConfiSense on its Jira site. "You" means that organisation, or a person who uses ConfiSense on its behalf.

2. Who we are

ConfiSense is developed and operated by Arkron Pty Ltd (ABN 93 698 430 438), based in Melbourne, Australia. In this policy, "Arkron", "we" and "us" mean that company.

Arkron is responsible for how ConfiSense handles information. Atlassian is not responsible for Arkron's handling of it.

3. What ConfiSense reads

ConfiSense works on your Jira configuration: how Jira is set up, not the work your teams track in it.

Jira configuration. ConfiSense reads:

  • workflows, with their statuses, transitions and rules;
  • workflow schemes, work item types and work item type schemes;
  • custom fields, with their contexts, options and field configurations;
  • screens, screen tabs and screen schemes;
  • permission schemes, notification schemes, project roles and groups;
  • projects, project categories, components and versions;
  • the names, owners and sharing of filters and dashboards, and board scopes;
  • statuses, resolutions, priorities and Jira events.

Some of this configuration contains names or text your administrators typed, such as a workflow name, a filter name or a value in a workflow rule. ConfiSense stores that text as part of its analysis.

Work item counts. ConfiSense asks Jira how many work items match a query, and Jira returns a number. ConfiSense does not read work item content such as summaries, descriptions, comments or attachments. The counts are made with the app's own access to Jira, so they can cover projects that the administrator using ConfiSense cannot browse.

Jira audit log. ConfiSense reads audit log entries about workflows and workflow schemes to tell whether an analysis is out of date. It keeps the time of its last check, a count of the changes and a marker of the latest change.

Confluence. ConfiSense creates a Confluence space named "ConfiSense" on your site and writes report pages to it. Those pages are stored in your own Confluence site.

Rovo. ConfiSense includes an optional Rovo agent. When someone asks it a question, ConfiSense answers from its stored analysis and does not save the question. Anyone on your site who can use Rovo can see the agent, but it answers only Jira administrators. Rovo is an Atlassian product, and Atlassian's terms apply to it.

What ConfiSense does not collect. It does not ask for or store Atlassian passwords or API tokens. It does not handle payment details; Atlassian handles Marketplace billing.

4. Information about people

ConfiSense keeps as little information about people as it can. It does not store email addresses. It stores Atlassian account IDs only where the table below says so. Names, email addresses and avatars shown on screen are read from Jira when a page is opened.

InformationWhy ConfiSense has itStored by ConfiSense?
Account ID of the administrator who starts a consolidation or rollbackTo show who made the change in HistoryYes
Account IDs of the previous owner, the new owner and the administrator in an ownership transfer, and the display names of the previous and new ownerTo keep the transfer historyYes
Account ID of an administrator using ConfiSenseTo check administrator access and keep their recently viewed itemsYes
Account IDs inside workflow rules, for example a rule that names a specific userThey are part of the workflow configuration ConfiSense comparesYes. They are kept in the workflow analysis and in the consolidation history.
People named in permission schemes and notification schemesThey are part of the configuration ConfiSense comparesNot as an account ID. A code is stored in its place, as described below.
Email addresses named as notification scheme recipientsTo compare schemes and to show the recipient on screenNo. A code is stored for comparison. The address is read from Jira when the scheme is opened.
People's display names shown on screenTo show who a person isNo, apart from the ownership transfer history. Names are read from Jira when a page is opened.
Email address, account type, active status and avatar shown when choosing a person in the Ownership ManagerTo help an administrator pick the right personNo

Jira only gives ConfiSense an email address when the person's Atlassian profile settings allow it.

Codes that stand for people. For people and email addresses named in permission schemes and notification schemes, ConfiSense stores a code in place of the account ID or address. The code is made with a secret key that is created for your site and kept in Atlassian's secret storage for the app. A person's code stays the same from one analysis to the next, so ConfiSense can compare schemes. A code does not name the person, but it stays linked to them, so it is a pseudonym.

Where account IDs appear on screen. Permission scheme details, the workflow comparison view and Rovo answers can show an account ID. History shows the administrator's name, read from Jira.

5. How ConfiSense uses information

ConfiSense uses the information in sections 3 and 4 to:

  • analyse your Jira configuration, find duplicate items and show where each item is used;
  • show the results in ConfiSense, in Config Explorer and through the Rovo agent;
  • make the changes an administrator chooses and confirms: workflow consolidation, rollback, and transferring ownership of filters and dashboards;
  • keep a history of those changes, including who made them, so administrators can review and undo them;
  • publish reports to the ConfiSense Confluence space;
  • remove stored information about a person when their Atlassian account is closed, as section 8 describes;
  • find and fix problems, and answer support requests.

Arkron does not sell information handled by ConfiSense. Arkron does not use it for advertising or marketing. Arkron does not use it to train artificial intelligence or machine learning models.

6. Where information is kept and who can see it

ConfiSense runs entirely on Atlassian's Forge platform. It sends no information to servers run by Arkron or by any other third party.

Where it is kept

  • Forge hosted storage for your site. Settings, analysis results, run records, change history, ownership transfer history and error records. An error record can hold a short piece of the error text Jira returned.
  • Your Confluence site. The report pages ConfiSense writes to the ConfiSense space. ConfiSense puts no names, email addresses or account IDs in them.
  • Forge platform logs. Operational logs with configuration names and IDs, ConfiSense's own run IDs, timings, counts, workflow property values and error messages. Error messages can include text returned by Jira. That text can include Atlassian account IDs and, in rare cases, other details about a person.

If your organisation pins its Jira site to a data residency location, ConfiSense's Forge hosted storage follows that location. Atlassian says Forge data residency does not cover logs.

Who can see it

  • Your Jira administrators. Only Jira administrators can open and use ConfiSense.
  • People with access to the ConfiSense Confluence space. The report pages follow that space's permissions, which your administrators control.
  • Atlassian. Atlassian hosts and runs ConfiSense on Forge and stores its data.
  • Arkron. By default, Atlassian gives app developers access to their app's logs for each site where the app is installed. Your administrators can turn this off in Atlassian's admin settings. Arkron uses logs only to find and fix problems. Arkron staff are based in Australia.
  • Arkron's maintenance function. ConfiSense includes a maintenance function that Arkron support can use to inspect or remove a faulty run record. It works only with a secret token. No token is set in the production version of ConfiSense, so it refuses every call.
  • Support reports. An administrator can download a support report from App Settings and choose to send it to us. It holds run states, error codes, counts, timings, the app version and your site address. It holds no names, email addresses or account IDs.

Arkron shares information with no one else, unless the law requires it.

7. How long information is kept

ConfiSense keeps its stored information for as long as it is installed, with these limits:

  • Analysis results are kept while ConfiSense is installed. For Fields, a newer analysis replaces the older one. For the other areas, earlier analyses are kept as well.
  • Consolidation and rollback records are kept while ConfiSense is installed, so the History page stays complete. A finished consolidation run is reduced to a summary after 30 days, and the summary is kept.
  • Ownership transfer history keeps about the most recent 500 entries.
  • Scheduled scan history keeps about the most recent 30 runs.
  • The administrator access check is kept for 15 minutes.

8. Closed accounts and uninstalling

Closed and changed Atlassian accounts. About once a week, ConfiSense reports to Atlassian the account IDs it stores in its run history, ownership transfer history, administrator access records and recently viewed lists. Atlassian answers with any account that was closed or changed.

  • Closed account. ConfiSense replaces the person's account ID with a placeholder in its run history and ownership transfer history, and clears their name from the ownership transfer history. It deletes their administrator access record and their recently viewed list.
  • Changed account. ConfiSense clears the stored display name in the ownership transfer history and reads it from Jira again when it is next needed.
  • Not covered by this report. Account IDs inside workflow rules, and the codes that stand for people in permission schemes and notification schemes, are not part of the weekly report. They are not removed when an account closes. They are removed when ConfiSense is uninstalled.

When ConfiSense is uninstalled. ConfiSense's Forge hosted storage follows Atlassian's data lifecycle for Forge apps. Atlassian takes the data out of use at uninstall and permanently deletes it at the end of Atlassian's retention period. If ConfiSense is installed again within 21 days, Atlassian can link the earlier data to the new installation on request. The ConfiSense Confluence space and its report pages stay in your site after uninstall. Your administrators can delete them.

Removing ConfiSense's data. Uninstalling ConfiSense removes its stored data as described above. For any question about your data, use the contact details in section 11.

9. Security

  • ConfiSense runs on Atlassian Forge. Atlassian says it encrypts data in Forge app storage at rest and encrypts traffic in transit.
  • Only Jira administrators can open and use ConfiSense. ConfiSense checks the person's Jira administrator permission, and refuses access if the check cannot be completed.
  • ConfiSense changes Jira only after an administrator chooses a change and confirms it. A confirmed change can finish, or roll back, in the background.
  • Scheduled scans are off until an administrator turns them on. Background housekeeping still runs every few minutes: it completes or recovers changes already started, cleans up, and sends the weekly report described in section 8.

No system is completely secure. If a security incident affects your data, we will tell affected customers and Atlassian.

10. Your choices and privacy requests

Your organisation's administrators control how ConfiSense is used. They can:

  • install or uninstall ConfiSense;
  • turn scheduled scans on or off;
  • choose whether to use the Rovo agent;
  • turn off Arkron's access to logs in Atlassian's admin settings;
  • set a data residency location for their Atlassian products.

People can control whether their email address is visible to apps in their Atlassian profile settings.

If you want to see, correct or delete information about you that ConfiSense holds, please contact your organisation's Jira administrator first, because your organisation controls the Jira site. You can also contact us using the details in section 11.

11. Changes and contact

We may update this policy when ConfiSense or the law changes. We will post the updated policy at this address and change the effective date. If a change is significant, we will tell customers and Atlassian.

For privacy or security questions about ConfiSense, contact:

  • Arkron Pty Ltd, Melbourne, Australia
  • Email: vish@arkron.com.au