Sift — Table Filters, Pivots & Charts for Confluence — Privacy Policy
Effective date: 2026-09-01 Last updated: 2026-09-01
This privacy policy describes how Sift — Table Filters, Pivots & Charts for Confluence ("we", "us", "the app") handles your data. Sift — Table Filters, Pivots & Charts for Confluence is an Atlassian Marketplace app distributed via the Atlassian Forge platform. By installing Sift — Table Filters, Pivots & Charts for Confluence, you agree to this policy.
Summary in plain English
- All data stays inside Atlassian's infrastructure. Sift — Table Filters, Pivots & Charts for Confluence performs all analysis inside Atlassian's Forge runtime. No End-User Data is transmitted to any third party or outside Atlassian's infrastructure.
- We don't operate any servers. Sift — Table Filters, Pivots & Charts for Confluence runs on Atlassian Forge — Atlassian hosts every function call and storage write.
- All stored data is encrypted at rest in Forge's Key Value Store, tied to your Atlassian Cloud site. It is never logged or returned to any third party; all processing happens inside Atlassian's Forge runtime.
1. Data we access
Sift — Table Filters, Pivots & Charts for Confluence is designed to collect and store nothing.
When you view a Confluence page containing the Sift macro, the app reads only the content needed to render that macro's table or chart:
From your Atlassian site (via Forge asUser() calls)
- The body of the current page, so the app can locate the table the page editor selected as the data source and read the macro's saved configuration
- The page's attachments list, so the macro editor can offer attached CSV/TSV/JSON files as data sources
- The content of one attachment — the CSV, TSV, or JSON file the page editor selected as the data source (up to 4 MB), if the macro uses a file source
Every read runs with the viewing user's own permissions. If the viewer cannot see the page or the attachment, the app cannot read it either, and shows a "No permission" message instead of data.
That content is processed in memory to apply the saved filters, compute any pivot, and render the table and/or chart. The result is shown immediately and discarded. No rows, no cell values, no file contents, and no identifiers are written to disk, cached, transmitted off-platform, or retained between page views.
The macro's saved settings — the chosen source, filters, pivot, and display options, plus any small pasted dataset — live inside the page content itself as ordinary macro configuration, stored by Confluence exactly like any other macro on the page. The app itself stores nothing anywhere.
The app accesses no other data — not your account profile, not group memberships, not other pages, not space metadata, not search history, not edit history.
2. Where data is stored
Sift — Table Filters, Pivots & Charts for Confluence stores the following entities in Forge Key Value Store, hosted and encrypted by Atlassian:
Sift stores nothing in Forge Key Value Store. There are no entities — no user records, no cached datasets, no scan history, no audit log, no settings. Forge KVS is unused by the app. The macro's configuration is saved by Confluence within the page itself, like any macro.
Forge Key Value Store data is encrypted at rest by Atlassian using AES-256 and tied to your Atlassian Cloud site. Sift — Table Filters, Pivots & Charts for Confluence operates as a tenant inside this storage; we cannot access the data without going through Forge's authenticated APIs invoked by an admin user of your org.
Sift — Table Filters, Pivots & Charts for Confluence performs all analysis inside Atlassian's Forge runtime. No End-User Data is transmitted to any third party or outside Atlassian's infrastructure.
Data residency: Forge storage follows Atlassian's data residency commitments. If your Atlassian site is in a specific data region, Sift — Table Filters, Pivots & Charts for Confluence's storage stays in that region.
3. Data we share with third parties
None. The app makes no external network calls of any kind. It has no analytics provider, no error reporting service, no AI vendor, no marketing tools, and no integrations with anything outside Atlassian Forge.
The only APIs the app contacts are Atlassian's own Confluence REST APIs (page content and attachment reads) via Forge's internal proxy — Atlassian-operated endpoints inside Forge's runtime, not external services. No End-User Data ever leaves Atlassian's infrastructure.
3a. Account actions and data changes
None. The app has no write permissions, makes no changes to any account or content, and writes no data anywhere — not in Confluence, not in Forge Storage, not in any external system. It is a read-only table, pivot, and chart tool. There is no audit log because there is nothing to audit.
4. Data we do NOT collect
- Issue contents, comments, attachments
- Document contents (Confluence pages, JSM tickets, JPD ideas)
- User passwords or authentication tokens beyond what you explicitly provide via Settings
- Behavioral or telemetry data about how admins use Sift — Table Filters, Pivots & Charts for Confluence
- IP addresses or geolocation
- Cookies (Sift — Table Filters, Pivots & Charts for Confluence runs inside Atlassian's iframe — Atlassian's cookies apply, not ours)
5. Data retention
Sift stores no data — there is nothing to retain. Every table and chart is computed in memory on page view from the page's own content or its attachments, and discarded immediately. There are no working records, no audit log, no API keys, and no settings stored by the app anywhere.
On uninstall: Atlassian automatically purges all Forge storage associated with the app within 30 days per Atlassian's Forge data lifecycle policy.
5a. Automatic erasure on Atlassian account closure
Sift — Table Filters, Pivots & Charts for Confluence implements Atlassian's personal-data reporting flow. Once a week, Sift — Table Filters, Pivots & Charts for Confluence posts the list of Atlassian accountIds for which it stores personal data to Atlassian's report-accounts endpoint. If Atlassian responds that an account has been closed (the user has exercised right-to-erasure, or the account has been permanently deactivated) or updated (data is stale or the user requested a refresh):
There is nothing for Sift to erase on account closure — the app stores no accountId, no displayName, no email, and no per-user records of any kind. The weekly report-accounts post returns an empty list because there is no personal data tracked to report.
You can also trigger the same erasure path for any user by clearing their entries through any in-app "Clear all data" developer tool, or by uninstalling Sift — Table Filters, Pivots & Charts for Confluence entirely.
6. Your rights
You have the right to:
- Access the data Sift — Table Filters, Pivots & Charts for Confluence stores — visible in the in-app screens
- Export any in-app audit log as CSV (where the app exposes one)
- Delete all data via any in-app "Clear all data" developer tool, or by uninstalling Sift — Table Filters, Pivots & Charts for Confluence
- Be erased automatically when Atlassian flags your account as closed (see section 5a)
For requests under GDPR, CCPA, or similar regulations, contact us at support@taskhooker.com. The automatic erasure flow runs weekly; if you need faster action, email us and we'll process the deletion manually.
7. Children's privacy
Sift — Table Filters, Pivots & Charts for Confluence is a business administration tool for Atlassian Cloud organisations. It is not intended for, marketed to, or used by individuals under 18. We do not knowingly collect data about minors.
8. Changes to this policy
We may update this policy when materially new features ship. The "Last updated" date at the top reflects the most recent change. Material changes will be communicated via the Marketplace listing and any in-app notice we deem appropriate.
9. Contact
For privacy questions:
- Email: support@taskhooker.com
- Website: https://sift.taskhooker.com
- Address: Melbourne, Australia