Privacy Policy

ISA/IEC 62443 Compliance Tracker · The Bent Spatula · Last updated 6 September 2026

Summary. This app does not collect, store, transmit, or share any personal data. It runs entirely on Atlassian infrastructure and holds no data of its own.

What the app does with your data

The app is an Atlassian Forge app. It runs inside Atlassian's cloud platform and communicates only with the Jira and Confluence REST APIs of the site it is installed on. When you use it, the app:

All of this happens against your own Atlassian site. Nothing is sent anywhere else.

What the app stores

Nothing. The app has no database and does not use Forge storage. Everything it produces - issues and pages - lives in your own Atlassian instance and is owned and controlled by you.

Because nothing is stored, there is no data to export, retain or delete on uninstall. Removing the app leaves the issues and pages it created in place, under your control.

Third parties

None. The app makes no external network calls and integrates with no third-party services, analytics or trackers. It declares no remote hosts in its manifest.

The app qualifies for Atlassian's Runs on Atlassian programme, which requires that an app processes and stores data only within Atlassian's own infrastructure.

Permissions

The app requests only the Atlassian API scopes it needs, each used solely for the purpose described:

ScopePurpose
read:jira-workList projects and issue types; detect already-created requirements
write:jira-workCreate the epics and tickets you request; link them to guide pages
read:space:confluenceList Confluence spaces you can choose from
read:page:confluenceDetect guide pages that already exist
write:page:confluenceCreate implementation-guide pages you request

The app requests no user-directory scope. It never reads, searches or stores a user record, and every issue it creates is unassigned.

The app never deletes anything, and never changes an issue's fields - no summary, description, status or assignee is ever modified. It writes in only two other ways: attaching a Confluence guide link to a ticket that does not have one, and refreshing the "Requirement enhancements in scope" section of a guide page so that raising your Security Level keeps it accurate. That section is bounded by markers and is left alone if anyone has edited inside it. Everything else you write is untouched.

Your rights

Since the app holds no personal data, there is no data held about you to access, correct or erase. Data inside your Atlassian site remains subject to your own agreement with Atlassian.

Changes

Any change to this policy will be published on this page with an updated date.

Contact

support@thebentspatula.com