Scope and privacy contact
This policy applies to Sallux’s Gatehouse and Page Steward apps. Sallux is responsible for the app-specific processing described here. Atlassian separately operates the Forge platform and Marketplace under Atlassian’s own terms and policies.
Privacy questions, access or correction requests, and complaints may be directed to the Sallux Privacy Officer at drew@sallux.dev. We may need to verify the requester and the applicable Atlassian installation before responding.
Where the apps run
Both apps run on Atlassian Forge. They do not use a Sallux-operated remote backend, external analytics service, advertising network, generative-AI provider, or external data store. App processing and storage occur within Forge and the customer’s Atlassian Cloud environment. No external egress domains are configured.
Gatehouse for Jira
Gatehouse reads Jira issue fields requested by the configured readiness rules when a user opens a Gatehouse surface or a configured workflow transition is evaluated. Those issue fields are evaluated transiently and are not stored by Gatehouse.
Gatehouse stores an installation- and project-scoped readiness policy and its update timestamp in Forge hosted storage. It does not persist Jira issue content, issue keys, Atlassian account IDs, profile data, email addresses, or user-behaviour analytics.
Page Steward for Confluence
Page Steward performs a bounded metadata scan of current Confluence pages. It does not request or read page bodies, comments, or attachments.
It stores a minimized Forge-hosted review index containing page ID and title, native relative link, space details, latest update time, labels needed for configured exclusions, whether owner metadata exists, classification and reason codes, scan timestamps, scan state, and policy. It does not persist owner or author account IDs, display names, or email addresses.
Sharing and sale
Sallux does not sell end-user data, share it with advertisers, or send it to third-party subprocessors selected by Sallux. Atlassian provides Forge hosting and Marketplace services. Customer administrators control installation and Atlassian permissions.
Operational logs
Application logs are limited to operational event names, scan run IDs, counts, status codes, and safe error codes. They are designed not to contain issue descriptions, page bodies or titles, project or issue identifiers, names, email addresses, credentials, or API tokens.
Retention and deletion
Gatehouse policy remains in installation-scoped Forge storage until replaced or the app’s installation data is deleted. Page Steward reconciles its index to the latest completed scan and removes obsolete page records. Uninstallation and recovery of Forge hosted data are governed by Atlassian’s then-current Forge retention behaviour.
An authorized customer administrator may contact Sallux for assistance with an app-specific privacy request. Because the apps do not operate a remote Sallux database, many installation-data controls remain with Atlassian and the customer’s site.
Security, international processing, and changes
The apps use Forge authentication, least-privilege scopes, server-side authorization checks, bounded inputs, dependency review, and automated tests. Atlassian determines the locations and data-residency options available to Forge customers. We do not claim that the apps independently provide legal or regulatory certification.
We may update this policy when app functionality, data practices, Marketplace requirements, or applicable law changes. Material changes will be reflected by the updated date above and communicated where required.
