Last updated: 2026-07-14
Baselines for Confluence Cloud is a Confluence Cloud app that captures point-in-time snapshots of pages and their attachments. Its user interface runs on Atlassian Forge, and it is served by a backend operated by Plugin Developers on Amazon Web Services (AWS). To create and serve baselines, the app reads your Confluence content and stores baseline records — references to the pages you snapshot (page ID, title, link, path, version and dates), the space involved, your schedules, permissions and settings — in the backend's database. It does not keep a permanent copy of your page bodies: the actual page content and attachments are read from Confluence on demand when you view, compare, export or import a baseline. PDF export sends the assembled content and images to a rendering service (also operated by Plugin Developers on AWS), where the intermediate files are held only transiently and auto-deleted. Our infrastructure sub-processors are Atlassian and AWS. We do not sell or rent your data, and baseline records are removed when you delete them or uninstall the app.
Baselines for Confluence Cloud ("Baselines", the "App") is a content-snapshot and version-tracking app for Confluence Cloud, published by Plugin Developers ("we", "us", "our"). This Privacy Policy explains what data the App accesses and processes, why, where it is stored, and the choices you have. It applies to the Baselines app installed from the Atlassian Marketplace.
In data-protection terms, the Atlassian customer who installs Baselines is the controller of the Confluence data involved; Plugin Developers, through the App, processes that data on the customer's behalf to provide content snapshots, comparison, export, import and scheduling.
Baselines has two parts. Its frontend is an Atlassian Forge app (Forge UI Kit) that runs inside Atlassian's platform. Its backend is a service that Plugin Developers operates on Amazon Web Services; the Forge app communicates with it through Atlassian's Forge Remote mechanism, and the app also serves classic Atlassian Connect pages. This means that, unlike a Forge-only app, Baselines does transmit the Confluence content it needs to your snapshots to a backend that Plugin Developers operates, so it can build, store and serve baselines. We describe that flow honestly below so you know exactly where your data goes.
A baseline is a saved snapshot taken at a moment in time. When you create one, the backend reads the pages you selected (and their attachments) and records what it needs to identify and re-serve them later. When you view, compare, export or import a baseline, the current or captured version of each page is read from Confluence at that time.
Baselines accesses only the data it needs to capture and serve snapshots:
To build, display, compare, export and import baselines, Baselines reads Confluence content — page and blog-post bodies, titles, hierarchy/path, version numbers and modification dates, and the attachments embedded on those pages. This content is read from Confluence at the time it is needed (for example when a baseline is created, viewed, compared, exported or imported).
Baselines reads basic user profile details — such as account ID, display name and avatar — so it can show who created a baseline and present readable names instead of internal account IDs.
Baselines stores the records and settings needed to provide the service: baseline records (for each snapshot: the space, the list of captured items as references — page ID, title, link, type, path, version and dates — the creator's account ID and display details, and creation timing), scheduled-baseline configurations (space, frequency, time, name prefix and date format), permission assignments, and app settings. These records are stored in the backend's PostgreSQL database on AWS. Baseline records reference your pages; they are not a permanent copy of your page bodies.
We process the data above solely to provide the features you installed Baselines for:
We do not use your Confluence data for advertising, profiling, model training, or any purpose other than operating Baselines for you.
Baseline records, schedules, permissions and settings are stored in a PostgreSQL database operated by Plugin Developers on Amazon Web Services. The backend compute that reads your Confluence content and builds baselines also runs on AWS. In other words, to provide baselines, the App transmits the Confluence content it processes to Plugin Developers' AWS backend; we do not claim that your content stays inside Atlassian.
What is persisted in that database is the baseline record — references to your pages and the metadata described above — not a permanent store of your full page bodies. The live page content and attachments are fetched from Confluence on demand for viewing, comparison, export and import, processed to fulfil your request, and not retained as a separate long-term copy beyond the baseline record and any transient files described next.
When you export a baseline to PDF, the backend assembles the pages into a single HTML document (including embedded images and any Jira issue macros) and sends it to a rendering service that Plugin Developers operates on AWS (AWS Lambda with Amazon S3). The rendering service converts the HTML to a PDF and returns it for download. The intermediate files used for a render job are stored transiently in a private S3 bucket and are automatically deleted on a short lifecycle (within one day); they are used only to produce your PDF.
Our infrastructure sub-processors are:
Each processes data under its own terms and security commitments. Baselines does not introduce any advertising or analytics vendor into the handling of your Confluence data.
We do not sell, rent or trade your personal information — including email addresses — and we do not disclose it to third parties, except to the infrastructure sub-processors named above as needed to run the service, or as required by applicable law or regulation. Any non-personal, aggregate information we may handle to operate and improve the service is processed only as described in this policy.
Baselines acts on your behalf using Atlassian's authorization, so it can only read content you are permitted to read, and a baseline only ever captures content the requesting user can access. Import publishes content back to Confluence only when you explicitly choose to, and it creates a new page rather than overwriting existing content.
Baselines requests the Confluence permissions needed to operate:
On the Forge side these correspond to the read, write and act-as-user Confluence scopes; on the Connect side to READ, WRITE and ACT_AS_USER. A Confluence administrator approves these when the app is installed.
Baseline records, schedules, permissions and settings are retained for as long as they exist in the App — that is, until you delete a baseline or a schedule, or uninstall the App. Deleting a baseline removes its record from the backend database. Transient render-job files are auto-deleted on the short S3 lifecycle described above regardless of anything else.
Your underlying Confluence pages, attachments and any pages created by Import remain in Confluence and are unaffected by deleting a baseline, since they belong to your Confluence instance, not to Baselines. If you need your Baselines data removed on uninstall or on request, contact us using the details below and we will action it for the App data we hold.
The Forge frontend runs in Atlassian's platform and authenticates to the backend through Atlassian's Forge Remote mechanism (a platform-issued token). Traffic to the backend and the rendering service is over HTTPS. The rendering service authenticates requests with an API key and restricts outbound fetches, and its intermediate files auto-expire. Access to the backend infrastructure on AWS is restricted to Plugin Developers. See our Security & data residency page for more detail on the architecture and controls.
This policy and our processing of personal data are governed by the laws of the European Union, including the General Data Protection Regulation (GDPR), together with the applicable local laws of the EU member state in which Plugin Developers is established.
Your organisation (the Atlassian customer) is the controller of the Confluence data Baselines processes; Plugin Developers, through the App and its AWS backend, acts as a processor on your behalf, and Atlassian and AWS act as sub-processors. Data subjects can exercise their rights — including access, rectification, erasure and restriction — through your organisation's own Confluence, which remains the system of record for your pages; Plugin Developers will reasonably assist with any such request that reaches us and concerns the App data we hold. Nothing here limits mandatory rights available to you under the data-protection law of your own place of residence.
We may update this Privacy Policy from time to time to reflect changes in the app or in legal requirements. When we do, we will revise the "Last updated" date shown above. Material changes will be reflected on this page.
If you have questions about this Privacy Policy or how Baselines handles data, contact Plugin Developers: