Attachment Guard โ Privacy Policy
Last updated: 21 August 2026
Provider: Alzhan Group LLC
Contact: support@alzhangroupllc.com
What this app is
Attachment Guard is an Atlassian Forge app for Confluence Cloud. It records which attachments are checked out, detects when a checked-out attachment is overwritten, and keeps a history of those events.
Where your data is held
Attachment Guard is built on Atlassian Forge and runs entirely on Atlassian's infrastructure. It stores data in Forge storage, within your Atlassian environment.
The app operates no servers of its own and transmits no data to any third party. It makes no outbound network requests outside Atlassian's own APIs.
What the app stores
Check-out records, for each file currently checked out:
- Confluence space, page and attachment identifiers
- The file's name
- The Atlassian account ID of the person who checked it out
- The date and time it was checked out
- The attachment version number at that moment
- An optional free-text note entered by that person explaining why
History records, for each check-out, release, override and restoration:
- The same identifiers and file name as above
- The Atlassian account IDs of the people involved
- The date and time
- Attachment version numbers before and after a change
- The optional note described above
Names are not stored. To show readable names instead of account IDs, the app looks up a display name from Confluence while rendering a screen and discards it immediately afterwards. No name is written to storage at any point. Check-out and history records hold Atlassian account IDs only.
Notification timestamps, used to avoid sending repeated notices about the same file.
What the app does not store
The app does not read, copy or store the contents of your attachments, except transiently during a restore, when it retrieves an earlier version of a file from Confluence and uploads it back to Confluence as a new version. That content is not retained by the app.
The app does not store names, email addresses, page content, or any credentials. It stores Atlassian account IDs, which identify an account without disclosing anything about the person holding it.
Who can see it
Only users of your Confluence site, subject to Confluence's own permissions. The app requests only the Atlassian permissions listed on its Marketplace listing, and acts as the signed-in user when reading your content, so it cannot show anyone a file they could not already open.
Retention and deletion
Records are kept while the app is installed so the history remains available for audit purposes.
On uninstall, the app loses access to your site and the Forge storage for that installation is soft deleted by Atlassian. Deletion is per installation: each site's data sits in that site's own Atlassian app partition, so removing the app from one site does not affect another.
Two details a compliance reviewer will want stated plainly:
- Reinstalling does not restore your data automatically.
- For 21 days after uninstallation, a new installation can be relinked to the previous data. That requires your explicit consent and a recovery request raised with Atlassian. We cannot do it unilaterally, and after that window it is not available to us at all.
Soft-deleted data is then retained for the remainder of the period set by Atlassian's Standard Data Retention and Disposal policy, described in Atlassian's SOC 2 report. That schedule is Atlassian's rather than ours โ we operate no storage of our own, so there is no copy of your data anywhere for us to retain or delete.
Reference: https://developer.atlassian.com/platform/forge/storage-reference/hosted-storage-data-lifecycle/
To request deletion of specific records while the app is installed, contact support@alzhangroupllc.com.
Changes
Material changes to this policy will be reflected on the Marketplace listing before they take effect.
Contact
Alzhan Group LLC
Houston, Texas, United States
Attachment Guard is operated from the United States. If your procurement or vendor-assessment process requires a registered postal address on a contract or data processing agreement, email us and we will provide it.