Attachment Guard โ€” Privacy Policy

Last updated: 21 August 2026

Provider: Alzhan Group LLC

Contact: support@alzhangroupllc.com

What this app is

Attachment Guard is an Atlassian Forge app for Confluence Cloud. It records which attachments are checked out, detects when a checked-out attachment is overwritten, and keeps a history of those events.

Where your data is held

Attachment Guard is built on Atlassian Forge and runs entirely on Atlassian's infrastructure. It stores data in Forge storage, within your Atlassian environment.

The app operates no servers of its own and transmits no data to any third party. It makes no outbound network requests outside Atlassian's own APIs.

What the app stores

Check-out records, for each file currently checked out:

History records, for each check-out, release, override and restoration:

Names are not stored. To show readable names instead of account IDs, the app looks up a display name from Confluence while rendering a screen and discards it immediately afterwards. No name is written to storage at any point. Check-out and history records hold Atlassian account IDs only.

Notification timestamps, used to avoid sending repeated notices about the same file.

What the app does not store

The app does not read, copy or store the contents of your attachments, except transiently during a restore, when it retrieves an earlier version of a file from Confluence and uploads it back to Confluence as a new version. That content is not retained by the app.

The app does not store names, email addresses, page content, or any credentials. It stores Atlassian account IDs, which identify an account without disclosing anything about the person holding it.

Who can see it

Only users of your Confluence site, subject to Confluence's own permissions. The app requests only the Atlassian permissions listed on its Marketplace listing, and acts as the signed-in user when reading your content, so it cannot show anyone a file they could not already open.

Retention and deletion

Records are kept while the app is installed so the history remains available for audit purposes.

On uninstall, the app loses access to your site and the Forge storage for that installation is soft deleted by Atlassian. Deletion is per installation: each site's data sits in that site's own Atlassian app partition, so removing the app from one site does not affect another.

Two details a compliance reviewer will want stated plainly:

Soft-deleted data is then retained for the remainder of the period set by Atlassian's Standard Data Retention and Disposal policy, described in Atlassian's SOC 2 report. That schedule is Atlassian's rather than ours โ€” we operate no storage of our own, so there is no copy of your data anywhere for us to retain or delete.

Reference: https://developer.atlassian.com/platform/forge/storage-reference/hosted-storage-data-lifecycle/

To request deletion of specific records while the app is installed, contact support@alzhangroupllc.com.

Changes

Material changes to this policy will be reflected on the Marketplace listing before they take effect.

Contact

Alzhan Group LLC

Houston, Texas, United States

support@alzhangroupllc.com

Attachment Guard is operated from the United States. If your procurement or vendor-assessment process requires a registered postal address on a contract or data processing agreement, email us and we will provide it.