Bespoke Jira Charts & Reports for Confluence — Privacy Policy
Effective date: 2026-08-31 Last updated: 2026-08-31
This privacy policy describes how Bespoke Jira Charts & Reports for Confluence ("we", "us", "the app") handles your data. Bespoke is an Atlassian Marketplace app distributed via the Atlassian Forge platform. By installing Bespoke, you agree to this policy.
Summary in plain English
- All data stays inside Atlassian's infrastructure. Bespoke performs all chart aggregation inside Atlassian's Forge runtime. No End-User Data is transmitted to any third party or outside Atlassian's infrastructure.
- We don't operate any servers. Bespoke runs on Atlassian Forge — Atlassian hosts every function call.
- The app stores nothing. A chart's definition — its search, chart type, grouping, and colors — lives inside the Confluence page's own macro parameters, stored and encrypted by Atlassian as ordinary page content. Bespoke has no database of its own.
1. Data we access
Bespoke is designed to collect and store nothing.
When you view a Confluence page containing a Bespoke chart, the app reads only what is needed to render that one chart, as the person viewing the page:
From your Atlassian site (read on your behalf, with your own Jira permissions)
- The work items matching the chart's JQL search or saved filter, via
POST /rest/api/3/search/jql— fetching only the group-by and stack-by field values needed to build the chart (capped at 5,000 work items per chart) - The saved filter's JQL, via
GET /rest/api/3/filter/{id}, when the chart is built from a saved filter rather than raw JQL - The Jira field list, via
GET /rest/api/3/field, used only inside the chart-builder panel to populate the "Group by" and "Stack by" pickers
That data is processed in memory to produce grouped counts, rendered as a chart. The result is shown to you immediately and discarded. No work-item content, no field values, and no identifiers are written to disk, cached, transmitted off-platform, or retained between page views.
The app accesses no other data — not your account profile beyond what Jira's own permission model already exposes, not group memberships, not Confluence page content beyond the macro's own parameters, not space metadata, not search history, not edit history.
2. Where data is stored
Bespoke stores nothing in Forge Key Value Store or any other Forge storage module. There are no entities — no user records, no cached chart data, no scan history, no audit log. Forge storage is unused by the app.
A chart's configuration (its JQL or filter ID, chart type, group-by/stack-by fields, top-N setting, colors, title) is stored by Confluence itself, as the macro's parameters within the page's own content — the same place Confluence stores every other macro's settings. Bespoke never writes this configuration anywhere else.
Data residency: because Bespoke stores nothing of its own, there is no separate data-residency question for the app. Confluence page content (including macro parameters) follows Atlassian's data residency commitments for your site.
3. Data we share with third parties
None. The app makes no external network calls of any kind. It has no analytics provider, no error reporting service, no AI vendor, no marketing tools, and no integrations with anything outside Atlassian Forge.
The only APIs the app contacts are Atlassian's own Jira REST APIs (search/jql, filter/{id}, field) via Forge's internal request proxy — Atlassian-operated endpoints inside Forge's runtime, not an external service. No End-User Data ever leaves Atlassian's infrastructure.
3a. Account actions and data changes
None. The app has no write permissions to Jira, makes no changes to any account or work item, and writes no data anywhere outside the Confluence page's own macro parameters, which Confluence — not Bespoke — stores. It is a read-only charting tool.
4. Data we do NOT collect
- Work item contents beyond the specific field values needed to group a chart (comments, attachments, descriptions are never read)
- Confluence page contents beyond the chart macro's own parameters
- User passwords or authentication tokens
- Behavioral or telemetry data about how you use Bespoke
- IP addresses or geolocation
- Cookies (Bespoke runs inside Atlassian's iframe — Atlassian's cookies apply, not ours)
5. Data retention
Bespoke stores no data of its own — there is nothing to retain. Every chart's data is fetched and aggregated in memory on page view and discarded immediately. The only persisted state is the chart's own configuration, which lives in Confluence page content and is retained or deleted exactly as that page is.
On uninstall: Atlassian automatically purges any Forge storage associated with the app within 30 days per Atlassian's Forge data lifecycle policy. Because Bespoke uses no Forge storage, this has no practical effect — there was nothing to purge.
6. Your rights
You have the right to:
- Access a chart's configuration — visible and editable directly in the macro's config panel
- Delete a chart's configuration by deleting the macro from the page, or by uninstalling Bespoke entirely
For requests under GDPR, CCPA, or similar regulations, contact us at support@taskhooker.com.
7. Children's privacy
Bespoke is a business reporting tool for Atlassian Cloud organisations. It is not intended for, marketed to, or used by individuals under 18. We do not knowingly collect data about minors.
8. Changes to this policy
We may update this policy when materially new features ship. The "Last updated" date at the top reflects the most recent change. Material changes will be communicated via the Marketplace listing and any in-app notice we deem appropriate.
9. Contact
For privacy questions:
- Email: support@taskhooker.com
- Website: https://bespoke.taskhooker.com
- Address: Melbourne, Australia