Privacy notice
How Claervo PII Guard reads Jira and Confluence content to find personal data and secrets, what it stores, and how nothing leaves your Atlassian site.
Effective · 8 September 2026
Provider and contact
Claervo provides Claervo PII Guard for Jira & Confluence. Privacy and data-rights requests can be sent to support@claervo.com. The Atlassian site owner remains the controller of the content the app scans; Claervo has no access to your site.
Product boundary
The app is built on Atlassian Forge. Compute, the Custom UI and app storage run inside Atlassian's environment for your site. The app declares no egress permission: it cannot send data to Claervo or to any third party.
Data the app reads
To detect sensitive data the app reads, as the app and only within the scope you configure:
- Jira: work item summaries, descriptions, comments and custom text fields, plus project keys and names.
- Confluence: page and blog post titles and bodies, comments, plus space keys and names.
- The account id of the administrator using the app, for the audit trail.
Data the app stores
App data is stored with Atlassian Forge storage in your site's region, separately for the Jira and the Confluence installation.
- Findings: item id and title, project or space, field name, detection rule, severity, confidence, a masked sample (first and last two characters), a one-way SHA-256 prefix of the value, occurrences, timestamps and status.
- Policy: enabled rules, custom patterns, allowlist entries (exact values are stored as hashes), scope and field selection.
- Settings, daily count snapshots and audit records of scans and administrator actions.
Data the app does not collect
The app never stores the detected value itself, the surrounding text, attachments, user names or e-mail addresses of Atlassian users, and it performs no analytics, advertising or profiling.
What the app writes
Only when an administrator chooses an action: replacing detected values with redaction markers in the affected field, adding a review label, or applying a Jira security level. Nothing is written automatically.
Retention and deletion
Data lives in Forge storage while the app is installed. Settings → Reset app data removes everything immediately; uninstalling the app deletes all stored data.
Sub-processors and rights
There are no sub-processors: Atlassian hosts the app under the Atlassian Cloud Terms of Service. Access, correction and deletion requests about app data can be fulfilled by the site administrator from the app, or sent to support@claervo.com.