OneView for Confluence · by Aryon Forge
Updated July 19, 2026

Privacy Policy

For OneView for Confluence, built on the Atlassian Forge platform by Aryon Forge.

Built on Atlassian Forge No sale of customer data Least-privilege permissions No advertising or profiling
01

Overview

This Privacy Policy explains how OneView for Confluence ("the App") collects, processes, stores, and protects information when used within Atlassian Confluence Cloud.

The App is developed by Aryon Forge and built on the Atlassian Forge platform. Its primary purpose is to let users view and interact with attachments stored on Confluence pages.

By using the App, you acknowledge the data processing activities described in this policy.

02

Contact information

ItemDetails
VendorAryon Forge
Privacy contactsupport@aryonforge.com
Support contactsupport@aryonforge.com
03

Information we process

To provide the App's functionality, OneView may process the following categories of information:

CategoryPurpose
Confluence page metadataIdentify the current page and associated attachments
Attachment metadataDisplay file name, media type, size, and version
Attachment contentRender supported attachments within the viewer when requested by the user
App configurationStore application settings using Atlassian Forge Storage
Macro preferencesStore macro-specific settings, such as pinned attachment selection
Operational logsRecord diagnostic and operational events to support application reliability and troubleshooting

The App only processes information that the current user is authorized to access within Confluence.

04

Purpose of processing

Information is processed solely to provide the features of OneView for Confluence, including:

  • Displaying attachments from the current Confluence page
  • Rendering supported attachment formats
  • Storing application and macro configuration
  • Maintaining application reliability and diagnostics
  • Supporting security monitoring and troubleshooting

Customer data is not processed for advertising, profiling, or marketing purposes.

05

Data storage

Application data is stored using Atlassian Forge hosted storage, where required for application functionality.

OneView does not maintain a separate customer database outside the Atlassian Forge platform for customer content.

Attachment files are processed only when required to render them within the viewer, and are not permanently copied or archived by the App.

06

Data sharing

OneView does not sell or rent customer data. Customer information is not shared with third parties except:

  • As necessary for operation within Atlassian Cloud services
  • When required by applicable law or legal process
  • To protect the security, integrity, or rights of the App, its users, or Atlassian services
07

Data residency & international transfers

The App operates on the Atlassian Forge platform. Data residency, hosting regions, and international data transfers are governed by Atlassian's cloud infrastructure and applicable platform capabilities.

Customers should refer to Atlassian's documentation for information about data residency options available for their organization.

08

Data retention

Data is retained only for as long as necessary to operate the App and fulfill legitimate business or legal requirements.

Data typeRetention
Application configurationRetained while the App remains installed, or until deleted
Macro preferencesRetained until updated or removed
Operational logsRetained only for a limited period required for diagnostics and operational support
09

Security

OneView follows security best practices provided by the Atlassian Forge platform, including:

  • Principle of least privilege when requesting permissions
  • Atlassian-managed authentication and authorization
  • Secure storage using Atlassian Forge services
  • Operational logging for diagnostics and security monitoring

While reasonable safeguards are implemented, no system can guarantee absolute security.

10

Your rights

Depending on applicable privacy laws and your organization's policies, you may have rights to:

  • Request access to personal information
  • Request correction of inaccurate information
  • Request deletion where applicable
  • Request restriction of processing
  • Object to certain processing activities

Requests may be submitted using the contact information below.

11

Changes to this policy

This Privacy Policy may be updated periodically to reflect changes to the App or applicable legal requirements.

The "Last updated" date at the top of this page indicates the latest revision.

12

Contact

If you have questions about this Privacy Policy, or wish to submit a privacy-related request, please contact:

Privacy contact

support@aryonforge.com

Support contact

support@aryonforge.com

13

Release notes

Version history for OneView for Confluence. The most recent release is listed first.

  1. v2.4.0 August 4, 2026 Current

    The viewer no longer opens onto a copy of something you just scrolled past.

    • Images the page displays inline are no longer opened by default. OneView now opens on the first file whose content a reader cannot already see. Previously a page with an inline banner image would often open showing that same image again.
    • A new "Already shown on this page" section collects those images at the bottom of the file list, collapsed, with a count. It expands on one click, and opens automatically when it is the only section or when a file inside it is being viewed.
    • Only genuinely visible content is treated this way. A file attached to a page as a chip — the card showing a file name and a thumbnail — is referenced by the page but not displayed by it, so PDFs, slide decks and documents attached that way stay in their normal type groups.
    • The viewer header now explains the duplicate instead of merely noting it: opening a file through OneView is what writes the audit entry, applies the watermark and enables the SHA-256 integrity check. Confluence's own inline preview does none of those.
    • Nothing is hidden. Every attachment remains listed and selectable — this release changes what is in front, not what is available. Pinned macros are unaffected.
  2. v2.3.0 July 30, 2026

    PowerPoint charts and SmartArt now render; dependency security hardening.

    • The hand-written slide renderer was replaced with a maintained, visually regression-tested library. Charts and SmartArt now render, and fidelity improved across text, tables, bullets, images and gradients.
    • Fixed an intermittent multi-second freeze when moving between slides, caused by a resize feedback loop between the renderer and the Confluence iframe.
    • Resolved a high-severity vulnerability in a transitive dependency (brace-expansion, reachable via the Forge API package), and migrated app storage to the current Forge KVS API in the same change.
    • No known vulnerabilities remain in the app's production dependencies as of this release.
  3. v2.2.0 – v2.2.2 July 30, 2026

    PowerPoint attachments render as real slides rather than extracted text.

    • PPTX previews gained real slide geometry: positioned text with correct size and styling, background colours, embedded images, grouped shapes and theme colours.
    • Added tables, bullet and numbered lists, vertical text alignment, autofit scaling, shape borders and gradient fills.
    • Fixed a defect where most slides rendered blank because placeholders inheriting their position from the slide layout were skipped.
  4. v2.1.0 July 30, 2026

    Every attachment is viewable through OneView, including files embedded in the page.

    • Files inserted directly into the page body were previously excluded. That removed OneView's compliance features — audit logging, watermarking and integrity verification — from exactly the files most likely to be read, since those apply only to a file opened through the macro.
    • Embedded files are now listed and flagged with an "Also on page" tag rather than hidden.
    • Reliability fix: the underlying check now uses Confluence's current v2 REST API. The previous implementation depended on an endpoint some sites have retired, which had silently disabled the check on those sites.
  5. v2.0.0 July 23, 2026

    Compliance and security release.

    • Integrity verification — one-click SHA-256 digest of any attachment, computed server-side and shown in the viewer header.
    • Compliance digest — an aggregated, non-identifying summary of recent activity for the current page, available to space administrators.
    • Watermarking — a configurable diagonal overlay rendered over every preview.
    • Custom blocklists and larger limits: inline text preview to 20 MB, attachment size to 5 GB, audit retention to 500 events per page.
    • Hardening: every resolver validates its inputs against a strict allow-list, per-endpoint rate limiting was added, and the audit writer explicitly drops all user-identifying fields before anything is stored.
    • OneView ships as a single, fully-featured edition — every install receives every feature, with no licensing gate.
  6. v1.0.1 July 21, 2026

    Presentation and documentation refinements.

    • Improved information hierarchy, workspace framing and attachment-browsing states in the viewer.
    • Clearer end-user documentation.
  7. v1.0.0 July 19, 2026

    Initial release.

    • Attachment discovery and listing for the current Confluence page, with pagination, filtering and sorting.
    • Inline viewer support for PDF, images, audio and video, Markdown, code and text, JSON, XML, YAML, TOML, and CSV table preview.
    • Ability to pin one attachment to a macro instance so a page highlights a primary document.
    • Policy-driven controls: maximum inline text size, maximum attachment size, download toggle, blocked extensions, blocked MIME prefixes and an optional watermark label.
    • Server-side filtering of disallowed file types before any content reaches the browser.