Privacy policy
Pagecycle and PageCheck run on Atlassian. Your pages, statuses and AI checks stay in your Atlassian site, and BrainGrid does not receive or store them.
Who we are and what this covers
BrainGrid AI, Inc. ("BrainGrid", "we", "us") makes Pagecycle and PageCheck, apps for Confluence Cloud sold on the Atlassian Marketplace. This policy explains what personal data we handle, why, and the choices you have. It covers:
- the apps, when installed in an Atlassian site;
- this website, atlassian.braingrid.ai, including the release notes;
- our support portal and our email.
It does not cover Confluence itself, which Atlassian provides under its own privacy policy, or the rest of braingrid.ai, which has its own.
Inside the apps, your organization decides what goes into its Confluence site, and the apps process that data on your organization's behalf. For the data we handle to sell and support the apps (licensing, support and email), BrainGrid decides how it is used.
Runs on Atlassian
Everything the apps store is kept in Forge storage for your site, which Atlassian keeps in the same data residency region as your Confluence site and moves with it, or on your Confluence pages as normal Confluence data. BrainGrid operates no servers that receive your content. We do not receive or store your pages, statuses, comments or AI checks, and we do not use them to train AI models.
Atlassian hosts the apps and their storage under its own security program and its terms with us as a Marketplace partner.
Pagecycle
Pagecycle adds workflows and review dates to Confluence pages. It stores the following in Forge storage for your site, unless noted:
| Data | Why |
|---|---|
| Space settings, workflows and automation rules | To run each space's workflow |
| Each tracked page's status, review date, a fingerprint (hash) of its body and bookkeeping ids | To check status changes and notice edits. Pagecycle reads a page's body only to compute the fingerprint and never saves it |
| History: every move, with the page, the from and to statuses, the Atlassian account id of the person who made it, their comment and the reason; and pending moves, with the same details | The audit trail in History, the board and CSV exports |
| Account ids that appear in history, with when they were last reported to Atlassian | Atlassian's personal data reporting (below) |
| Short operational records: automation runs and problems shown on the Health tab | To run each automation once and to show failures |
| The page's status, and the comments and labels automations add | To show the status on the page and keep it searchable. Stored in Confluence as normal page data |
The only personal data Pagecycle stores is Atlassian account ids and the comments people write when they move a page. Every week Pagecycle reports the account ids it stores to Atlassian's personal data reporting API. When Atlassian reports an account as closed, Pagecycle replaces that account id everywhere in its storage with a "former user" marker.
PageCheck
PageCheck labels Confluence pages AI, Human or Mixed. It is coming soon to the Atlassian Marketplace, and this section describes it as it will launch.
When a page version is checked, PageCheck reads the published version and runs the AI check inside the app, on Atlassian's platform. Drafts are never checked, and nothing is checked until a Confluence admin chooses the spaces PageCheck runs in. With automatic checks on, an edit is checked when it is published; with them off, a reader asks for a check. PageCheck stores the following in Forge storage for your site, unless noted:
| Data | Why |
|---|---|
| For each checked page version: page id, space, version, word count, the result and its shares, and a fingerprint (hash) of the checked text | To show the label under the page title, and to reuse a result when the text has not changed |
| The checked text and its passages, with the headings that label them | To show the passages behind a label. Kept for the newest two checked versions of each page; deleting a page removes them |
| Ids of deleted pages | So a check already running cannot store a deleted page's text |
| The month's AI checks: words used and the month's limit | To keep each site within its monthly AI checks |
| A count of the month's active users, kept as a set of small numbers (a HyperLogLog sketch), and a random key for the month | To size the month's AI checks without keeping a list of who the users are. The key is deleted shortly after the month ends, and from then on nothing links the numbers to anyone |
| Settings: the spaces PageCheck runs in and whether checks are automatic | To run only where admins chose |
| The label's text and icon on each checked page, and whether PageCheck is on in each space | To show the label under the page title. Stored in Confluence as page and space properties |
PageCheck stores no Atlassian account ids, names or email addresses as records of their own. Page text can contain personal data, such as names written on a page or mentioned; PageCheck keeps it only to produce and show the AI check.
Who can see app data
Only people in your Confluence site, and only for pages they can view. Both apps check the viewer's permission with Confluence on every request, and every board, history view and export is filtered to the pages the viewer can see. When someone connects an agent through Rovo or over MCP, the agent receives what that person can view. BrainGrid staff have no access to your site's app storage.
What BrainGrid collects
Outside the apps, we handle a small amount of personal data to sell and support them.
Licensing data from Atlassian. When your organization installs or buys an app, the Atlassian Marketplace gives us license details for the installation: the organization's name, the site, the app edition and user tier, license dates, and the names and email addresses of the technical and billing contacts. Atlassian handles billing and payment; we never see card details.
Support requests. What you send through our support portal, which runs on Atlassian's Jira Service Management, or by email to hello@braingrid.ai: your name, email address, organization and the content of your request, including anything you choose to attach.
Email. Names, business email addresses, job titles and organizations of people we email about our apps, such as Confluence and Atlassian admins. We gather these from business sources, such as public professional profiles and companies' own websites, and from people who contact us.
This website. The pages at atlassian.braingrid.ai load no analytics or advertising scripts and set no cookies. Our hosting provider keeps standard request logs, such as IP address, browser and pages requested, to run and secure the site.
We do not sell personal data, and we do not share it for cross-context behavioral advertising.
How we use it, and our legal bases
| Purpose | Data | Legal basis (where GDPR or UK GDPR applies) |
|---|---|---|
| Provide, license and support the apps | Licensing data, support requests | Performance of our contract with your organization |
| Send service notices, such as security notices and changes to these terms | Licensing contacts | Our legitimate interest in running the apps safely |
| Tell admins about our apps | Email data | Our legitimate interest in promoting our products; you can opt out at any time |
| Run and secure this website | Request logs | Our legitimate interest in a working, secure website |
| Meet legal, tax and accounting obligations | Licensing data | Legal obligation |
Every marketing email says how to opt out, and we stop when you ask, by reply or by writing to hello@braingrid.ai.
Sharing and sub-processors
The apps have no sub-processors beyond Atlassian, which hosts them and their storage.
For the data we handle ourselves, we use service providers that host this website, our email and our support portal. They act on our instructions under contracts that limit them to providing those services. We share personal data with others only:
- when the law requires it, such as a valid court order;
- to protect the rights, property or safety of BrainGrid, our customers or others;
- with a successor, if BrainGrid is part of a merger, acquisition or sale of assets, under this policy.
International transfers
Stored app data stays in your Atlassian site's data residency region. BrainGrid is based in the United States, so the data we handle ourselves (licensing, support and email) is processed in the United States. Where the law requires it, we protect transfers of personal data from the European Economic Area, the United Kingdom and Switzerland with the European Commission's Standard Contractual Clauses or an equivalent safeguard.
Retention and uninstall
- Pagecycle keeps history for the period a space admin chooses (30 days, 90 days, 1 year or 3 years; 3 years by default) and deletes older history weekly. Health problems are kept 30 days and automation run records 90 days.
- PageCheck keeps checked text for the newest two checked versions of each page, and results until the app is uninstalled.
- When an app is uninstalled, Atlassian deletes its Forge storage for your site. Atlassian can recover it on request for a short period, then it is removed. Statuses, properties, comments and labels written to Confluence stay on your pages as your data.
- We keep licensing records while your organization is a customer and afterwards as long as tax and accounting rules require; support requests for as long as they help us support you, about three years after the last contact; and email data until you opt out or it is no longer relevant, after which we keep only what we need to honor your opt-out.
Security
App data is protected by Atlassian's Forge platform, which Atlassian describes as encrypted in transit and at rest and isolated per site, under Atlassian's security program. Every app request runs as your site's installation and checks the viewer's Confluence permissions. For the data we handle ourselves, we limit access to the people who need it.
If we learn of a security incident that affects your personal data, we tell the affected customers without undue delay and as the law requires. Report a security issue to hello@braingrid.ai.
Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you, and get a copy of it;
- correct it if it is wrong;
- delete it;
- object to or restrict how we use it, including for direct marketing;
- withdraw consent, where we rely on consent;
- complain to your data protection authority.
Because app data lives in your organization's Atlassian site, most requests about it are met by your site admins, and we help them. For anything else, write to hello@braingrid.ai. We may need to confirm your identity, and we answer within 30 days. We do not treat you differently for using these rights.
California residents. In the last 12 months we collected the categories described above: identifiers and professional information (names, email addresses, job titles, organizations), commercial information (license details) and internet activity (website request logs), for the purposes listed in this policy. We do not sell or share personal information, and we do not use sensitive personal information.
Children
The apps and this website are for organizations and are not directed at children under 16. We do not knowingly collect children's personal data.
Changes and contact
We post changes to this policy on this page with a new effective date, and tell license contacts about material changes by email before they take effect.
Questions or requests: BrainGrid AI, Inc., hello@braingrid.ai.