Privacy Policy
Last updated: 4 October 2026
This policy explains what data is involved when you use Apifolio, the Confluence app, and this website (apifolio.dev). Apifolio is made by Rosario Vitale, an independent developer based in Italy ("we", "us"), who is the data controller for the personal data described in section 2. Contact: privacy@apifolio.dev.
The short version
- Apifolio runs on Atlassian. Its code runs inside Atlassian's Forge platform, and it sends no data to servers outside Atlassian.
- We never receive your Confluence content: no pages, no spec files, no comments, no user data.
- The app sets no cookies of its own and contains no analytics or tracking.
- This website uses no cookies, no analytics and no third-party trackers.
1. Data processed by the app
To show your API documentation, Apifolio reads, inside your Confluence site:
- the OpenAPI or Swagger files attached to pages, and basic page information (ID, title);
- the macro settings stored in the page.
Files are read in your browser as the current user, so Confluence permissions always apply. For PDF and Word exports, for the Rovo agent and for anonymous visitors of public spaces, the same reads happen in Apifolio functions that run on Atlassian's infrastructure. Nothing is copied out of Atlassian, and we have no access to it.
When you save a macro, Apifolio stores a short text digest of the API (endpoint paths and summaries) in the macro so that Confluence search can find it. It is stored in your page, like any other page content.
Your data stays where your Confluence site's data lives, under Atlassian's security and data-residency controls. See Atlassian's Privacy Policy and Trust Center.
2. Data we receive
- Licensing and billing information that Atlassian shares with Marketplace partners: for example the site URL, the licensed organisation, the licence type and, when you provide them, technical and billing contacts. We use it to manage licences, provide support and meet legal obligations. Payments are handled by Atlassian; we never see card details.
- Support requests: when you write to us, we receive your email address, your message and anything you attach. Please don't send us confidential specs; a screenshot or a short excerpt is usually enough.
- Error logs: Atlassian gives app developers access to the logs of their app's functions. Apifolio logs only short error categories (for example "attachment not found"), never spec content or personal data. Atlassian keeps these logs for a limited time.
3. AI features
"Copy for AI" copies Markdown to your clipboard in your browser; Apifolio sends nothing to any AI service. The optional Apifolio API Expert agent runs on Rovo, Atlassian's AI, under your organization's Rovo settings and Atlassian's terms. Apifolio's actions return data from your specs to Rovo inside Atlassian.
4. This website
apifolio.dev is a static site hosted on Cloudflare Pages. It uses no cookies, analytics or trackers. Cloudflare processes technical data such as IP addresses to deliver and protect the site (Cloudflare Privacy Policy).
5. Legal bases (GDPR)
- Licensing, billing and support: performance of a contract and our legitimate interest in running the service.
- Legal and tax obligations: compliance with the law.
- Security of the app and website: legitimate interest.
For the content processed by the app inside your Confluence site, your organization decides what is processed. If your organization needs a data processing agreement, write to privacy@apifolio.dev.
6. Service providers
We use a small number of providers: Atlassian (Marketplace, licensing, Forge hosting), Cloudflare (website hosting and email routing) and Google (email inbox for support). Some of them may process data outside the European Economic Area, under appropriate safeguards such as the EU Standard Contractual Clauses.
7. Retention
- Support emails: up to 24 months after the request is closed.
- Licensing and billing records: as long as required by tax and accounting law (in Italy, up to 10 years).
8. Your rights
You can ask to access, correct or delete your personal data, to restrict or object to its processing, and to receive it in a portable format, by writing to privacy@apifolio.dev. You can also complain to a data protection authority. In Italy this is the Garante per la protezione dei dati personali.
9. Children
Apifolio is a business tool and is not directed at children.
10. Changes
We will update this page when the app or our practices change, and change the date at the top. For important changes we will also notify customers' technical contacts.