Tim Schartman

Privacy Policy

Applies to Crosscheck for Confluence. Last updated 27 July 2026.

The short version. Crosscheck runs entirely inside Atlassian's infrastructure. Your Confluence content is never transmitted to me, to any server I operate, or to any third-party service. I have no ability to read your pages. The app stores a small amount of derived data and short text excerpts, and all of it stays within your own Atlassian site.

Who is responsible

Crosscheck for Confluence is built and operated by Tim Schartman, an individual developer based in Illinois, United States. Questions about this policy can be sent to support@timschartman.com.

Where the app runs

Crosscheck is an Atlassian Forge app. Forge apps execute on infrastructure operated by Atlassian, not on servers operated by the developer. Crosscheck declares no external network permissions, which means the Atlassian platform itself prevents it from sending data outside the Atlassian environment.

Atlassian independently verifies this and awards the Runs on Atlassian badge only to apps that use exclusively Atlassian-hosted compute and storage and do not egress customer data. Crosscheck carries that badge. You do not have to take my word for any of the above — the badge is Atlassian's assertion, not mine.

What the app reads

When you run a scan on a space, Crosscheck reads, using the permissions your administrator granted at install:

Crosscheck only reads spaces when a scan is run against them. Personal spaces are excluded entirely and are never read.

What the app stores

Analysis results are written to Forge storage, which is provided and hosted by Atlassian and associated with your own Confluence site. Stored data comprises:

DataPurpose
Numerical content signatures (MinHash) Detecting overlap between pages. These are one-way hashes; the original text cannot be reconstructed from them.
Short text excerpts — individual sentences containing a number, date, version or currency amount, truncated to 300 characters Identifying which pages state conflicting values, and showing you the evidence for a finding
Quoted claims within findings — the specific conflicting statements from each page Displaying a contradiction so you can judge it. Without the quotes a finding would not be actionable.
Page metadata: ID, title, version, last-updated date, last editor's Atlassian account ID, outbound links, word count Page health scoring, ownership and orphan detection
Scan progress and monthly AI usage totals Resuming interrupted scans and enforcing usage limits

Full page text is not stored. Page content is analysed in memory during a scan and discarded; only the derived signatures, metadata and the short excerpts described above are written to storage.

Because titles, excerpts and editor account IDs are retained, stored data may include personal information if your pages contain it. It remains inside your Atlassian site throughout, subject to the same data residency configuration as the rest of your Confluence data.

AI processing

Crosscheck uses the Forge LLMs API to judge whether two pages genuinely contradict each other. This is an Atlassian-operated service running Anthropic Claude models within the Atlassian platform.

AI analysis runs only on paid plans. On the free plan, no content is ever sent to a model, because no model is called at all.

What the app does not do

These are not policy promises alone. The app declares no external network permissions, so the Atlassian platform blocks such transmission regardless of what the code attempts.

Retention and deletion

There is no separate copy for me to delete, because no copy is ever transmitted to me.

Sub-processors

None. All processing and storage takes place within Atlassian's infrastructure. I engage no third-party processors, hosting providers, analytics services or AI vendors for this app.

Your rights

Because your data never leaves your Atlassian site, requests to access, export or erase it are satisfied directly within your own Confluence instance — through the Reset action, or by uninstalling the app. Your organisation's existing Atlassian data controls apply unchanged.

If you have a question this policy does not answer, write to support@timschartman.com.

Changes to this policy

Any material change will be published here with an updated date. If a future version of the app were ever to transmit data outside Atlassian, that would require new permissions that your administrator must explicitly approve, and it would be described here first.