Ryan IT Solutions

Last updated 1 September 2026

Privacy Policy

This policy covers Winnow for Confluence, published by Ryan IT Solutions. The short version is that your content never leaves your Atlassian site, and we cannot read it.

Who we are

Ryan IT Solutions is the publisher of Winnow for Confluence, distributed through the Atlassian Marketplace. You can reach us at support@ryanit.io.

Where your content is processed

Winnow is a Forge app. It runs entirely on infrastructure operated by Atlassian, inside your own Atlassian site. It declares no permission to contact any external service, and the Forge platform enforces that — an outbound request would be refused by the platform, not merely absent from our code.

This includes the language models. Winnow reads pages using Atlassian's Forge LLMs API, which runs models on Atlassian's own infrastructure. Your page content is not sent to us, to any model vendor we have chosen, or to any other third party.

We have no access to your content. There is no administrative back door, no support console, and no copy of your data on our systems. If you asked us to look at a specific finding, we could not do it without you showing us.

What Winnow stores

Winnow keeps a small amount of information between scans, in Atlassian-hosted Forge storage inside your site:

  • Space identifiers — the id, key and name of each space you ask it to watch, with its health score and page count.
  • Page identifiers — page id, title, version number and last-modified date. Version numbers are how Winnow knows which pages changed, so that a nightly check only re-reads those.
  • Evidence quotes — short verbatim extracts from pages, the sentence that a finding rests on. These are shown to you in the report so you can verify a finding rather than trust it.
  • Finding text — a written summary and suggested action for each issue, which will describe or paraphrase the page it concerns.

What it does not store

  • Full page content. Pages are read into memory during a scan and discarded when it ends.
  • Any user identifier. Winnow does not read or record account ids, names, or email addresses — not even the identity of the person who last edited a page. Who wrote a page makes no difference to whether it is correct.
  • Usage analytics, telemetry, or product metrics of any kind. Nothing is collected for our benefit.

Logs

Winnow writes diagnostic logs to the Atlassian-hosted Forge logging service, visible to us for the app we published. These record what a scan did — how many pages it read, how long it took, how many model calls it made and what they cost us — and error messages returned by the platform. They do not contain page content, page titles, or user identifiers. Logs are not forwarded anywhere outside Atlassian.

Data residency

Because everything Winnow stores lives in Atlassian-hosted Forge storage, it follows the data residency location you have set for Confluence. If your Confluence data is pinned to a region, Winnow's data is pinned to the same region.

Sub-processors

None. Winnow shares data with no third party. Atlassian is not a sub-processor of ours in this arrangement — it is your provider, hosting your data under your agreement with them.

Retention and deletion

Winnow keeps the information above for as long as the app is installed. When you uninstall it, Atlassian deletes the app's storage according to the Forge hosted-storage lifecycle: the data is soft-deleted immediately and can be restored if you reinstall within 21 days, after which Atlassian removes it under its standard retention policy. We retain nothing separately, because we hold nothing separately.

You can also stop Winnow reading a space at any time by switching it off in the app's admin screen, without uninstalling.

Your rights

If you are an individual whose personal data may appear inside a page Winnow has quoted, the controller of that data is the organisation that operates the Confluence site — your employer or the site's owner — not Ryan IT Solutions. Requests to access, correct or erase it should go to them. We will assist their administrators where we can, but we cannot act on such a request ourselves, because we have no means of reaching the data.

Changes to this policy

If this policy changes materially we will update the date at the top and note the change in the app's Marketplace release notes. We will not reduce the protections described here without saying so plainly.

Contact

Questions about this policy: support@ryanit.io. Security matters: security@ryanit.io.