bytera

Bytera Apps

Atlassian Marketplace apps that keep your knowledge alive and your teams in sync.

DocumentationPricingSupport
FEATURED
Pulse logoPulseContent Health for Confluence
DocumentationSecurity PolicyPrivacy PolicyTerms of Service
XPress logoXPressPDF Exporter for Confluence
DocumentationSecurity PolicyPrivacy PolicyTerms of Service
SyncUp logoSyncUpSprint Intelligence for Jira
DocumentationSecurity PolicyPrivacy PolicyTerms of Service
Spotlight logoSpotlightAI Charts & Reports for Jira
DocumentationSecurity PolicyPrivacy PolicyTerms of Service
BY PLATFORM Confluence JiraGET STARTEDTry it free on Marketplace ↗Book a demo
DocsPricingAboutBlog
Book a demo
← XPress

XPress - Privacy Policy

Last updated: September 2026

1. Overview

Bytera ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how XPress, our Confluence app listed on the Atlassian Marketplace, accesses, processes, and protects your data.

Bytera is the data controller and is fully responsible for the privacy, security, and integrity of any data processed by XPress. Atlassian is not responsible for our data practices.

2. Data We Access

XPress is a Confluence app that exports pages and blog posts to PDF and HTML. To provide this functionality, XPress accesses the following data through Atlassian APIs:

2.1 Confluence Content (Read Access)

  • Page and blog post content: Titles, body content, and formatting - accessed when you initiate an export.
  • Attachments: Images and files embedded in pages - accessed to include them in the exported document.
  • Space metadata: Space names and structure - used to display content selection options.
  • Hierarchical content: Page tree structure - used for bulk and nested page exports.

2.2 Your Content Is Never Changed

  • No writes: XPress does not create, change, or delete anything in Confluence. Exported files are kept in XPress's own storage within Forge and are never attached to your pages.

2.3 User Context

  • Atlassian Account ID: Used to identify who initiated an export request and to enforce permissions. Inside Forge, it is also used to count how many different people exported in the last 7 days and to check that a download report comes from the person who made the export. The account ID itself is not sent to analytics. We do not access profile details beyond what Atlassian provides in the app context.

3. Data Processing & External Services

Important: XPress uses an external rendering service to generate PDF documents.

3.1 PDF Rendering Service

When you export content to PDF, formatted content is sent to our secure, cloud-hosted rendering service (operated by Amazon Web Services) solely to be converted into a PDF file. HTML exports are produced entirely within Forge and never reach this service. The render service:

  • Acts purely as a rendering engine - it does not read, interpret, analyze, or store the content in any way.
  • Does not persist any data. Content is processed in-memory and discarded immediately after the PDF is generated.
  • Does not log, record, or retain any content or metadata. There is zero data retention on the external service.
  • All data is transmitted over encrypted HTTPS connections.
  • Is hosted on AWS in the US East (N. Virginia) region.

All content reading, processing, and file storage operations happen entirely within the Atlassian Forge environment. The external render service only receives pre-formatted HTML for conversion and returns the resulting PDF - no data leaves the rendering pipeline.

3.2 Forge Platform

XPress runs on Atlassian's Forge platform. The following Forge services are used:

  • Forge Object Store: Used to store the files you export, in PDF or HTML, within the Atlassian cloud environment. Each file is deleted automatically after 30 days. Your site's uploaded logo and fonts are kept here too, until they are removed.
  • Forge SQL (MySQL): Used to keep your export history, which is deleted automatically after 30 days, and daily counts of the usage events your site has sent, which are deleted automatically within 4 days.
  • Forge App Storage: Used for app configuration settings and templates.
  • Forge Queues: Export and render tasks are processed through Forge async queues for reliable execution.

3.3 Usage Analytics

XPress sends usage events to PostHog, an analytics service hosted in the United States and declared to Atlassian as an analytics destination. The events show us which parts of XPress each site uses and where exports or searches do not work out, so we can see what works and fix what does not.

  • What is sent: your Confluence site's cloud ID and its address (for example yourcompany.atlassian.net), the kind of event, when it happened, your XPress license status and type, and the XPress version that sent it. Kinds of event include XPress being opened; an export starting, finishing, failing, being refused or being downloaded; a template or the site brand being changed; a logo or font file being refused; a button on one of XPress's own screens being used; and a notice when your site sends more events than XPress allows. An event can also carry general values, such as where in Confluence XPress was used (a space, XPress's own page, a page's menu or its byline), a page-count range, the file format or paper size, whether a setting such as the cover page was switched on, what kind of template an export started from and which groups of its settings were changed, ranges for how long an export took and how big the file was, why an export failed or was refused, which kind of control started an export (the Enter key or a button), how many searches found nothing, whether a file was downloaded for the first time, and the result of a logo or font upload with a range for its file size.
  • A daily summary of your site: once a day, XPress also sends a summary of how your site is set up and used: a range for how many templates your site has made and for how many spaces have a default template; whether any starter template was edited; whether any template uses labels, heading or figure numbers, its own typography or its own file name; whether the site has its own logo, fonts or colors; whether the site or any one person on it has reached the template limit; a range for how many exports were made in the last 7 days and how long ago the last one was; and how many people exported in the last 7 days, given as 0, 1, 2 to 5, 6 to 20, or more than 20. XPress works these out inside Forge and sends only these ranges and yes or no answers.
  • What is never sent: XPress sends no Atlassian account ID, name or email address, and no scrambled form of one. It sends no page content, page titles, space names, template names, labels, file names, search text, or header, footer or watermark text, and not the colors your brand uses.
  • How it is sent: from XPress's server side within Forge, not from your browser. XPress loads no third-party analytics or tracking code in your browser. XPress's own screens note a few things only the browser sees, such as which of their buttons were used, how many searches found nothing, which control started an export, and a logo or font file refused before upload, and pass them to XPress's server side. Before anything is sent, the server checks every general value against a fixed list of what is allowed, and nothing outside that list is sent.

4. Data We Store

Data TypeWhereRetention
Exported files (PDF and HTML)Forge Object Store (within Atlassian cloud)30 days, then deleted automatically
Export historyForge SQL (within Atlassian cloud)30 days, then deleted automatically
Usage event counts (how many usage events your site sent each day and in the latest hour, with no account IDs and no content)Forge SQL (within Atlassian cloud)Up to 4 days, then deleted automatically
Site logo and fonts you uploadForge Object Store (within Atlassian cloud)Until removed or app is uninstalled
App configuration and templatesForge App StorageUntil app is uninstalled
Page content (during PDF generation)Render service (in-memory only)Seconds - discarded immediately after rendering

We do not store Confluence page content outside of the Atlassian cloud environment. Exported files remain within Forge, managed by Atlassian's infrastructure.

5. How We Use Data

We use the data we access exclusively for:

  • Converting Confluence content to PDF or HTML (core app functionality).
  • Storing exported files within Forge so you can download them.

We do not sell, rent, or share your data, and we do not use it for advertising or marketing. Apart from providing XPress, the only other use is the site-level usage analytics described in section 3.3, which include your site's address but no account ID, no name or email address from anyone's Atlassian account, and no page content.

6. Data Security

We implement industry-standard security measures:

  • Forge Sandbox: XPress runs in Atlassian's secure Forge environment with tenant isolation and sandboxed execution.
  • Encrypted Transit: All communication between Forge and our render service uses HTTPS/TLS encryption.
  • Least Privilege: We request only the minimum API scopes necessary for app functionality.
  • No Persistent Storage of Content: Page content is never written to disk on our render service - it is processed in-memory only.
  • Infrastructure Security: Our render service runs on secure cloud infrastructure with automatic scaling, patching, and enterprise-grade security controls.

7. Data Sharing

We do not share your data with any third parties, with the following exceptions:

  • Cloud Rendering Service (AWS): Page content is transmitted to our cloud-hosted render service for PDF generation. AWS acts as our infrastructure provider, not a data processor.
  • Usage Analytics (PostHog): Site-level usage events, as described in section 3.3. They are filed under your Confluence site and include its address, but carry no account ID, no name or email address from anyone's Atlassian account, and no page content.
  • Legal Requirements: We may disclose data when required by law, legal process, or to protect our rights or the safety of users.

Apart from the usage analytics above, we do not use any advertising, analytics or tracking services within XPress.

8. Your Rights

In accordance with applicable data protection laws (including GDPR), you have the right to:

  • Access: Request information about what data we process.
  • Rectification: Request correction of inaccurate data.
  • Erasure: Request deletion of your data. Since we do not permanently store content, uninstalling XPress removes all app-related data from Forge.
  • Data Portability: Request your data in a portable format.
  • Objection: Object to the processing of your data.

To exercise any of these rights, please contact us at support@bytera.tech.

9. Permissions Explained

XPress requests the following Atlassian API scopes and their justification:

PermissionWhy It's Needed
Read pages, content, spacesTo access and display Confluence content for export
Read attachmentsTo include images and files in exported PDFs
SearchTo enable content search and filtering within the app
App storageTo store app configuration, templates, and exported files

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of material changes by updating the "Last updated" date and, where appropriate, through our Atlassian Marketplace listing.

11. Contact

For any privacy-related questions, data requests, or security concerns:

  • Email: support@bytera.tech
  • Website: bytera.tech/contact
  • Marketplace: Bytera on Atlassian Marketplace
bytera

Building the Digital Era

Apps

  • Pulse
  • XPress
  • SyncUp
  • Spotlight
  • Atlassian Marketplace ↗

Company

  • About Us
  • Blog
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Trust Center

© 2026 Bytera. All rights reserved.