Legal

KnowledgeLint Privacy Policy

Effective 9 August 2026. This policy describes the KnowledgeLint V1 data flow for the public website, customer requests, evaluations, and Marketplace customers.

Data processed

KnowledgeLint processes Confluence page metadata and temporarily reads page body text during an authorized scan. It may also process labels, owners, update timestamps, parent identifiers, referenced attachment names, findings, short evidence snippets, audit events, settings, AI usage counters, Atlassian account IDs needed for app workflows, and Jira issue links.

Evaluation and founding-launch requests

When you submit an evaluation or founding-launch request, Wotaso stores the work email, name, company, workflow, Rovo status, optional Confluence user count, critical question, source path, and campaign parameters you provide. These details are used to review the request and contact you about the fit review and related next steps—not to add you to a newsletter or automated sales sequence.

Requests are stored in a Wotaso-operated marketing database, are not mixed with customer Confluence content, and are deleted after 180 days unless they are still needed to handle the request, establish a customer relationship, or meet legal obligations.

Controller and legal basis for requests

Wotaso GmbH is the controller for evaluation and founding-launch request data. Company and contact details are available in the linked imprint. Request processing and the related reply are based on taking steps at your request before a possible agreement. Limited in-memory rate limiting and abuse prevention protect the form and service; the lead database does not store IP addresses.

Optional website analytics

The public KnowledgeLint website uses the AnalyticsCLI TypeScript SDK only after you choose Allow analytics. The legal basis is your consent. Before consent, the SDK is initialized with event collection disabled and sends no analytics event. You can reject optional analytics without losing access and can reopen Privacy choices in the footer at any time.

Analytics events are limited to event names, the current page path, page language, coarse web runtime context, sanitized campaign tokens, and—after consent—a pseudonymous session and browser identifier. KnowledgeLint does not send form content, names, email addresses, company details, critical questions, Confluence content, or Jira content to AnalyticsCLI. Technical connection data may still be processed by the collector and its hosting infrastructure when an event is delivered.

Analytics events must be configured for deletion after no more than 90 days. Withdrawing consent disables future collection and rotates or removes SDK identifiers stored in the browser. Aggregate reports that can no longer be linked to a browser may remain. Production analytics stays disabled until Wotaso has documented the collector hosting locations, access controls, deletion procedure, and any required data-processing or transfer safeguards.

Data stored

KnowledgeLint does not store full Confluence page bodies. Page bodies and selected AI prompt passages are transient scan data. Stored data is limited to page metadata, fingerprints, risk cases, findings, short redacted evidence, settings, audit events, Jira links, and aggregate AI usage metadata.

When attachment analysis is enabled, supported attachment contents may be downloaded and text may be extracted transiently inside Atlassian Forge. Attachment binaries and full extracted text are not persisted. Bounded extracted passages may be sent to Forge LLM for the authorized audit. Unsupported, inaccessible, or oversized attachments are reported as coverage gaps instead of being silently treated as reviewed.

AI processing

KnowledgeLint V1 uses Atlassian Forge LLMs as its default AI provider and declares no external runtime egress. Administrators control AI page, input-character, and token budgets and may disable AI processing.

AI-assisted findings are source-grounded recommendations for human review. KnowledgeLint does not guarantee exhaustive detection and does not use customer content to train unrelated models or datasets.

Hosting, retention, and account requests

KnowledgeLint runs on Atlassian Forge, Forge SQL, Atlassian REST APIs, and Forge LLM. Residency and transfer behavior depend on the applicable Atlassian Cloud and Forge capabilities.

Administrators can configure retention. KnowledgeLint also supports a stored-account summary and anonymization workflow for Atlassian account IDs while retaining non-personal operational audit records.

Customer responsibilities

Customers are responsible for selecting authorized spaces, choosing appropriate AI settings, reviewing findings before acting, and handling requests relating to their own Confluence and Jira content. KnowledgeLint does not automatically edit or delete Confluence pages; Jira tickets require explicit administrator action.

Contact

Privacy and support requests can be sent to contact@wotaso.com. You may request access, correction, deletion, restriction, portability, or object where applicable, and you may contact the competent data protection authority. For product requests, include the Atlassian site and relevant scan or finding ID, but never send passwords, API tokens, or full Confluence page bodies.