Privacy statement: PlantUML Private
The app has no server of mine to send your data to, and requests no permission to read your Confluence content.
The short version
PlantUML Private renders PlantUML diagrams inside your own browser, on your own Confluence page. I do not operate a server that your diagrams pass through. The app requests no permission to read your Confluence content, and it runs no code of mine on Atlassian’s infrastructure. There is no database of mine holding your diagram source, and the app has no mechanism by which it could be sent to me.
What data the app touches
| Data | What happens to it |
|---|---|
| The PlantUML source you type | Rendered in your browser. Stored in the macro’s own configuration on your Confluence page, the same mechanism Confluence uses for any macro’s settings. Not transmitted to me or to any third party by the app. |
| The rendered diagram | Generated and displayed in your browser. Not uploaded anywhere by the app. |
| Your identity, account and site details | The app requests no OAuth scopes, so it cannot read your profile, pages or space list. I do not receive them. |
| Analytics or telemetry | None is collected by the app, and this website sets no cookies and uses no analytics or third-party requests. Atlassian’s platform may collect standard Marketplace-level installation and usage information, as it does for every app (see below). |
Why this is structural
- No server. The app is static files (HTML, JavaScript and a rendering engine) served by Atlassian’s infrastructure and run in your browser. I operate no backend, API or database that the app talks to.
- No permissions. No scopes are requested, so none are listed on the install screen.
- Remote includes are refused. If diagram source contains a remote
!include, the rendering engine declines it before any network request is attempted. This was verified against PlantUML core 1.2026.6. - Nothing is fetched to render. The 43 themes and the C4, Kubernetes and Office libraries are bundled with the app.
Measured against a production deployment, the only off-origin requests were two scripts the Forge platform adds to every Custom UI frame. Neither is app code, and neither carries diagram content.
Why this matters
Some diagram apps work by sending diagram source to a render server on the internet and displaying the image that comes back. With that design the source leaves your instance, and depends on that server’s ownership, configuration and availability. PlantUML Private has no render server, so that failure mode does not apply to it.
What I do not control
- This statement describes what the app’s own code does. It is not a statement about Atlassian’s platform. Atlassian, as operator of Confluence Cloud, has access to page content, including whatever the app stores in its macro configuration, as it does for every macro from every vendor. That relationship is governed by your agreement with Atlassian.
- I do not control your organisation’s Confluence configuration, such as who can see a page. Standard Confluence page permissions apply to a page carrying this macro as they do to any other page.
- Installation and billing happen through Atlassian’s Marketplace and are between you and Atlassian. I do not receive your payment details through the app.
- If you email me for support and include diagram source or other details, that information reaches me because you chose to send it, by ordinary email. I use it only to respond to you.
Retention
Nothing from the app reaches me, so there is nothing from the app for me to retain. If you uninstall the app, diagrams stored in each page’s macro configuration remain wherever Confluence’s own uninstall behaviour leaves them. Support emails are kept for as long as needed to deal with your request.
Contact
Chandlery is Scott Page, a sole trader in the United Kingdom. Questions about this statement: support@chandlery.dev.