Full Space Copy
Privacy and security · Last updated: 27 September 2026
Published by GOTH - Global Online Tech Hub on Atlassian Marketplace.
Privacy policy
What this app stores
For each copy, comparison, synchronization or bulk operation, Full Space Copy keeps what it needs to follow it, resume it after an interruption and report on it:
- the key and name of the spaces involved, and the options chosen,
- the progress, the steps and their time,
- which copied page corresponds to which original page, by identifier,
- the titles of pages that could not be copied or that differ, for the report and the proof dossier,
- the Atlassian account identifier of the person who started the operation.
What this app does not store
It does not store page content, attachments or comments: they go from one space to the other during the copy without being kept by the app. It stores no name and no email address: a person's name is read from Confluence when it is displayed.
When it copies a comment or a blog post, the app writes its original author's name and date at the top. That text is part of the content of your copied space, not of the app's data.
Personal data
The only personal data kept is the Atlassian account identifier: of whoever started an operation, scheduled a copy or a synchronization, saved a configuration or changed access to the app. It is used to show each person their own operations and to keep the audit log.
Every week, the app reports these identifiers to Atlassian. When Atlassian reports that an account was closed, the app erases what relates to it: the starter of its operations becomes anonymous and its schedules are deleted.
Where it is stored
Inside Atlassian's own infrastructure, using the Forge storage service, in the region assigned to your Atlassian site. No data is sent to any server operated by GOTH or by any third party. The app holds the Runs on Atlassian badge, which certifies exactly this.
Who can read it
Each operation is visible only to the person who started it and to site administrators, in the audit log. The app's lists are read with the user's own permissions: nobody sees, through this app, a space or a page they could not see in Confluence.
How long it is kept
One year for a space copy, with its report and proof dossier; 90 days for other operations; 30 days for the markers used to resume an interrupted copy. A synchronization or a scheduled copy is kept until it is deleted. Uninstalling the app deletes all its storage, which Atlassian performs on its side.
Security statement
Hosting and data residency
The app runs entirely on Atlassian Forge and carries the Runs on Atlassian badge. There is no server, no database and no logging service operated by the publisher. Data residency follows your Atlassian site.
Who can start an operation
Only administrators of the source space who are allowed to create spaces can start a copy. Other operations require administering the spaces involved. These permissions are checked by Confluence on every action, on the server side, not only when the screen is displayed. A site administrator can also limit the app to some groups.
Permissions requested
A copy recreates an entire space: pages, blog posts, attachments, settings and access. It therefore needs to read and write most of a space's content. The permissions, grouped by purpose:
- Read and write space content: read:page:confluence, write:page:confluence, delete:page:confluence, read:blogpost:confluence, write:blogpost:confluence, read:folder:confluence, write:folder:confluence, read:whiteboard:confluence, read:database:confluence, read:embed:confluence, write:embed:confluence, read:comment:confluence, write:comment:confluence, read:attachment:confluence, write:attachment:confluence, write:confluence-file, read:label:confluence, write:label:confluence, read:confluence-props, write:confluence-props, read:confluence-content.all, read:confluence-content.summary, write:confluence-content, search:confluence.
- Create the destination space and carry over its settings: read:space:confluence, write:space:confluence, write:confluence-space, read:confluence-space.summary, read:space-details:confluence, read:space.property:confluence, write:space.property:confluence, read:template:confluence, write:template:confluence, read:configuration:confluence, write:configuration:confluence, manage:confluence-configuration.
- Check permissions and carry over access: read:confluence-content.permission, read:space.permission:confluence, write:space.permission:confluence, read:content.restriction:confluence, write:content.restriction:confluence, read:confluence-user, read:user:confluence.
- storage:app: keep the state of operations, described above, in Forge storage.
- report:personal-data: report to Atlassian every week the accounts whose identifier the app keeps.
Authentication
Calls to Confluence use the user's identity whenever they display something, and the app's identity for the copy itself, once permissions have been checked. The app holds no credentials of its own: there is no API token, no password and no secret to leak.
For any question, or to report a vulnerability: contact@goth-tech.fr