Privacy policy
Last updated 5 October 2026
Legilio is an app for Confluence Cloud that turns OpenAPI and Swagger specs into API documentation on Confluence pages. This policy explains what data the app handles, what we receive as its vendor, and how to reach us. “We” means Sergii Khomenko, a sole proprietor registered in Ukraine.
In short
Legilio runs entirely on Atlassian’s Forge platform. It has no servers of its own and sends nothing outside Atlassian. It has no analytics and sets no cookies. The only thing it stores is your site’s choice of allowed spec sources.
Your specs
Specs stay where you put them: in the macro body or in a page attachment. When someone views a page, Legilio reads the spec with that person’s Confluence permissions and renders it in their browser. PDF and Word exports also run inside Atlassian. Legilio doesn’t copy specs anywhere and doesn’t keep them after rendering.
What Legilio stores
One settings record per Confluence site, kept in Atlassian’s Forge storage: whether specs pasted into the macro and page attachments are allowed. It contains no personal data. Forge storage sits in the same location as your Confluence data, so it follows your site’s data residency. If you uninstall Legilio, Atlassian keeps the record for 28 days and then deletes it.
Personal data the app sees
To decide who may change the settings, Legilio asks Confluence whether the current user is a Confluence admin. The answer is used once and not stored.
Logs
Legilio’s code doesn’t write spec content or personal data to logs. If something fails, Atlassian’s platform records technical details such as error messages, and these may reach us: by default, Atlassian shares a site’s app logs with the app’s vendor. A site admin can turn this off in Atlassian Administration under Connected apps.
What we receive from Atlassian
When your organization tries or buys Legilio, Atlassian shares the license details with us, including your organization’s name and the names and email addresses of its technical and billing contacts. We use them only for licensing, billing questions and support.
Support
When you open a request in our support portal or write to us, we keep the conversation to help you. Ask us, and we’ll delete it.
This website
This website sets no cookies and has no analytics.
Who processes data for us
Atlassian runs Legilio, hosts this website and our support portal, and handles Marketplace sales; see the Atlassian Privacy Policy. Support emails are stored by our email provider. We don’t sell personal data or share it with anyone else.
Legal basis
We handle license and support data to provide the app you bought (performance of a contract), and app logs to keep Legilio working (our legitimate interest in fixing faults).
Your rights
You can ask us what personal data we hold about you, and ask us to correct it, delete it or stop using it. Write to us and we’ll reply within 30 days. You can also complain to the data protection authority where you live.
Changes
When this policy changes, we’ll update this page and the date at the top.
Contact
Sergii Khomenko
ask@xoma.me