Privacy Policy
Last updated: 2026-07-27.
This policy explains what WikiFix does with your data. WikiFix is operated by Totem Dev. For anything not covered here, email security@wikifix.ai. Region-specific rights are at the end, under For EU residents and For non-EU residents.
Who this applies to
WikiFix is a B2B Confluence Cloud app. The “customer” is the Atlassian organization that installs it; the data we handle is your organization’s Confluence content and the account identifiers of the users who run scans and apply fixes.
Cookies on this website
This section is about wikifix.ai itself — the site you’re reading right now — separately from the installed product described below. We use one analytics tool, PostHog, on its EU instance, to see which pages help and where visitors drop off.
Nothing loads until you click Accept on the cookie banner shown on your first visit. If you reject it or leave it unanswered, no analytics script loads at all — the only cookie set is the one remembering your choice, which lasts about 6 months before asking again. Change your mind anytime via Cookie preferences in the footer.
If you do accept, two things go further than page counting, and you should know about them:
- Session replay is on, and form inputs aren’t masked. That includes what you type into the contact form.
- If a contact-form submission fails to reach us, the details you typed are sent to PostHog — name, work email, company, role, and your notes — so we can follow up by hand instead of losing your message.
The same toggle covers script-error reporting, since it runs through the same PostHog integration.
What we collect
Confluence content (processed, mostly not stored). When you run a scan, we read the pages in the spaces you select, directly from Confluence. We do not keep a copy of your wiki. What persists in our database is:
- A derived embedding index – numeric vectors, not your source text.
- The short excerpts behind each finding: the quote, the affected block, the titles of the pages the finding involves, and – for a suggested fix – the proposed replacement text.
Full page bodies are dropped at the database layer and re-read live from Confluence on each scan. There is one exception, and it exists so that you can undo things: when you merge duplicate pages, the page you didn’t keep has its previous body stored, because that is what a revert puts back.
Account identifiers. To run scheduled scans and to apply or revert fixes on your behalf, we hold the access tokens the Atlassian Forge platform issues for each participating user, encrypted, and rotate them. We use an internal user id (our own identifier, mapped from your Atlassian account at sign-in) as the primary key across our systems.
Email address (used to notify, not stored). To email the scan-completion summary to the report’s owner, we read that user’s email address from Atlassian at send time (via Confluence’s read:email-address scope, using the app identity). We never store it, and we use it only for sending that completion email — apart from the feedback case described next, which you can turn off before you send.
Feedback you send us. When you send feedback — from the Feedback button, or the optional note when you ignore a finding — the form shows your email address and a tick-box saying we may reply to you. It starts ticked, so if you leave it as-is, your address goes to PostHog with your message and we can answer you. Untick it and no address is sent; you can also type a different one. If your Atlassian profile keeps your email private, we never see it, and the form simply offers you an empty box instead.
Product analytics and error data. We use PostHog for product analytics and Sentry for error tracking. These receive metadata only – page titles, excerpts, and content are stripped by a code-enforced allow-list before any event leaves our systems. Deliberate exceptions: your Atlassian site host, your own search-box queries, and the reply-to address described above are recorded to make the product work and measurable.
AI-quality monitoring (content-bearing). To monitor and improve the quality of the AI’s findings, we record each AI request and response to Langfuse, our LLM-observability subprocessor. Unlike product analytics and error tracking, this does include content: the full prompt we send to the model and the model’s reply embed the page text under review.
Where we process it
Your data is processed in AWS Frankfurt (eu-central-1). Default AI inference runs on AWS Bedrock through an EU inference profile that stays within EU regions; cross-continent inference is blocked in code. Some AI steps may instead run on Mistral’s EU endpoint in France, which is EU-resident and pinned in code as well. Analytics (PostHog) and error tracking (Sentry) run on their EU instances, and Langfuse is pinned to an EU-resident instance. We run a single region and don’t offer hosting in other geographies.
Exception – bring-your-own-key. If you configure your own Anthropic API key, your prompts go to Anthropic’s API directly — both the scan and the rewrite that authors a fix — which is outside our EU-region pin and under your own agreement with Anthropic. Use the default path if EU residency for every inference call matters to you.
How we use it
Only to run the service: scan your selected spaces, find outdated and contradictory pages, propose fixes, and – when you approve – apply or revert them. Your content is never used to train AI models; default inference on AWS Bedrock does not use prompts or completions for training per AWS’s terms.
How long we keep it
We delete your data within 30 days of uninstall, automatically — a daily job purges tenants once they pass the 30-day mark, whether or not you ask. The 30 days exist so that a re-install picks up where you left off. If you want it gone sooner, email security@wikifix.ai. Database backups roll off after 7 days.
Who we share it with
We use third-party sub-processors to run the service. Rather than half-list them here and let the two versions drift apart, the current and authoritative list – every vendor, what it’s for, the data it processes, and where it sits – is on our Sub-processors page, and every change to it is published to a feed you can follow. The one worth calling out in this policy is Langfuse, because it receives content (see “AI-quality monitoring” above). Billing for your subscription runs through the Atlassian Marketplace. We don’t sell your data to anyone, ever.
Government access
WikiFix is operated by Totem Dev, incorporated in Moldova. Where authorities can compel data, they reach it through the providers that hold it and through legal-assistance channels; our place of incorporation does not put it beyond reach. Your content is held by AWS, a US-incorporated provider that can be compelled under the US CLOUD Act regardless of where it stores data, including the EU. Authorities can also seek assistance from Moldova under mutual-legal-assistance treaties (the US and Moldova are both parties to the Budapest Convention on Cybercrime, UNTOC, and UNCAC). We operate no government data-access program: we require valid legal process, challenge overbroad or unlawful requests, and notify you where legally permitted. What limits exposure in practice is EU-region processing, data minimization (we keep derived vectors and short excerpts, not full page bodies), and encryption.
For EU residents
If you are in the EU or EEA, the GDPR applies. Your organization is the data controller for its Confluence content; WikiFix (Totem Dev) acts as your processor. You have the rights of access, rectification, erasure, restriction, portability, and objection. To exercise them, email security@wikifix.ai; you can also uninstall WikiFix at any time, which removes our access and leads to deletion of your tenant’s data within 30 days (see How long we keep it). Your data is processed in the EU (AWS Frankfurt) and every sub-processor is pinned to its EU region, so on the default path your data stays in the EU. Our GDPR-aligned Data Processing Agreement is published in full and applies automatically when you accept our Terms — nothing to request, negotiate or sign, though we’ll send a countersigned copy if your procurement process needs one. You may lodge a complaint with your national supervisory authority. Totem Dev’s home jurisdiction, Moldova, is itself bound by the Council of Europe Convention 108+ on data protection.
For non-EU residents
If you are outside the EU/EEA, your data is still processed in the EU (AWS Frankfurt) – we don’t offer regional hosting elsewhere. We extend the same core handling to everyone, regardless of location: data minimization, encryption, no use of your content to train AI models, and access, correction, or deletion on request via your organization at security@wikifix.ai. The Government access section above applies to you as well.
US residents (California / CPRA). We do not sell or share your personal information, and we do not use it for cross-context behavioral advertising. You may request to know, access, or delete the personal information we hold by emailing security@wikifix.ai.
Changes
We’ll update this page when our practices change and update the date at the top. The data-handling detail on the security page is kept in sync with this policy.