Peercraft Privacy Policy
Last updated: 29 July 2026
Peercraft ("the app") is an Atlassian Forge app for Confluence Cloud, published by Norda ("we", "us"; contact: ossi@norda.is). This policy describes what data the app processes, where it is stored, and what leaves Atlassian's infrastructure.
What the app stores, and where
Peercraft runs on Atlassian's Forge platform. Application data is stored in Forge Key-Value Storage inside your Confluence site's Atlassian cloud environment, isolated per installation:
- Courses, sections, lectures, quizzes, announcements, and instructor profiles created by your users.
- Learning records: per-user progress, quiz attempts and scores, notes, bookmarks, favorites, Q&A posts, reviews, certificates, badges, assignments, watch-time streaks, and abuse reports.
Learning records are keyed to the user's Atlassian account ID. We have no standing access to this data; it lives in your site's Forge storage and is removed by Atlassian's platform processes when the app is uninstalled, subject to Atlassian's retention behavior for Forge storage.
The app reads Confluence user directory information (display names, avatars, account IDs) via Atlassian APIs to show who created content and to let managers assign courses. It never stores Atlassian passwords or API tokens.
What leaves Atlassian (sub-processors)
Four external services receive data, strictly to provide app features. These services are operated under accounts held by Norda — your organization does not need (and cannot connect) its own accounts. None of them receive Atlassian account IDs, names, or emails — they receive course content only:
| Service | What is sent | Why |
|---|---|---|
| Cloudflare R2 (media.peercraft.io) | Uploaded videos, images, caption files, materials | Object storage and serving. Uploads use short-lived presigned URLs signed by the backend; files are stored in Cloudflare's managed object storage. |
| AssemblyAI (api.assemblyai.com) | The public R2 URL of a video | Auto-caption transcription: AssemblyAI fetches the video and generates WebVTT captions. No user identity is sent. |
| OpenAI (api.openai.com) | Lecture transcripts and titles, text-lesson content, and learner questions typed into the AI tutor | AI features: quiz generation, lecture summaries, course-copy drafting, and the learning tutor. |
| YouTube (youtube.com) | Public YouTube video IDs of lectures added by URL | Embedding YouTube lectures, fetching titles/thumbnails/captions. |
If instructors or learners type personal information into free-text content (for example into a lecture transcript or a tutor question), that content is processed by the services above as part of the feature.
Data residency
Data held in Forge storage follows your Confluence site's Atlassian data residency configuration (in scope). Media stored in Cloudflare R2 and content processed by OpenAI and AssemblyAI are out of scope for Atlassian data residency.
Retention and deletion
- Deleting a course in the app deletes its related records (videos, quizzes, progress, reviews, assignments) from Forge storage.
- Media files uploaded to Cloudflare R2 are retained in Norda's R2 bucket; contact us to request deletion of specific media.
- OpenAI processes requests transiently under its API data-usage policy; content sent through the app is not used to train models.
Your rights
Site administrators control installation and can uninstall the app at any time. For questions, data-subject requests, or security reports, contact support@peercraft.io. We notify Atlassian of security incidents through Atlassian's ecosystem security process.
Changes
We will update this policy when the app's data handling changes and note the date above.