Help · Security and privacy
Security and privacy
The main points:
Documents are private by default and only reachable with a link you created. Every workspace is served from its own subdomain, so one workspace's content cannot be loaded from another's address even with a valid link.
Hosted pages run under a strict security policy: a page can only fetch its own dataset, and Profusia never executes anything from a document on the server.
Profusia has no access to your email, your Jira or the rest of your Google Drive, and never asks for it. The one outside credential it can hold is a Google authorization, and only if an owner switches on Google Docs/Sheets sync: it is encrypted, never shown back, and limited by Google to the files Profusia itself creates in your Drive.
All tokens and keys are stored hashed, expire where appropriate, and can be revoked.
There is a fuller public write-up at /trust, which is the page to send to a security reviewer.