MSG/EML Email Viewer for Confluence Terms of Use

Effective 19 August 2026

About these terms

These are Provider-Specific Terms that supplement the Bonterms Standard End User Agreement, Version 1.0 (the "Standard Agreement"). The Standard Agreement governs your use of MSG/EML Email Viewer for Confluence and is incorporated by reference, except where these Provider-Specific Terms expressly override or supplement it. Where a provision of these Provider-Specific Terms conflicts with the Standard Agreement, these Provider-Specific Terms prevail to the extent of the conflict, and in all other respects the Standard Agreement continues to apply. Capitalised terms used and not defined here have the meanings given to them in the Standard Agreement. The current text of the Bonterms Standard End User Agreement, Version 1.0 is published at https://bonterms.com/standard/end-user-agreement-v1/.

Who we are

MSG/EML Email Viewer for Confluence is provided by Cloudscript Pty Ltd (ABN 14 700 662 362) ("we", "us"), as a plugin available on the Atlassian Marketplace for Forge. By installing or using MSG/EML Email Viewer for Confluence, you agree to these terms.

The service

MSG/EML Email Viewer for Confluence is a Confluence Cloud macro. It reads a .msg or .eml file already attached to the page it is placed on and renders it as an email card showing the subject, sender, recipients, date, body, inline images and a list of the email's own attachments. Each listed attachment can be downloaded individually from the card. Attachments are never rendered or opened in place, and a message nested inside another message is listed rather than expanded. An author can also upload an email file from the macro's configuration screen; the file is held in the browser as a pending selection and is sent only when the author presses Save, at which point it becomes an ordinary Confluence page attachment. Files above 50 MiB (52,428,800 bytes) are declined rather than retrieved.

The macro declares two Forge permission scopes, read:attachment:confluence to list and read the page's attachments and write:confluence-file to create an attachment on the upload path, and it declares no outbound network access to any host. Email content is retrieved from the page's own Confluence attachments over Atlassian's platform APIs, parsed in the viewing user's browser, and written to no store at any point. Remote content referenced by an email is blocked when the card is drawn, and the viewing user can choose to load it for that render. Every read travels the acting user's own Confluence permissions, so what a given viewer can see is decided by Confluence rather than by the app. Where a file cannot be read or rendered, the macro shows a card naming what happened instead of rendering a partial or misleading result.

A page containing the macro can be exported to PDF, which reproduces the email card as it appears on the page, including inline images. Word and other static export paths receive a card naming the configured attachment and pointing to PDF as the export format that carries the rendered email. On those non-PDF export paths a function hosted on Atlassian's Forge platform receives the macro's configured attachment file name and display label in order to produce that card. No email body, recipient list, or attachment content reaches that function, and it retains nothing and sends nothing onward.

Access and licensing

MSG/EML Email Viewer for Confluence is licensed through the Atlassian Marketplace under Atlassian's standard marketplace terms for Forge apps. Your use of Atlassian's host product (Confluence) remains subject to your separate agreement with Atlassian. Licensing is enforced from installation: where the licence is inactive, the macro does not render an email, and does not permit a new macro instance to be inserted or an existing one to be reconfigured. Guest and anonymous viewers of a page may see a rendered card where your Confluence site is configured to permit it, subject in every case to the same Confluence permissions that govern any other content on the page.

Restrictions on use

Except as expressly permitted by these terms or by Atlassian's marketplace terms for Forge apps, you must not: reverse engineer, decompile, or attempt to extract the source code of MSG/EML Email Viewer for Confluence; resell, sublicense, rent, lease, or redistribute MSG/EML Email Viewer for Confluence outside the Atlassian Marketplace; remove or obscure any proprietary notice in MSG/EML Email Viewer for Confluence; or use MSG/EML Email Viewer for Confluence in a manner that breaches Atlassian's acceptable use policies for the host product.

You must also not use MSG/EML Email Viewer for Confluence, or information derived from it, to reverse engineer or replicate its source code or its rendering behaviour for a product or service that competes with it, or to publish a benchmark or comparative assessment of it that misrepresents how it behaves. Nothing in these terms restricts you from developing, buying, or using any other product, from competing with us generally, or from evaluating MSG/EML Email Viewer for Confluence fairly and reporting the result. This paragraph replaces section 7.3(f) of the Standard Agreement, which does not apply to your use of MSG/EML Email Viewer for Confluence.

Your content and your responsibilities

You decide which email files are attached to your Confluence pages, which of them a macro instance displays, and who may view the pages that carry them. The app renders what it is pointed at and applies your Confluence site's own permissions to every read; it makes no assessment of whether a particular email is appropriate to store or display in a given space, and it provides no redaction, classification, or access control of its own. Emails frequently contain personal information about third parties, and you remain responsible for having a lawful basis to hold and display that information in Confluence, and for setting page and space permissions accordingly.

Intellectual property

MSG/EML Email Viewer for Confluence, including its source code, design, and all related intellectual property, is owned by Cloudscript Pty Ltd and its licensors. These terms grant you a licence to use MSG/EML Email Viewer for Confluence as described above; they do not transfer any ownership or intellectual property rights to you. Nothing in these terms gives us any ownership of, or licence to, the email files or other content you hold in your Confluence site.

Data handling

For details on what data MSG/EML Email Viewer for Confluence collects, where it is stored and processed, and how long it is retained, see our Privacy Policy.

Third-party and open-source components

MSG/EML Email Viewer for Confluence is built on the Atlassian Forge platform and includes the following third-party runtime components. The Atlassian Forge SDK packages @forge/bridge (frontend) and @forge/api (used by the export function for a server-side licence read) are provided by Atlassian under Atlassian's developer terms. React and React DOM, used for the macro's user interface, are licensed under the MIT Licence. @kenjiuno/msgreader, which parses .msg files, is licensed under the Apache Licence 2.0, and @kenjiuno/decompressrtf, which decompresses the compressed RTF body of a .msg file, is licensed under the BSD 2-Clause Licence. postal-mime, which parses .eml files, is licensed under the MIT No Attribution Licence. DOMPurify, used to sanitise email HTML before it is rendered, is licensed under the Mozilla Public Licence 2.0 or the Apache Licence 2.0 at the recipient's option. iconv-lite (character-encoding conversion), buffer, and string_decoder are licensed under the MIT Licence.

Security Measures

This section sets out the security posture specific to MSG/EML Email Viewer for Confluence and supplements the security provisions of the Standard Agreement. As described under "The service" above, the app declares no outbound network access to any host and operates no data store of its own; its manifest declares neither. Because there is no Cloudscript-operated server, database, cache, or log destination in this app's path, there is no separate Cloudscript-operated store or transmission path for this app to secure. Email content travels only between your own Confluence attachments and the viewing user's browser, over Atlassian's own platform. Email HTML is sanitised before it is rendered, remote content is blocked by default, and parsing runs in a Web Worker under a fifteen-second deadline so that a malformed or hostile file yields an error card rather than an unresponsive page.

The platform-level and vendor-level practices that apply to the app (Atlassian Forge's own sandboxing and egress controls, the controls on our developer and publishing accounts, and our vulnerability-handling process) are described in the site-wide Security Policy at https://cloudscript.io/security and are not restated here. Suspected vulnerabilities in this app can be reported to security@cloudscript.io.

Data Processing Addendum

The Data Processing Addendum for MSG/EML Email Viewer for Confluence forms Schedule 1 to these Provider-Specific Terms. It is the Data Protection Addendum identified in these Provider-Specific Terms for the purposes of the Standard Agreement.

Our assessed position for this app is that we supply software and are neither a controller nor a processor of personal data within the meaning of the General Data Protection Regulation, and neither a business nor a service provider within the meaning of the California Consumer Privacy Act. The Addendum is published because procurement, vendor-assurance and internal governance processes commonly require a data processing document from every software supplier irrespective of that supplier's role under data protection law, and it is drafted to describe what the app actually does and the commitments we can actually meet. Publishing it is not an acknowledgement, admission, or acceptance that we are a processor, a service provider, or a controller in respect of the app, and it must not be construed as one. The reasoning is set out in the Addendum under "Status of this document" and "Roles of the parties".

Support

Support requests: support@cloudscript.io.

Changes to these terms

We may update these Provider-Specific Terms from time to time. This section governs changes to these Provider-Specific Terms only; the Standard Agreement is amended only as that agreement itself provides.

Where a change is material, we will publish the revised terms on this page at least 30 days before they take effect, showing the date on which they take effect. If you do not accept a material change, you may terminate your subscription to MSG/EML Email Viewer for Confluence without penalty at any time before that date. Where a change is not material, it takes effect when it is published on this page, and the "Effective" date at the top of this page is updated to the date of the revision.

A change made under this section does not apply retrospectively, and does not materially reduce our overall obligations to you during a subscription term that has already begun.

Termination

Your licence to use MSG/EML Email Viewer for Confluence ends when you uninstall it or when the licence lapses. The app operates no data store of its own and makes no outbound network request to any host, so there is no app-side copy of your data for it to delete on uninstall, and no Cloudscript-held record of your email content exists at any point. The macro's own configuration (the attachment identifier, the attachment file name, and the display label) is held as part of your Confluence page content, and any email file uploaded through the macro is an ordinary Confluence page attachment. Both remain yours, in your own Confluence site, and are unaffected by whether this app is installed.

Neither is subject to a retention period set by this app, because the app sets none. It declares no Forge storage module and implements no uninstall lifecycle hook, so there is nothing on the app's side for a retention or deletion step to act on, at uninstall or at any other time. Both follow Confluence's own attachment and page lifecycle rather than any lifecycle this app imposes, and the app neither controls nor varies that lifecycle. For how this data is handled generally, see our Privacy Policy.

Disclaimer of warranties

Except as expressly stated in these terms, MSG/EML Email Viewer for Confluence is provided "as is" and "as available," without warranties of any kind, whether express, implied, or statutory, including any implied warranties of merchantability, fitness for a particular purpose, or non-infringement, to the maximum extent permitted by applicable law. In particular, we do not warrant that every email file will render completely or exactly as it appeared in the mail client that produced it. The app does not convert the layout of a message whose body is available only as native RTF, and it does not render Windows metafile images. Where a file cannot be read or rendered, the app shows a card naming what happened. The app is a viewer, and it is not a substitute for an archival or evidential system of record. Nothing in this section excludes, restricts, or modifies any guarantee, condition, or warranty that cannot lawfully be excluded, restricted, or modified under the Australian Consumer Law or other applicable law; where such a guarantee applies, the "Limitation of liability" section below governs the extent of our liability for a failure to comply with it.

Limitation of liability

To the maximum extent permitted by applicable law, Cloudscript Pty Ltd will not be liable for any indirect, incidental, special, consequential, or punitive damages, or any loss of profits, revenue, or data, arising out of or in connection with your use of MSG/EML Email Viewer for Confluence, whether in contract, tort, or otherwise, even if advised of the possibility of such damages. Our total aggregate liability is capped as set out in section 14 of the Standard Agreement, which these Provider-Specific Terms do not vary. Nothing in these terms excludes or limits any guarantee, warranty, or other right that cannot lawfully be excluded or limited under the Australian Consumer Law or other applicable law.

Governing law

These terms are governed by the laws of New South Wales (NSW), Australia, and the courts of New South Wales have exclusive jurisdiction over any action arising out of or relating to them. For the purposes of the Standard Agreement, the Governing Law is the law of New South Wales and the Courts are the courts of New South Wales, in place of the default the Standard Agreement would otherwise apply.

Contact

Cloudscript Pty Ltd (ABN 14 700 662 362)
Support: support@cloudscript.io
Security: security@cloudscript.io