What leaves your Confluence site
Being precise about this is more useful than reassuring generalities. Diagram source leaves your site in exactly two circumstances: rendering a text language, and using an AI feature.
Everything else, including all storage and all permissions, stays inside your tenant.
#When this matters
Security reviews and data protection assessments.
Deciding whether to self-host the renderer.
Writing your own internal documentation about the app.
#The detail
Thing | What happens |
|---|---|
Text language rendering | The diagram source is sent to a rendering service to be drawn. |
AI features | What you ask for, plus the diagram source when editing an existing one. |
draw.io and Excalidraw | Nothing. They render entirely in your browser. |
Storage | Nothing. Source and previews stay in your Confluence site. |
Permissions | Nothing. Access is decided by Confluence. |
The airtight configuration. A self-hosted Kroki renderer plus AI features disabled means no diagram content reaches us at all, while every editor and language keeps working.
#A few things that catch people out
Self-hosting the renderer removes the first case entirely. See
Turning off AI features removes the second case entirely.
Approving your own egress domains adds a third case that you control and choose.
#Related
Ask us the awkward questions. They have answers.
