Paperlatch

Privacy Policy

Confirm & Chase for Confluence · Last updated 22 September 2026

The short version. The app runs on Atlassian Forge and stores its data in Atlassian's own app storage, inside your Atlassian cloud site. We operate no server, so no data about you or your users is transmitted to us or to any third party.

What the app stores

For each page where the macro is used, the app stores:

DataWhy
Atlassian account ID of the person who confirmedTo record who confirmed
The date and time of the confirmation, in UTCTo record when
The page ID and the policy version at that momentTo tie the confirmation to what was confirmed
The confirmation text chosen by the page authorTo display the prompt
The ID and name of the Confluence group chosen as the audienceTo work out who has not confirmed

Nothing else is stored. In particular the app does not store the content of your pages, email addresses, IP addresses, or any usage analytics.

What the app reads but does not store

To render the report, the app reads page titles, the public display names of users, and the membership of the group you select as the audience. These are read at the moment the report is opened and are not written to storage.

Where the data lives

In Atlassian Forge app storage, within your own Atlassian cloud site and subject to the data residency that applies to that site. The data never leaves Atlassian's infrastructure. We have no facility to read it, export it, or connect to it.

Permissions the app requests

The app requests no write permission, does not act on behalf of any user, and does not request access to email addresses.

Retention and deletion

Confirmations are kept for as long as the app is installed, because their purpose is to serve as a durable record. When the app is uninstalled, Atlassian deletes the app's storage according to its own retention schedule for Forge apps. Because the data is held in your site, a site administrator may also remove it by removing the macro and uninstalling the app.

Your users' rights

The stored personal data is an Atlassian account ID and a timestamp. As the operator of your Confluence site you are the controller of that data. If a data subject asks you to erase their confirmations, a site administrator can do so by uninstalling the app, which removes its storage. We cannot act on such a request on your behalf, because we have no access to the data.

The Marketplace listing page

The app's listing page on the Atlassian Marketplace is operated by Atlassian, not by us. Atlassian permits partners to attach a Google Analytics measurement ID to their listing page, and we do so in order to see how many people view the listing. That measurement applies only to the Marketplace listing page — it is not present in the app itself and collects nothing from inside your Confluence site.

Changes

If this policy changes materially, the listing will be updated and the date at the top of this page will change.

Contact

support@paperlatch.com