Paperlatch
Confirm & Chase for Confluence · Last updated 22 September 2026
The short version. The app runs on Atlassian Forge and stores its data in Atlassian's own app storage, inside your Atlassian cloud site. We operate no server, so no data about you or your users is transmitted to us or to any third party.
For each page where the macro is used, the app stores:
| Data | Why |
|---|---|
| Atlassian account ID of the person who confirmed | To record who confirmed |
| The date and time of the confirmation, in UTC | To record when |
| The page ID and the policy version at that moment | To tie the confirmation to what was confirmed |
| The confirmation text chosen by the page author | To display the prompt |
| The ID and name of the Confluence group chosen as the audience | To work out who has not confirmed |
Nothing else is stored. In particular the app does not store the content of your pages, email addresses, IP addresses, or any usage analytics.
To render the report, the app reads page titles, the public display names of users, and the membership of the group you select as the audience. These are read at the moment the report is opened and are not written to storage.
In Atlassian Forge app storage, within your own Atlassian cloud site and subject to the data residency that applies to that site. The data never leaves Atlassian's infrastructure. We have no facility to read it, export it, or connect to it.
read:page:confluence — to show page titles in the reportread:user:confluence — to show display namesread:group:confluence — to determine the audienceread:confluence-user — to identify the person confirmingstorage:app — to store the confirmations described aboveThe app requests no write permission, does not act on behalf of any user, and does not request access to email addresses.
Confirmations are kept for as long as the app is installed, because their purpose is to serve as a durable record. When the app is uninstalled, Atlassian deletes the app's storage according to its own retention schedule for Forge apps. Because the data is held in your site, a site administrator may also remove it by removing the macro and uninstalling the app.
The stored personal data is an Atlassian account ID and a timestamp. As the operator of your Confluence site you are the controller of that data. If a data subject asks you to erase their confirmations, a site administrator can do so by uninstalling the app, which removes its storage. We cannot act on such a request on your behalf, because we have no access to the data.
The app's listing page on the Atlassian Marketplace is operated by Atlassian, not by us. Atlassian permits partners to attach a Google Analytics measurement ID to their listing page, and we do so in order to see how many people view the listing. That measurement applies only to the Marketplace listing page — it is not present in the app itself and collects nothing from inside your Confluence site.
If this policy changes materially, the listing will be updated and the date at the top of this page will change.