Privacy Policy
Last updated: 2 September 2026
This Privacy Policy describes how Rethought ("we", "us") handles data in connection with the Policy Acknowledgement Tracker app for Confluence Cloud (the "App").
The short version
- The App is built entirely on Atlassian Forge and runs exclusively on Atlassian's infrastructure.
- We do not operate any servers, and no data is ever transmitted outside of Atlassian's platform. The App declares zero egress permissions.
- We (the vendor) have no access to your data. All App data lives in Forge storage within your Atlassian installation.
- The App never reads or stores the body content of your Confluence pages.
Data the App stores
To provide its functionality, the App stores the following in Atlassian Forge storage, scoped to your installation:
| Data | Purpose |
|---|---|
| Page IDs, page titles, and page version numbers of tracked policy pages | Identifying tracked policies and pinning acknowledgements to versions |
| Confluence group IDs/names and Atlassian account IDs and display names of assignees | Determining who must acknowledge each policy |
| Acknowledgement records (account ID, timestamp, page version, campaign cycle) | Tracking status and producing audit evidence |
| Policy configuration (deadlines, cycles, settings) | Operating re-attestation campaigns |
The App does not store page body content, passwords, or any data from outside your Atlassian site.
How data is processed
- All processing happens inside Atlassian Forge functions on Atlassian infrastructure, subject to Atlassian's own security and compliance controls.
- Interactive operations (page search, page reads) run with the requesting user's own permissions, so the App can never expose content a user could not already access.
- A daily scheduled job refreshes group memberships and rolls re-attestation cycles. It processes only the data listed above.
Data sharing
We do not sell, share, or transmit your data to anyone. We cannot: the App has no external endpoints, no analytics, no telemetry, and no egress permissions. Data handling is governed by your agreement with Atlassian and Atlassian's privacy policy for platform-hosted data.
Data retention and deletion
- Acknowledgement history is retained while the App is installed, to serve as audit evidence.
- Removing a policy stops tracking but retains its history.
- Uninstalling the App causes Atlassian to delete the App's stored data for your installation in accordance with Forge platform policy.
Your rights
Because all data resides within your own Atlassian installation and under your organisation's control, data subject requests (access, deletion, correction) can be fulfilled by your own Confluence administrators using the App's export features, or by uninstalling the App. For assistance, contact us at tanzeel@rethought.to.
Changes
We may update this policy from time to time. Material changes will be reflected on this page with an updated date.
Contact
Rethought · Lahore, Pakistan · tanzeel@rethought.to