Entrymark Privacy Policy
Effective date: October 2, 2026
This policy covers Entrymark: Data Forms for Confluence (the "App"), a Forge app published on the Atlassian Marketplace by Great Work LLC ("Great Work", "we", "us"), 651 N Broad St Suite 206, Middletown, DE 19709, USA. Contact: hello@greatwork.company.
Summary
The App runs entirely on Atlassian's Forge platform. Everything it stores stays in Atlassian-hosted Forge storage for your Confluence site. Great Work does not run servers for the App, does not receive your forms or responses, and does not sell or share personal data.
What the App stores
Inside Forge SQL storage for your site:
- For each form: the page or blog post id, its space key, the macro's id on the page, a short report code, the form's questions and settings (title, intro text, question types, options, validation rules, show-when rules, close date, response limit, who can see responses, notification settings and the Atlassian account IDs of the people to notify), the Atlassian account ID of the form owner, whether it is anonymous, a random per-form value, any manual close or reopen, the id of the notification comment thread, notification counters, and timestamps.
- For each response to a named form: the respondent's Atlassian account ID, their answers, a status (New, Seen, Done, Archived), and when it was sent and last edited.
- For each response to an anonymous form: the answers, a status, and the day it was sent (no time of day). No account ID is stored with the response. If the form allows one response per person, the App also stores a one-way code derived from the person's account ID and the form's random value, kept separately from the responses and not linked to any of them. It only lets the App recognize that the person already responded.
Answers can contain whatever respondents type, and person and page answers contain Atlassian account IDs and page ids and titles. The App does not store email addresses or page content.
What the App reads from Confluence
As the signed-in user, the App asks Confluence: whether that user may edit the form's page (to decide who can build the form and see or manage responses); which pages the user can see (for page answers, for copying questions into a copied page, and for reports that point at a form on another page); pages whose title matches what the user types in a page question; and display names for respondents and person answers (shown in the responses table and CSV export). These responses are used in the moment and not stored, except the title of a page chosen as an answer.
Once an hour, for forms with new or edited responses and notifications turned on, the App reads the form page's status and title as the App (there is no signed-in user for scheduled work).
Notifications
When a form owner turns on notifications, the App adds a footer comment on the form's page (and later replies to it) that @mentions the owner and the people the owner chose, with the number of new and edited responses. Confluence then sends its own notifications. The comment contains counts only, never answers or respondent names, and anyone who can view the page can read it.
CSV exports
People who can see a form's responses can export them. For named forms the export includes respondents' display names and account IDs. The CSV is shown in the user's browser for them to copy; the App does not send it anywhere.
What leaves Atlassian
Nothing. The App has no external network permissions and no remote backend. Great Work cannot see your forms, responses or users. Atlassian provides the hosting and processes data under its own terms (https://www.atlassian.com/legal/privacy-policy) as the platform provider.
Logs
Forge keeps function logs that Great Work can read for troubleshooting. The App logs error messages and notification run counts, not questions, answers or account IDs, and never logs tokens. Atlassian controls log retention.
Who can see what
Anyone who can view a page can fill in its form while it is open. Respondents see their own named responses. Responses are visible to the form owner and, depending on the form's setting, to people who can edit the page or to everyone who can view it. The form owner and (unless the form is owner-only) page editors can set statuses, delete responses and close or reopen the form. Only the owner changes who can see responses. Great Work staff have no access to your site unless you invite us for support.
Retention and deletion
Data stays while the App is installed. Respondents can withdraw their own named responses while the form is open, if the form allows editing. People who manage a form can delete responses, and the owner can delete the form with all its responses. When the App is uninstalled, Atlassian deletes the App's Forge storage for that site according to the Forge platform's data deletion process.
Data residency
Forge storage follows your Confluence site's data residency location where Atlassian supports it for Forge apps.
Your rights
Because Great Work does not receive or hold your data, requests to access, correct or delete personal data should go to your Confluence site admin. We will help: email hello@greatwork.company.
Children
The App is a business tool and is not directed at children under 16.
Changes
We will post changes on this page and update the effective date. Material changes will be announced in the App's release notes at least 30 days before they apply.
Contact
Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company. Support portal: see the Marketplace listing.