Lessonmark Privacy Policy
Effective date: October 1, 2026
This policy covers Lessonmark: Courses, Quizzes and Training for Confluence (the "App"), a Forge app for Confluence Cloud made by Great Work LLC ("Great Work", "we"), 651 N Broad St Suite 206, Middletown, DE 19709, USA, hello@greatwork.company. Publish at https://greatwork.company/apps/lessonmark/privacy.
1. The short version
The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). Everything it stores stays in your Atlassian site's Forge storage. It has no servers of its own, sends nothing outside Atlassian, and has no analytics or tracking. Great Work cannot see your courses, quizzes, answers or records.
2. What the App stores
In Forge SQL for your site:
- Courses: titles, descriptions, steps (page ids and titles, quiz ids), settings, owners (Atlassian account ids).
- Quizzes: questions, options, right answers, settings, owner, and the page and macro they sit on.
- Assignments: the course, groups and people assigned, due dates, reminder settings, and for each assigned person when they were assigned and when they were last reminded.
- Progress: for each learner and step, when they opened and confirmed it, the page version confirmed, and which quiz attempt passed it. Cleared when the course is completed (the record keeps the evidence).
- Quiz attempts: depends on the quiz's answer privacy setting, which every learner sees
before answering:
- Named: the account id, answers, score and result.
- Private answers: the account id and whether they passed. Their answers and score are stored separately with no account id and only the ISO week, and are shown only as totals once the site's minimum number of people have answered.
- Anonymous: no account id. A salted hash of the account id is kept only to count attempts; answers are stored as in Private answers.
- Completion records: the course and version, completion and expiry dates, the steps with page versions and quiz results, the statement signed, a salted hash of the person, and beside it (not in the signed part) the account id, display name and typed signature.
- Settings: training manager groups, the minimum responses setting, and your site's URL (for links in reminder comments).
In Forge secret storage: the key used to sign completion records, and the last license state the App saw.
3. What the App reads from Confluence
As the person using it: their account id, display name and groups; whether they can view or edit a page; page and blog post titles and version numbers; search results for page pickers and CQL queries; space keys named in a CQL query; group names and people for pickers; display names for reports. As the App, in the daily sync: the members of assigned groups and display names. The App never reads page bodies.
4. What the App writes to Confluence
Only reminder comments, and only when an assignment has a reminder page: one footer comment that mentions the people who are due or overdue, posted as the App. Confluence then notifies them by their own notification settings. Anyone who can view that page can read the comment.
5. Where data is stored
All App data is stored by Atlassian in Forge SQL and Forge storage for your site, subject to Atlassian's data residency settings. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors.
6. Who can see what
- Learners: their own training, progress, attempts, records and certificates.
- Course owners: their courses' reports and records, and results of quizzes they can edit.
- Training managers (Confluence admins and the groups admins choose): every course, quiz, assignment, report and record.
- People who can edit a page with a quiz: that quiz and its results.
- Great Work LLC: no access. If you open a support request, we see only what you send us.
- Atlassian: as the platform operator, under Atlassian's privacy policy.
7. Retention and deletion
Courses, quizzes, assignments, attempts and records stay until your admins remove them or uninstall the App. Completion records are kept on purpose: they are your audit trail. When an Atlassian account is closed, Atlassian's personal data reporting tells the App (checked weekly), and the App deletes that person's progress and assignments, removes the account id and answers from their quiz attempts, and erases the account id, display name, typed signature and salt from their completion records. The signed part of those records stays so the chain still verifies, but nothing left identifies the person. Uninstalling the App removes its Forge storage according to Atlassian's Forge data deletion process.
8. Support requests
If you contact support through our help desk or by email, we process what you send (name, email, message, attachments) only to answer you, keep it up to 24 months, and delete it sooner on request.
9. Your rights
Depending on where you live (for example EU/UK GDPR or US state privacy laws), you may have the right to access, correct, delete or port personal data and to object to processing. For data in your Atlassian site, your organization (the Atlassian customer) is the controller and Atlassian processes it on your behalf; your admins can export records and reports or uninstall the App. For support data, Great Work LLC is the controller: email hello@greatwork.company. We respond within 30 days.
10. Security
Every request is checked on the server: learners only open pages Confluence lets them view, and editing, reports and records are limited to the people listed in section 6. Completion records are append-only, hash-chained and signed with a per-site key held in Forge secret storage. Report vulnerabilities to hello@greatwork.company.
11. Children
The App is a business tool and is not directed to children under 16.
12. Changes
We will post changes here and update the effective date. Material changes will also be announced in the App's Marketplace release notes.
13. Contact
Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company