Sealwell for Confluence: Privacy Policy
Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company
This policy explains what information the Sealwell app for Confluence Cloud (the "App") processes, where it is kept, and your rights. It covers only the App, not Atlassian's products, which are governed by Atlassian's own privacy policy.
1. Summary
- The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). It has no servers of its own and sends no data to Great Work or to any third party. It uses no AI service.
- Content your users put in a Secure section is encrypted (AES-256-GCM) with a key created for your site and stored in Forge secret storage, and the encrypted content is stored in Forge app storage for your site. It is not written into Confluence pages.
- The App decrypts content only inside Atlassian's Forge platform, and only for a person who passes the App's permission check. This is encryption at rest with access control, not end-to-end encryption.
- Great Work LLC has no access to your content, your audit log or your settings.
2. What the App processes
| Data | Why | Where it lives |
|---|---|---|
| Section content (text, secret names and values) | To show it to the people your owners chose | Encrypted in Forge app storage for your site, until deleted |
| Section metadata: page id, macro id, title, mode, owners and audience (Atlassian account ids, group ids and names, optional end dates), expiry, who created and last changed it and when, version, key version | To decide who may see each section and to manage it | Forge app storage, until the section is deleted |
| Audit events: time, Atlassian account id of the person, action (created, edited, viewed, revealed, denied, copied, deleted, admin actions), section title and id, page id, and a short detail such as "secret #2" or "audience +1/-0" | So owners and admins can see who accessed what | Forge app storage, kept for the retention your admin picks (90 days, 180 days, 1 year or forever) |
| Settings: who may create sections, owner-group requirement, auto-hide time, audit retention | To apply your admins' choices | Forge app storage |
| The site encryption key(s) | To encrypt and decrypt section content | Forge secret storage, never shown or exported |
| Group memberships and page permissions of the person viewing | To make the access decision | Read from Confluence at the moment of each request, not stored |
The App never writes secret names or values to the audit log or to application logs. It does not collect email addresses, IP addresses, passwords, API tokens, payment information or analytics. It sets no cookies and loads no third-party scripts.
3. What the App reads from Confluence
Whether a person can view or edit a page (Confluence's permission check), the groups a person belongs to, the list of groups (for the pickers), and page titles, links and status (for the admin list). The App does not read page bodies and never writes to Confluence.
4. Where data is stored
All App data is stored by Atlassian in Forge app storage and Forge secret storage for your site, subject to Atlassian's data residency settings. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors.
5. Who can see what
- A section's content: its owners, and its audience while their access and the section are current, provided Confluence also lets them view the page.
- People outside the audience see the section title and owners (or nothing, if the owner chose "hide completely").
- Section owners see that section's activity log.
- Confluence admins see the list of sections (titles, pages, owners, audience size, never the content), the site audit log and settings, and can reassign owners or delete sections. These admin actions are logged.
- Great Work LLC: no access. If you open a support request, we see only what you send us.
- Atlassian: as the platform operator, under Atlassian's privacy policy.
6. Retention and deletion
Section content stays until an owner or admin deletes it, or an admin removes sections whose page was deleted from the trash. Audit events expire after the retention period your admin picks. Uninstalling the App removes its Forge storage, including the encryption keys, according to Atlassian's Forge data deletion process; after that, section content cannot be recovered by anyone, including Great Work.
7. Support requests
If you contact support through our help desk or by email, we process what you send (name, email, message, attachments) only to answer you, keep it up to 24 months, and delete it sooner on request. Please never send us protected content or secrets.
8. Your rights
Depending on where you live (for example EU/UK GDPR or US state privacy laws), you may have the right to access, correct, delete or port personal data and to object to processing. For data in your Atlassian site, your organization (the Atlassian customer) is the controller and Atlassian processes it on your behalf; your admins can delete sections or uninstall the App. For support data, Great Work LLC is the controller: email hello@greatwork.company. We respond within 30 days.
9. Security
Content is encrypted at rest with authenticated encryption bound to each section, keys are held separately in Forge secret storage and can be rotated by admins, every request is checked on the server against Confluence permissions, groups and the section's owners and audience before anything is decrypted, and admin features are only available on Confluence's admin-only settings page. Report vulnerabilities to hello@greatwork.company.
10. Children
The App is a business tool and is not directed to children under 16.
11. Changes
We will post changes here and update the effective date. Material changes will also be announced in the App's Marketplace release notes.
12. Contact
Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company