Treekeep Privacy Policy
Effective date: October 1, 2026
This policy covers Treekeep: Edit Restriction Inheritance for Confluence (the "App"), a Forge app published on the Atlassian Marketplace by Great Work LLC ("Great Work", "we", "us"), 651 N Broad St Suite 206, Middletown, DE 19709, USA. Contact: hello@greatwork.company.
Summary
The App runs entirely on Atlassian's Forge platform. It passes page edit restrictions down a page tree, makes bulk restriction changes you preview and approve, and reports pages whose restrictions differ from their parent. It sends nothing outside Atlassian. Great Work does not run servers for the App, does not receive your content, and does not sell or share personal data.
What the App stores
All in Forge storage for your site:
- Inheritance rules: the top page's id, title and space key, the mode (Match or Add), whether page creators are kept as editors, pages that opted out, whether the rule is paused, and the Atlassian account id of the person who turned it on.
- Change records (kept 180 days, then deleted automatically): for each change, what was asked (for example "Add acme-design to edit restrictions"), the CQL query or top page used, the account id of the person who asked, and for each page: its id and title, its restriction list before and after (Atlassian account ids and group ids with display names), and the result.
- Report results (kept 180 days): the same per-page data for pages whose restrictions differ from their parent.
The App does not store page content.
What the App reads and changes
- It reads page titles, page ancestors and page restrictions, searches pages with CQL, reads the groups of the person using it (so it never removes their own access), and checks group existence and whether a group has members.
- It changes page restrictions only: when a person applies a previewed change, when they undo one, and when an inheritance rule they turned on applies to a new, moved or copied page or follows a change to the top page. It never changes page content and never deletes pages.
- Every page a person changes from a page is checked against that person's own edit permission; changes started from Space settings or Confluence admin settings cover pages the admin can view.
- Confluence requires the app making a restriction change to be listed in that restriction, so the App's own account appears as an editor on pages it restricts.
What leaves Atlassian
Nothing. The App has no external network permissions and no remote backend. Great Work cannot see your pages or users. Atlassian provides the hosting and processes data under its own terms (https://www.atlassian.com/legal/privacy-policy) as the platform provider.
Logs
Forge keeps function logs that Great Work can read for troubleshooting. The App logs only error messages, event types and page ids, never page content or restriction lists, and never logs tokens. Atlassian controls log retention.
Retention and deletion
Change records and reports expire after 180 days. Rules stay until someone turns them off or the App is uninstalled. When the App is uninstalled, Atlassian deletes the App's Forge storage for that site according to the Forge platform's data deletion process. Page restrictions the App set are ordinary Confluence restrictions and stay on your pages; your admins can change them in Confluence as usual.
Data residency
Forge storage follows your Confluence site's data residency location where Atlassian supports it for Forge apps.
Your rights
Because Great Work does not receive or hold your data, requests to access, correct or delete personal data (account ids and display names in change records) should go to your Confluence site admin. We will help: email hello@greatwork.company.
Children
The App is a business tool and is not directed at children under 16.
Changes
We will post changes on this page and update the effective date. Material changes will be announced in the App's release notes at least 30 days before they apply.
Contact
Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company. Support portal: see the Marketplace listing.