HTML for Confluence Pages — Privacy Policy

Effective date: 2026-09-01 Last updated: 2026-09-01

This privacy policy describes how HTML for Confluence Pages ("we", "us", "the app") handles your data. HTML for Confluence Pages is an Atlassian Marketplace app distributed via the Atlassian Forge platform. By installing HTML for Confluence Pages, you agree to this policy.


Summary in plain English


1. Data we access

HTML for Confluence Pages is designed to collect and store no page content, ever.

When a Confluence page containing the HTML Block macro is viewed, the app reads only what it needs to render that block:

From your Atlassian site (via Forge asUser() calls)

Every read runs with the viewing user's own permissions. If the viewer cannot see the page or the attachment, the app cannot read it either, and shows a "no permission" message instead of content.

The block's authored HTML, CSS and JavaScript live inside the page content itself as ordinary macro configuration, stored by Confluence exactly like any other macro on the page. Rendering (sanitization, sandboxed display, auto-height) happens entirely in the viewer's browser, inside the app's sealed iframe. Nothing is written to disk, cached, transmitted off-platform, or retained by the app between page views.

2. Where data is stored

HTML for Confluence Pages stores the following entities in Forge Key Value Store, hosted and encrypted by Atlassian:

HTML for Confluence Pages stores exactly one entity in Forge Key Value Store: a single settings record containing two admin preferences — allowJs (boolean) and maxProfile (one of strict / standard / trusted). It contains no user identifiers, no page content, and no personal data of any kind. Nothing else is stored — no user records, no cached content, no audit log.

Forge Key Value Store data is encrypted at rest by Atlassian using AES-256 and tied to your Atlassian Cloud site. HTML for Confluence Pages operates as a tenant inside this storage; we cannot access the data without going through Forge's authenticated APIs invoked by an admin user of your org.

HTML for Confluence Pages performs all analysis inside Atlassian's Forge runtime. No End-User Data is transmitted to any third party or outside Atlassian's infrastructure.

Data residency: Forge storage follows Atlassian's data residency commitments. If your Atlassian site is in a specific data region, HTML for Confluence Pages's storage stays in that region.


3. Data we share with third parties

None. The app makes no external network calls of any kind. It has no analytics provider, no error reporting service, no AI vendor, no marketing tools, and no integrations with anything outside Atlassian Forge.

The only APIs the app contacts are Atlassian's own Confluence REST APIs (attachment reads) via Forge's internal proxy — Atlassian-operated endpoints inside Forge's runtime, not external services. No End-User Data ever leaves Atlassian's infrastructure. (If a page author's own HTML embeds an external iframe or image, the viewer's browser loads that resource exactly as it would for a link on the page — the app itself contacts nothing.)

3a. Account actions and data changes

None against user accounts or content. The app has no content write permissions and makes no changes to any account, page, or attachment. Its only write is two site-wide admin preference values (see storage below), set deliberately by a Confluence admin on the app's settings screen.

4. Data we do NOT collect


5. Data retention

The only stored data is the two-value admin settings record above, which persists until changed by an admin or until the app is uninstalled (Forge deletes app storage on uninstall). All page content is rendered in memory in the viewer's browser and discarded; there are no working records, no logs of block content, and no API keys.

On uninstall: Atlassian automatically purges all Forge storage associated with the app within 30 days per Atlassian's Forge data lifecycle policy.


5a. Automatic erasure on Atlassian account closure

HTML for Confluence Pages implements Atlassian's personal-data reporting flow. Once a week, HTML for Confluence Pages posts the list of Atlassian accountIds for which it stores personal data to Atlassian's report-accounts endpoint. If Atlassian responds that an account has been closed (the user has exercised right-to-erasure, or the account has been permanently deactivated) or updated (data is stale or the user requested a refresh):

There is nothing to erase on account closure — the app stores no accountId, no displayName, no email, and no per-user records of any kind. The admin settings record contains no reference to who set it. The weekly report-accounts post returns an empty list because there is no personal data tracked to report.

You can also trigger the same erasure path for any user by clearing their entries through any in-app "Clear all data" developer tool, or by uninstalling HTML for Confluence Pages entirely.


6. Your rights

You have the right to:

For requests under GDPR, CCPA, or similar regulations, contact us at support@taskhooker.com. The automatic erasure flow runs weekly; if you need faster action, email us and we'll process the deletion manually.


7. Children's privacy

HTML for Confluence Pages is a business administration tool for Atlassian Cloud organisations. It is not intended for, marketed to, or used by individuals under 18. We do not knowingly collect data about minors.


8. Changes to this policy

We may update this policy when materially new features ship. The "Last updated" date at the top reflects the most recent change. Material changes will be communicated via the Marketplace listing and any in-app notice we deem appropriate.


9. Contact

For privacy questions: