Privacy
What our apps do with data, where that data lives, and who can reach it.
The short version
Calibro Software’s apps are Atlassian Forge apps. What each one creates — Calibro Track’s time entries and reports, Calibro Sketch’s diagrams — is stored inside your own Atlassian site’s infrastructure, not on a server of ours. We hold no copy of it and we cannot read it.
This website counts visits with Google Analytics, which sets one cookie, and carries a measurement pixel from OpenAI that attributes visits arriving from ads on ChatGPT. Everything else it collects, you type in yourself: an email address on an in-development product’s interest form or a roadmap request, and a vote on the roadmap, which asks for nothing about you at all.
The apps
Two of our five products are released and hold real data: Calibro Track and Calibro Sketch. What follows is what each one stores, reads and does with it. The other three — Calibro Pulse, Calibro Explore and Calibro Prioritize — are still in development and have nothing of their own here yet; see the interest-list forms below for the only thing they currently collect.
Calibro Track
What it stores. Calibro Track keeps its own records in Forge SQL, a database Atlassian provisions and runs for the app inside your site’s environment. Those records are:
- Time entries — the issue and project the work was against, the Atlassian account ID of the person who logged it, the date, the number of minutes, an optional description, and whether it is draft, submitted or approved.
- Approvals — the account ID of the approver, the decision, an optional reason, and when it was made.
- Project approvers — which account IDs may approve time for which projects.
- Saved reports — the report name, the owner’s account ID, and the grouping and filters that define it. Computed results are cached alongside for speed.
- Jira field metadata — the names and types of fields available to group a report by, cached so building a report does not re-enumerate them every time.
- Preferences and team settings — week start, date and duration format, weekly target, and whether approved time is locked.
The description on a time entry is free text you write. It is the one field in the app that holds something because a person typed it rather than because Jira already knew it, so treat it the way you would treat a Jira comment.
What it reads from Jira. The app holds three permissions and no others: read:jira-work (issues, projects and field values, so a report can group by them), read:jira-user (resolving account IDs to display names) and storage:app (the database above). Nothing in the app writes to Jira. Everything it reads is bounded by the Jira permissions of whoever is asking: a report covers only the projects that person can already browse.
Calibro Sketch
What it stores. A Sketch is Confluence’s own custom content — the drawing itself, stored, versioned and permissioned by Confluence exactly the way a page is. Calibro Sketch keeps no database of its own and holds no separate copy of anything you draw.
What it reads. The app holds these permissions: read:custom-content:confluence, write:custom-content:confluence and delete:custom-content:confluence (a Sketch’s own body), read:page:confluence and read:space:confluence (the page and space a Sketch is embedded in, for its breadcrumb), read:user:confluence (who wrote a page, for a Confluence smart object’s byline), and read:jira-work plus read:jira-user (the Jira issues you put on a canvas, and their assignee).
The app also asks for permission to create a Jira issue on your behalf (write:jira-work). That permission is granted at install like the others, and we’d rather list it and say plainly that this release’s interface does not use it — there is no button anywhere in the app that creates a Jira issue — than leave an unused grant unexplained on your install screen.
What’s the same for both
Neither app has a database of its own beyond what’s described above, neither declares any external egress — enforced by the Forge platform itself, not a promise we’re making unassisted — and neither gives us production access to what you store. If you report a bug, we can see what you choose to tell us and nothing else.
For data either app handles, your organisation is the controller and Calibro Software is a processor acting on your instructions. Atlassian is a sub-processor, and in practice the only one: it provides the compute and the storage both apps run on, and its own privacy commitments cover that layer.
Deletion
Uninstalling Calibro Track removes its database and everything in it; individual entries can also be deleted from inside the app at any time. Uninstalling Calibro Sketch leaves nothing extra to delete on our side — a Sketch is Confluence content, so it lives and dies with your Confluence data the same as a page does. Either way, there is no separate deletion request to file with us, because there is no copy for us to hold.
This website
Analytics
Every page here carries Google Analytics. It sets one cookie and records the pages you view, roughly where in the world you are, the kind of device and browser you are using, and how you arrived — the site that linked you, or the campaign tag on the link. We use it to see which pages are read, which links bring people here, and whether the ads we buy lead anywhere, and for nothing else. We have not turned on advertising features and we do not run ads against it. Until 1 September 2026 this ran only after a consent banner was accepted; it now runs on every visit, which is why the banner is gone.
Every page also carries a measurement pixel from OpenAI, because we advertise on ChatGPT. If you arrive from one of those ads it recognises the click, and if you then follow a link to the Atlassian Marketplace it reports that the ad led somewhere — that is the whole of its job. Clicking a Marketplace link is also recorded in Google Analytics, as an event named for the listing you left for.
The lawful basis for both is our legitimate interest in knowing whether this site and its advertising work. Google and OpenAI each act as our processor for their part, and their own terms cover what they do with the data on their side. Nobody else receives it. If you would rather not be counted, the common content-blocking browser extensions stop both scripts, and the site works identically without them.
Roadmap votes
Calibro Track’s roadmap lets you vote for what you want built next. Voting asks for nothing about you: no email, no name, no sign-up. What it records is which item you voted for and when.
To stop one person voting for the same thing repeatedly, your browser is given an anonymous identifier by Firebase when you first vote. It is a random string. It is not an account, it holds no email address or profile, it is not shared with anyone, and it tells us nothing about who you are — only that two votes for the same item came from the same browser, which is the one thing it exists to detect. It is stored in your browser, and clearing your site data removes it.
We do not publish vote totals, so nothing you do here appears on the site. The numbers beside each item are written by hand when we review the list. Votes are a signal to us, not a scoreboard.
Requests you submit
The roadmap also carries a form for asking for something that isn’t on the list. It stores what you typed, your email address, and when you sent it. The address is there so we can reply and tell you if the thing ships — that is the whole reason it is required, and we use it for nothing else. No newsletter, and we do not pass it on.
Nothing you submit is published. The roadmap is curated by hand, so a request is a message to us rather than something that appears on the site. Ask us to delete yours at any time at support@calibrosoftware.com and we will, without asking why.
The interest-list forms
Calibro Pulse, Calibro Explore and Calibro Prioritize are not released. Each one’s page carries a form for telling us you want to hear when it is. Nothing is collected unless you fill it in and submit it.
When you do, we store:
- Your email address — the one you typed.
- Your note, if you wrote one — the free-text answer to what you would use it for.
- Which link you clicked to open the form, so we know which part of the page persuaded you. This is a short label such as
heroorfooter-band, not a browsing history. - The time you submitted it, taken from your own device’s clock.
- Which product the form was on, so a Pulse signup and an Explore signup don’t get mixed up.
We do not collect your name, your employer, your IP address or anything about your Atlassian site. Submitting the form sets no cookie of its own, and what you send is not joined up with analytics: the visit and the signup are two unconnected records, and we have no way to tell you they are the same person.
The lawful basis is your consent, given by submitting the form. We use the address to send you one email when that product is installable, and for nothing else: no newsletter, no drip sequence, no announcements about anything else. We do not sell it, share it or pass it to any other company.
All three forms share one collection, held in Google Cloud Firestore on infrastructure Google operates for us, distinguished only by which product you signed up for. Google is the only sub-processor involved, and it acts as a host rather than as a recipient — it does not use the list for its own purposes. Nobody outside Calibro Software can read it; the form can add to it but cannot read it back.
We delete a product’s entries once its launch email has gone out, and sooner if that product is abandoned. Before then, ask us at support@calibrosoftware.com and we will remove your address and confirm that we have. You do not have to explain why, and it will not take a form.
Fonts
Every page here loads the IBM Plex typefaces from Google Fonts, which means your browser makes a request to Google on each page view and Google sees your IP address as a result. We ask for nothing else and receive nothing back from it. We intend to serve the fonts from this domain instead, which removes the request rather than merely disclosing it.
Changes
When this policy changes in a way that matters, the date at the top changes. We will not quietly broaden what we collect.