Privacy Policy — Page Approval

Last updated: 28 August 2026

Page Approval is an app for Confluence Cloud that records who signed off a page, and which version of it they signed off. This page explains exactly what the app stores, where it stores it, and who can read it.

The short version

The app keeps no copy of your pages. It never asks Atlassian for permission to read a comment or an attachment, and it stores no page text and no page titles. What it writes down is an approval record and a decision log, and those hold account identifiers, dates and version numbers — not names.

What the app stores

1. The approval itself, kept with the page

When someone sends a page for approval, approves it, or requests changes, the current state is stored as a content property on that page, inside your own Confluence. It holds who was asked to sign off (account IDs and group IDs), who has signed off and on which page version, and when. Because it lives with the page, deleting the page deletes the approval with it — which is the correct behaviour.

2. The decision log, kept in the app's storage

Every decision also becomes one line in Atlassian's Forge storage for your site, so that a company's audit trail does not depend on the page still existing. Each line contains:

The one free-text field, said plainly. Requesting changes requires a written reason, and that sentence is stored, because a refusal without a reason is not an audit trail. It is the only free text the app keeps. It is typed by a colleague and shown to colleagues, so treat it as you would a page comment: do not type personal details, health information or anything else sensitive into it. Anyone who can open the approval on that page can read it.

3. The space defaults, when someone sets them

A space administrator can set defaults for a space: who approves by default (account IDs and group IDs), whether one signature is enough or everybody must sign, and which pages the rule covers (only pages someone sends, every page with a label, or every page under a parent page). That is stored per space, with the label text and the parent page ID when those are used. A space with no settings at all works normally — the app needs no configuration.

4. A small index so the Approvals inbox can be built

So that the Approvals screen can list what is waiting without reading every page on your site, the app keeps an index containing only the page ID and the space key. No names, no titles.

Personal space keys are deliberately not stored as they are. In Confluence a personal space is named after its owner — its key is an account identifier. Storing it as it comes would mean storing an account ID without meaning to, in a field the weekly privacy routine does not look at. Every personal space is therefore recorded as ~personal instead, in the decision log and in the index. Nothing is lost: the key is only used to group and filter.

What the app never stores

Where the data lives

Everything stays inside your own Confluence site and Atlassian Forge storage, in the Atlassian cloud region of that site. The app is built on Forge and declares no external network access at all, which means the platform physically prevents it from sending anything anywhere. There are no servers of ours involved at any point. Atlassian's own privacy commitments and data residency options apply: see Atlassian's Privacy Policy.

Who can see what

Keeping and deleting data

The approval on a page is deleted by Confluence when the page is deleted, as part of the page. Everything else the app holds is deleted by Atlassian when an administrator uninstalls the app, as part of the normal uninstall process. There is no copy of ours to restore from, because we never had one.

The decision log is not editable, on purpose. In an approval app that is the whole point: a record of who approved a document must not be quietly rewritten. Identities can be erased from it — see the next section — and the app can be uninstalled, but individual lines are not edited to say something else.

When an Atlassian account is closed

Once a week, on its own, the app tells Atlassian which account identifiers it still holds and asks whether any of those accounts have been closed. It looks in both places that hold one — the decision log and the space defaults — and treats each one differently:

Nothing on any screen starts this, and no administrator has to remember it. It runs whether anyone is watching or not.

Your rights

If you are in the European Union or the United Kingdom, the GDPR gives you the right to access, correct, export or delete your personal data. The company that installed the app is the data controller. In practice the app holds no personal profile about you — only account identifiers, dates and version numbers inside your own company's approval record — so the quickest route for any request is your own Confluence administrator. You can also write to us directly at the address below.

For your legal team, the Data Processing Agreement sets out the same facts in the form the GDPR asks for (Article 28), and applies automatically from installation.

Changes

If this policy changes, the date at the top changes with it and the new version is published here before it takes effect.

Contact

Page Approval is supplied by Kauê Natan Gonçalves Bidim, trading as Saoirse Software, in Ireland. Questions about this policy — or a request to see or delete data — go to support@saoirsesoftware.com.