Last updated: 28 August 2026
Page Approval is an app for Confluence Cloud that records who signed off a page, and which version of it they signed off. This page explains exactly what the app stores, where it stores it, and who can read it.
The app keeps no copy of your pages. It never asks Atlassian for permission to read a comment or an attachment, and it stores no page text and no page titles. What it writes down is an approval record and a decision log, and those hold account identifiers, dates and version numbers — not names.
When someone sends a page for approval, approves it, or requests changes, the current state is stored as a content property on that page, inside your own Confluence. It holds who was asked to sign off (account IDs and group IDs), who has signed off and on which page version, and when. Because it lives with the page, deleting the page deletes the approval with it — which is the correct behaviour.
Every decision also becomes one line in Atlassian's Forge storage for your site, so that a company's audit trail does not depend on the page still existing. Each line contains:
The one free-text field, said plainly. Requesting changes requires a written reason, and that sentence is stored, because a refusal without a reason is not an audit trail. It is the only free text the app keeps. It is typed by a colleague and shown to colleagues, so treat it as you would a page comment: do not type personal details, health information or anything else sensitive into it. Anyone who can open the approval on that page can read it.
A space administrator can set defaults for a space: who approves by default (account IDs and group IDs), whether one signature is enough or everybody must sign, and which pages the rule covers (only pages someone sends, every page with a label, or every page under a parent page). That is stored per space, with the label text and the parent page ID when those are used. A space with no settings at all works normally — the app needs no configuration.
So that the Approvals screen can list what is waiting without reading every page on your site, the app keeps an index containing only the page ID and the space key. No names, no titles.
Personal space keys are deliberately not stored as they are. In Confluence a
personal space is named after its owner — its key is an account identifier. Storing it as it
comes would mean storing an account ID without meaning to, in a field the weekly privacy routine does
not look at. Every personal space is therefore recorded as ~personal instead, in the
decision log and in the index. Nothing is lost: the key is only used to group and filter.
Everything stays inside your own Confluence site and Atlassian Forge storage, in the Atlassian cloud region of that site. The app is built on Forge and declares no external network access at all, which means the platform physically prevents it from sending anything anywhere. There are no servers of ours involved at any point. Atlassian's own privacy commitments and data residency options apply: see Atlassian's Privacy Policy.
The approval on a page is deleted by Confluence when the page is deleted, as part of the page. Everything else the app holds is deleted by Atlassian when an administrator uninstalls the app, as part of the normal uninstall process. There is no copy of ours to restore from, because we never had one.
The decision log is not editable, on purpose. In an approval app that is the whole point: a record of who approved a document must not be quietly rewritten. Identities can be erased from it — see the next section — and the app can be uninstalled, but individual lines are not edited to say something else.
Once a week, on its own, the app tells Atlassian which account identifiers it still holds and asks whether any of those accounts have been closed. It looks in both places that hold one — the decision log and the space defaults — and treats each one differently:
Nothing on any screen starts this, and no administrator has to remember it. It runs whether anyone is watching or not.
If you are in the European Union or the United Kingdom, the GDPR gives you the right to access, correct, export or delete your personal data. The company that installed the app is the data controller. In practice the app holds no personal profile about you — only account identifiers, dates and version numbers inside your own company's approval record — so the quickest route for any request is your own Confluence administrator. You can also write to us directly at the address below.
For your legal team, the Data Processing Agreement sets out the same facts in the form the GDPR asks for (Article 28), and applies automatically from installation.
If this policy changes, the date at the top changes with it and the new version is published here before it takes effect.
Page Approval is supplied by Kauê Natan Gonçalves Bidim, trading as Saoirse Software, in Ireland. Questions about this policy — or a request to see or delete data — go to support@saoirsesoftware.com.