keelapps/Signoff/Privacy policy
Privacy policy — Signoff for Confluence
The short version
Signoff does not send your data anywhere. It runs entirely on Atlassian Forge, inside Atlassian's infrastructure. The app declares no external network permissions, which Atlassian enforces at the platform level. Notifications are Confluence comments, delivered by Confluence's own notification service — there is no external email provider, no vendor server, no third party.
What the app stores
Everything is stored in Forge app storage (Atlassian-hosted KVS) inside your own Atlassian tenant region.
| Data | Examples | Why |
|---|---|---|
| Approval records | page id and title, space key, the page version a request or approval covered, approver and requester account ids and display names, decisions, timestamps, notes and comments entered in approval forms | the approval trail is the product |
| Policies | policy names, approver account ids and display names, mode, validity, per-space bindings | to supply approvers and rules per space |
| Operational data | the daily scan's due-for-re-approval list and its checkpoint | so the due list opens instantly |
Personal data is limited to Atlassian account ids and display names of the people who request and decide approvals.
What the app writes to Confluence
One thing only: an optional footer comment on a page when approval is requested or decided, @-mentioning the people involved. Site admins can switch these comments off. The app never edits page content, never creates page versions, and never changes permissions.
What is never stored
- Page bodies, descriptions or rich-text content — only titles and version numbers
- Email addresses
- IP addresses, usage analytics, or behavioural tracking
Retention and deletion
- Per-page history is capped: beyond the cap, oldest entries are dropped.
- Uninstalling the app removes all Forge storage.
Data residency
Whatever your Atlassian site's residency is. Signoff adds no storage outside Forge and therefore introduces no additional residency considerations.
Sub-processors
None. Atlassian hosts everything; there is no other party involved.
Changes
Material changes to what is stored or where will be reflected here and in the Marketplace listing before they ship.
Contact
support@keelapps.atlassian.net — for questions about this policy, and for data access, correction or deletion requests.