Privacy Policy
This policy explains what data Northwick apps process, where it is stored, who can see it, and how it is deleted. It applies to all apps published by Northwick on the Atlassian Marketplace unless an app-specific policy says otherwise. The sections below describe our two apps for Confluence Cloud: Review Due and Acknowledge.
Summary
- Review Due stores only a small tracking record per page you choose to track. It never stores page content.
- Acknowledge stores, per page with an acknowledgement policy, the policy settings and one record per person who acknowledges, saying which version of the page they acknowledged and when. Someone who has not acknowledged has no record. It never stores page content.
- All data lives in Atlassian Forge hosted storage in your Atlassian site's data region. Nothing is sent to Northwick or to any third party.
- The app has no external servers and no network egress.
- We do not collect email addresses, and this website uses no cookies or analytics.
Review Due for Confluence
What Review Due stores
Review Due runs entirely on Atlassian Forge. For each Confluence page that a user chooses to track, the app stores one record containing:
| Field | Purpose |
|---|---|
| Page ID | Identifies the tracked page. |
| Page title | Shown in the stale-page dashboard. |
| Space key and space name | Group tracked pages by space in the dashboard and label them. |
| Page link path | The path Confluence reports for the page, so a dashboard row can link to it correctly. |
| Page owner's Atlassian account ID | Identifies who is responsible for the review. The app stores the opaque account ID only, not a name or email address. |
| Review cadence and dates | The review interval, the last review date and the next due date. |
| Review status | Whether the page is overdue, due soon or fine, stored with the record so the dashboard can sort and filter without recomputing it. |
| Reminder state, dates and comment ID | Whether a reminder has been posted, the date of the last one, the time an attempt began, and the ID of the reminder comment. Together these are what stop the app posting a second reminder for the same review. |
The app does not store page body content, attachments, comments other than the ID of its own reminder comment, email addresses, names, or any data from pages that are not tracked.
Two keys that belong to no page. The daily pass stores its own position so that it can continue where it stopped on a large site: one key for the reminder pass and one for the deletion-reconciliation pass. Each holds a cursor and timestamps — no page identity, no user identity — and they are named here because everything the app stores belongs on this page, not only the per-page records above.
Logs. The app writes operational logs to Atlassian's Forge logging service: page IDs, an opaque installation identifier, counts, and error messages. Logs never contain page content, names, email addresses or account IDs, they stay inside Atlassian's infrastructure, and Northwick reads them for two purposes only: to diagnose a failure, and to count, per installation, whether the app is in use (the number of tracked pages, without page or user identity). They are never used for advertising and never shared with anyone.
Where data is stored
All records are stored in Forge hosted storage, which is operated by Atlassian and located in the same Atlassian region as your Confluence Cloud site. Data residency follows your site's Atlassian data residency settings. Northwick does not operate any servers of its own, the app makes no outbound network calls, and no data leaves Atlassian's infrastructure.
Who can see the data
The review date, owner and status of a tracked page are visible to anyone who can view that page in Confluence. The dashboard shows tracked pages only to users who already have permission to view them. Northwick has no access to your Atlassian site or to any data the app stores.
How data is deleted
- Stop tracking. Choosing "Stop tracking" on a page deletes that page's record immediately.
- Page deletion. When a tracked page is deleted or moved to the trash in Confluence, the app removes its tracking record. Two paths do this: opening the dashboard removes the record of any tracked page it finds gone, at once; and once a day a reconciliation pass works through the stored records and removes the ones whose page no longer exists or is in the trash — which also covers pages deleted in bulk or together with their whole space. That pass is time-bounded: it holds a reserved share of each day's processing time, and if it cannot reach every record it continues from where it stopped on the next day's run, so on a very large site a full sweep can take more than one day. The app deliberately does not subscribe to Confluence's page-deletion events, because listening to them would require write access to your content.
- Uninstall. When the app is uninstalled from a site, Atlassian "soft deletes" its Forge hosted storage and retains it for 28 days, after which it is deleted permanently. Reinstalling the app does not restore the previous data automatically. Recovery is possible only if you ask us within 21 days of uninstalling: with your consent, we submit a request to Atlassian to re-link the retained data to the new installation, and Atlassian processes it before the 28-day retention period ends.1
To request deletion of all data held for your site, or to ask about anything in this policy, email Northwick.apps@gmail.com from an address associated with your Atlassian site and include your site URL. We will confirm the request and guide you through deletion, which you can also complete yourself by stopping tracking on each page or by uninstalling the app.
Acknowledge for Confluence
Acknowledge lets a page owner ask a defined audience to confirm that they have read a page. The owner chooses the audience (a Confluence group), a version mode (whether people must acknowledge again after the page changes) and an optional due date. Like Review Due, the app runs entirely on Atlassian Forge.
What Acknowledge stores
For each page that has an acknowledgement policy, the app stores one page record, and one record per person who acknowledges:
| Field | Purpose |
|---|---|
| Page ID and page title | Identify the page and label it in the acknowledgement report. |
| Space ID, space key and space name | Group pages by space in the report and the dashboard. |
| Page link path | The path Confluence reports for the page, so a row in the report links straight to it. |
| Creator's Atlassian account ID, and when the policy was created and last changed | Identifies who set the acknowledgement requirement up, so the app can mention them once the due date passes. The app stores the opaque account ID only, not a name or email address. |
| Audience group ID, group name and group type | The Confluence group whose members are asked to acknowledge. |
| Policy settings | The version mode, the pinned and last known page version, the optional due date and the reminder setting. |
| Cached counts | The size of the audience, how many have acknowledged, and when those two numbers were last counted — so the report opens without re-reading the group every time. |
| Reminder state (per page, not per person) | When the page was last reminded, the state and time of the current attempt, the ID of the reminder comment the app posted, and which rotation round the reminder is on — so the app neither posts duplicates nor mentions the same people every week. |
| Per person who acknowledged: Atlassian account ID | Identifies the person who acknowledged. The app stores the opaque account ID only, not a name or email address. |
| Per person who acknowledged: version and timestamp | Which version of the page the person acknowledged and when. |
| Per person who acknowledged: version history | The versions the person acknowledged earlier, at most 50 entries per person; the oldest is dropped beyond that. |
| Per person who acknowledged: removal time and who removed it | If a page editor removes someone's acknowledgement, the app keeps the record and marks it: when it was removed, and the opaque Atlassian account ID of the editor who removed it. The record is marked rather than deleted so that the report cannot be silently emptied; the person is shown as not having acknowledged, and the removal is also an entry in their version history. "Stop tracking" deletes every record of the page outright. |
Names are not stored. The app keeps the opaque Atlassian account ID only. The report shows names by asking Confluence for them at the moment it is viewed, under each viewer's Atlassian privacy settings, and the optional "Include names" export resolves them on the fly — restricted to the page's audience and its existing records — and writes them nowhere. One consequence is worth stating: if an account is later renamed or deactivated, the report shows whatever Atlassian returns for it then, not a name captured earlier.
Logs. The app writes operational logs to Atlassian's Forge logging service: page IDs, group IDs, an opaque installation identifier, counts, and error messages. Logs never contain page content, names, email addresses or account IDs, they stay inside Atlassian's infrastructure, and Northwick reads them for two purposes only: to diagnose a failure, and to count, per installation, whether the app is in use (the number of tracked pages, without page or user identity). They are never used for advertising and never shared with anyone.
To know who belongs to the audience, the app reads the membership of the chosen group through the Confluence API and keeps the resulting list of account IDs in a cache for at most 15 minutes. The app does not store page body content, attachments, comment text, display names, email addresses, avatars, IP addresses, group membership beyond that 15-minute cache, or any data about pages that have no acknowledgement policy.
Reminders
Once a week, the app posts a reminder comment on the page that @mentions people in the audience who have not yet acknowledged the current version — at most 25 in one comment, rotating through the outstanding list from week to week so that a large audience is covered without any single comment mentioning hundreds of people. These comments are ordinary Confluence comments and are visible to anyone who can view the page.
Where data is stored
All Acknowledge data is stored in Forge hosted storage on Atlassian's infrastructure, in the same Atlassian region as your Confluence Cloud site. Northwick operates no external servers, the app makes no outbound network calls, and no data leaves Atlassian's infrastructure.
Who can see the data
The acknowledgement report is shown only inside Confluence, and the app refuses to return it unless the person asking can edit that page or administer its space — so page editors and space administrators see who has acknowledged and who has not, and they can export those rows as CSV, which is displayed on screen for them to copy; the app never sends exports anywhere. Anyone else who can view the page sees only their own status and their own acknowledgement history, never another person's. Northwick has no access to your Atlassian site or to any data the app stores.
How data is deleted
- Stop tracking. Removing the acknowledgement requirement from a page deletes the policy and every record belonging to it immediately.
- Removal of a single record. Anyone who can edit the page can remove one person's acknowledgement from the report at any time. The record itself is kept and marked with the time of the removal and the account ID of the editor who removed it, and the person is shown as not having acknowledged — an acknowledgement record that could be deleted without trace would be worth nothing to an auditor. To delete the records themselves, stop tracking the page, which removes the requirement and all of them at once.
- Page deletion. Records are kept as long as the page's acknowledgement requirement exists, and deleting the page does not by itself delete them. When the app finds that a tracked page is gone, it marks the policy as pointing to a missing page. Nobody can be permission-checked against a page that no longer exists, so the dashboard then shows that entry only to administrators of its space — and to anyone after 30 days — and shows it minimised, as "Page <id> (deleted)" with its counts only, without the title, the group or the creator. Removing that entry from the dashboard deletes the policy and all of its per-person records. To have them removed sooner, stop tracking the page before deleting it, or email us.
- Uninstall. The same 28-day Forge retention rule described for Review Due applies: data is soft-deleted on uninstall, is not restored automatically on reinstall, and can be re-linked only on request within 21 days.1
To request deletion of all Acknowledge data held for your site, email Northwick.apps@gmail.com from an address associated with your Atlassian site and include your site URL.
Data we collect through this website and support
This website is a static site served by GitHub Pages. It sets no cookies and includes no analytics or third-party scripts. GitHub may log standard web-server data such as IP addresses as described in GitHub's privacy statement. If you email us for support, we keep your message and address only as long as needed to resolve your request.
Sub-processors
Atlassian (Forge hosting and storage) is the only processor of app data. Northwick uses no other sub-processors.
Changes to this policy
If we change this policy, we will update the effective date above. Material changes that affect an app will also be noted in that app's Marketplace listing.
Contact
Northwick · Northwick.apps@gmail.com
Notes
- Atlassian, Data lifecycle for Forge-hosted storage: retention of 28 days after uninstallation, no automatic restore on reinstall, and re-linking available on request within 21 days. ↩