Northwick

Privacy Policy

Effective date: 19 September 2026 · Last updated: 1 October 2026

This policy explains what data Northwick apps process, where it is stored, who can see it, and how it is deleted. It applies to all apps published by Northwick on the Atlassian Marketplace unless an app-specific policy says otherwise. The sections below describe our two apps for Confluence Cloud: Review Due and Acknowledge.

Summary

Review Due for Confluence

What Review Due stores

Review Due runs entirely on Atlassian Forge. For each Confluence page that a user chooses to track, the app stores one record containing:

FieldPurpose
Page IDIdentifies the tracked page.
Page titleShown in the stale-page dashboard.
Space key and space nameGroup tracked pages by space in the dashboard and label them.
Page link pathThe path Confluence reports for the page, so a dashboard row can link to it correctly.
Page owner's Atlassian account IDIdentifies who is responsible for the review. The app stores the opaque account ID only, not a name or email address.
Review cadence and datesThe review interval, the last review date and the next due date.
Review statusWhether the page is overdue, due soon or fine, stored with the record so the dashboard can sort and filter without recomputing it.
Reminder state, dates and comment IDWhether a reminder has been posted, the date of the last one, the time an attempt began, and the ID of the reminder comment. Together these are what stop the app posting a second reminder for the same review.

The app does not store page body content, attachments, comments other than the ID of its own reminder comment, email addresses, names, or any data from pages that are not tracked.

Two keys that belong to no page. The daily pass stores its own position so that it can continue where it stopped on a large site: one key for the reminder pass and one for the deletion-reconciliation pass. Each holds a cursor and timestamps — no page identity, no user identity — and they are named here because everything the app stores belongs on this page, not only the per-page records above.

Logs. The app writes operational logs to Atlassian's Forge logging service: page IDs, an opaque installation identifier, counts, and error messages. Logs never contain page content, names, email addresses or account IDs, they stay inside Atlassian's infrastructure, and Northwick reads them for two purposes only: to diagnose a failure, and to count, per installation, whether the app is in use (the number of tracked pages, without page or user identity). They are never used for advertising and never shared with anyone.

Where data is stored

All records are stored in Forge hosted storage, which is operated by Atlassian and located in the same Atlassian region as your Confluence Cloud site. Data residency follows your site's Atlassian data residency settings. Northwick does not operate any servers of its own, the app makes no outbound network calls, and no data leaves Atlassian's infrastructure.

Who can see the data

The review date, owner and status of a tracked page are visible to anyone who can view that page in Confluence. The dashboard shows tracked pages only to users who already have permission to view them. Northwick has no access to your Atlassian site or to any data the app stores.

How data is deleted

To request deletion of all data held for your site, or to ask about anything in this policy, email Northwick.apps@gmail.com from an address associated with your Atlassian site and include your site URL. We will confirm the request and guide you through deletion, which you can also complete yourself by stopping tracking on each page or by uninstalling the app.

Acknowledge for Confluence

Acknowledge lets a page owner ask a defined audience to confirm that they have read a page. The owner chooses the audience (a Confluence group), a version mode (whether people must acknowledge again after the page changes) and an optional due date. Like Review Due, the app runs entirely on Atlassian Forge.

What Acknowledge stores

For each page that has an acknowledgement policy, the app stores one page record, and one record per person who acknowledges:

FieldPurpose
Page ID and page titleIdentify the page and label it in the acknowledgement report.
Space ID, space key and space nameGroup pages by space in the report and the dashboard.
Page link pathThe path Confluence reports for the page, so a row in the report links straight to it.
Creator's Atlassian account ID, and when the policy was created and last changedIdentifies who set the acknowledgement requirement up, so the app can mention them once the due date passes. The app stores the opaque account ID only, not a name or email address.
Audience group ID, group name and group typeThe Confluence group whose members are asked to acknowledge.
Policy settingsThe version mode, the pinned and last known page version, the optional due date and the reminder setting.
Cached countsThe size of the audience, how many have acknowledged, and when those two numbers were last counted — so the report opens without re-reading the group every time.
Reminder state (per page, not per person)When the page was last reminded, the state and time of the current attempt, the ID of the reminder comment the app posted, and which rotation round the reminder is on — so the app neither posts duplicates nor mentions the same people every week.
Per person who acknowledged: Atlassian account IDIdentifies the person who acknowledged. The app stores the opaque account ID only, not a name or email address.
Per person who acknowledged: version and timestampWhich version of the page the person acknowledged and when.
Per person who acknowledged: version historyThe versions the person acknowledged earlier, at most 50 entries per person; the oldest is dropped beyond that.
Per person who acknowledged: removal time and who removed itIf a page editor removes someone's acknowledgement, the app keeps the record and marks it: when it was removed, and the opaque Atlassian account ID of the editor who removed it. The record is marked rather than deleted so that the report cannot be silently emptied; the person is shown as not having acknowledged, and the removal is also an entry in their version history. "Stop tracking" deletes every record of the page outright.

Names are not stored. The app keeps the opaque Atlassian account ID only. The report shows names by asking Confluence for them at the moment it is viewed, under each viewer's Atlassian privacy settings, and the optional "Include names" export resolves them on the fly — restricted to the page's audience and its existing records — and writes them nowhere. One consequence is worth stating: if an account is later renamed or deactivated, the report shows whatever Atlassian returns for it then, not a name captured earlier.

Logs. The app writes operational logs to Atlassian's Forge logging service: page IDs, group IDs, an opaque installation identifier, counts, and error messages. Logs never contain page content, names, email addresses or account IDs, they stay inside Atlassian's infrastructure, and Northwick reads them for two purposes only: to diagnose a failure, and to count, per installation, whether the app is in use (the number of tracked pages, without page or user identity). They are never used for advertising and never shared with anyone.

To know who belongs to the audience, the app reads the membership of the chosen group through the Confluence API and keeps the resulting list of account IDs in a cache for at most 15 minutes. The app does not store page body content, attachments, comment text, display names, email addresses, avatars, IP addresses, group membership beyond that 15-minute cache, or any data about pages that have no acknowledgement policy.

Reminders

Once a week, the app posts a reminder comment on the page that @mentions people in the audience who have not yet acknowledged the current version — at most 25 in one comment, rotating through the outstanding list from week to week so that a large audience is covered without any single comment mentioning hundreds of people. These comments are ordinary Confluence comments and are visible to anyone who can view the page.

Where data is stored

All Acknowledge data is stored in Forge hosted storage on Atlassian's infrastructure, in the same Atlassian region as your Confluence Cloud site. Northwick operates no external servers, the app makes no outbound network calls, and no data leaves Atlassian's infrastructure.

Who can see the data

The acknowledgement report is shown only inside Confluence, and the app refuses to return it unless the person asking can edit that page or administer its space — so page editors and space administrators see who has acknowledged and who has not, and they can export those rows as CSV, which is displayed on screen for them to copy; the app never sends exports anywhere. Anyone else who can view the page sees only their own status and their own acknowledgement history, never another person's. Northwick has no access to your Atlassian site or to any data the app stores.

How data is deleted

To request deletion of all Acknowledge data held for your site, email Northwick.apps@gmail.com from an address associated with your Atlassian site and include your site URL.

Data we collect through this website and support

This website is a static site served by GitHub Pages. It sets no cookies and includes no analytics or third-party scripts. GitHub may log standard web-server data such as IP addresses as described in GitHub's privacy statement. If you email us for support, we keep your message and address only as long as needed to resolve your request.

Sub-processors

Atlassian (Forge hosting and storage) is the only processor of app data. Northwick uses no other sub-processors.

Changes to this policy

If we change this policy, we will update the effective date above. Material changes that affect an app will also be noted in that app's Marketplace listing.

Contact

Northwick · Northwick.apps@gmail.com

Notes

  1. Atlassian, Data lifecycle for Forge-hosted storage: retention of 28 days after uninstallation, no automatic restore on reinstall, and re-linking available on request within 21 days. ↩