Native Page Approvals for Confluence, operated by ResiliaTech. Last updated 10 October 2026.
Native Page Approvals for Confluence ("the app") is an app for Atlassian Confluence Cloud. This policy explains what the app processes, where that data lives, and what we, ResiliaTech, can and cannot see.
In short: the app runs entirely on Atlassian's Forge platform, inside your Atlassian site. Approval records are saved on your Confluence pages. The app stores Atlassian account IDs only (requesters, approvers and the editor of an approved page), no names, emails or page titles, and sends nothing to ResiliaTech's servers or to any third party. It sends no email; approvers are notified through Confluence's own @mentions.
Who we are
ResiliaTech (Resilia Tech (Private) Limited), 14885 Pleasant Valley Road, Tynwald South, Harare, Zimbabwe. Contact: support@resiliatech.com.
For the data described below, your organisation, the Atlassian customer, is the controller. ResiliaTech provides the app, which processes the data on your organisation's behalf.
Data the app works with
Confluence data read through Atlassian's APIs. The page a request belongs to (its title, version and space), whether the signed-in user may edit it or administer the space, and user lookups for the approver picker and for showing names. Reads run as the signed-in user where the action is theirs; the app reads and writes its own records as the app, so a view-only approver can record a decision.
Approval records. Each page's record is saved on the page as a Confluence content property. It holds the current request (rule, due date, note), each approver's decision and comment with the page version it was made on, the approved version, and the history. People are identified by Atlassian account ID.
Notification comments. When notifications are on, the app posts footer comments on the page, as the app, that @mention approvers or the requester. They are ordinary Confluence comments and visible on the page.
The app's own records, kept in Atlassian Forge storage for your site:
site and space settings: rule, automatic re-approval, notification comments, self-approval, and default approvers (account IDs);
a dashboard index: for each page with a request, its state, requester and pending approvers (account IDs) and approved version, plus short per-person lists for the My approvals page. The index is derived from the page records and rebuilds itself.
Personal data. The app stores Atlassian account IDs as described above, and the free-text comments approvers write. Each week it reports stored IDs to Atlassian's personal-data reporting service, as Atlassian requires of apps that store account IDs. When Atlassian reports an account as closed, the app removes it from default approvers and its dashboard lists, and replaces it with a placeholder in page records; decisions and comments remain, the identity goes.
The app has no advertising, and no analytics or tracking of any kind.
Where the data is stored
Approval records and notification comments stay in your Confluence site, as Confluence data on each page.
Settings and the dashboard index are kept in Atlassian Forge storage, which Atlassian hosts and isolates per site, under Atlassian's terms and privacy policy. Data residency follows Atlassian's Forge data residency rules for your site.
The app makes no calls to servers outside Atlassian ("no egress") and sends no email. It is eligible for Atlassian's Runs on Atlassian programme.
What ResiliaTech can see
We cannot browse your site's Confluence content or the app's records. Atlassian gives us operational logs and metrics for the app, such as error messages and how often features are used. These can contain technical identifiers, for example a page or issue ID in an error. We use them only to keep the app working and to resolve support requests. If you send us information in a support request, we use it only to help you, and delete it when it is no longer needed.
Sub-processors
Atlassian, which hosts the app on its Forge platform and runs Confluence. We use no other sub-processors for app data.
Retention and deletion
Approval records are Confluence data stored on your pages. They follow Confluence's own retention and go when the page is deleted. Notification comments are ordinary page comments and can be deleted like any comment.
Settings and the dashboard index are deleted by Atlassian after the app is uninstalled from your site, in line with Atlassian's Forge data retention policy.
When an Atlassian account is closed, the app removes that account ID from its records in the next weekly personal-data cycle, as described above.
The app runs inside Atlassian's infrastructure. It uses the minimum Confluence permissions needed:
read pages and spaces, for the page, its permissions and its approval record;
write pages, only to save the approval record as a content property; the app never changes page content;
write comments, for notification comments;
read and search users, for the approver picker and for showing names;
app storage, for settings and the dashboard index;
report personal data, for Atlassian's weekly personal-data reporting.
All traffic is encrypted by Atlassian.
Your rights
Because your organisation controls this data, requests to access, correct or delete personal information should go to your Confluence administrator first. We will help them fulfil any request. You can also contact us at support@resiliatech.com.
Changes
If we change this policy, we will update the date above. For significant changes, we will tell customers through the Marketplace listing.