Privacy Policy
Last updated: August 17, 2026
Sealed: Page Approval & Document Control for Confluence ("the App") is a Confluence Cloud app developed and operated by Scritt Solutions ("Scritt", "we", "us", "our"). This policy explains what the App stores, where it stores it, and how long it keeps it.
1. Who we are
Scritt Solutions, a sole proprietorship operated by Ryosuke Kamei and based in Tokorozawa, Saitama, Japan, develops and operates the App. Our detailed address is disclosed without delay on request. Contact us at support@scritt.com.
2. Where your data goes
The App sends no data outside Atlassian's infrastructure. It runs on the Atlassian Forge platform under the Runs on Atlassian program, stores everything in Forge app storage and in Confluence itself, and makes no network calls to servers we operate or to any third party. We use no analytics, no error reporting service, and no subprocessors.
We cannot read the contents of your Forge app storage.
3. What the App stores
The App is an approval and audit-trail tool. To show who approved a page and when, it has to keep a record of what people did. That record identifies people by their Atlassian account ID.
- The audit trail. For every approval action: the account ID of the person who acted, the page and space it happened in, the type of action, the time, and a hash linking the record to the previous one so that a changed or missing record can be detected. Kept for as long as the App is installed. This is deliberate — an audit trail that can be pruned is not an audit trail — and there is no function to delete individual records.
- The reasons people type. When someone rejects a page or asks for a revision, the App requires a comment, and stores that text alongside the audit record. Kept for as long as the audit record.
- The current approval status of each page. The status, the account IDs of the approvers assigned when approval was requested, which of them have approved, the approval date, and any page restrictions that existed before the App locked the page. Stored on the page itself as a Confluence content property, and removed when the page is deleted.
- Your configuration. The workflow and step names you type, the account IDs and group IDs of the approvers you choose, and each space's display settings. Kept until you delete them.
- Notification preferences. One setting per person, stored against their account ID, so each person can choose how much notification they receive.
4. What the App reads but does not store
To draw its screens the App reads display names from Atlassian each time a screen is rendered, and discards them immediately — it never stores names, email addresses, or avatars. It also reads page metadata such as titles, version numbers, and existing restrictions. It does not read the body text of your pages.
5. What the App writes to Confluence
Three things: the approval status attached to a page, the edit restriction that locks an approved page, and a comment that notifies approvers by @mentioning them. Those comments are ordinary Confluence comments and stay where they are unless you delete them.
The App never modifies the body of any page, even though the permissions it requests include "write pages". Atlassian governs the property the App writes with that page-level permission; the narrower content-property permission applies only to an older API whose read and update endpoints Atlassian has removed. There is no narrower permission that lets the App work. Page version history shows that the App creates no page versions.
The App changes edit restrictions only. Viewing permissions are never touched, so locking a page never hides it from anyone who could already see it. The restrictions that existed before a lock are saved and put back when a revision is requested.
6. Retention and deletion
Everything the App stores lives for as long as the App is installed, except the approval status on a page, which goes when the page does.
Uninstalling the App permanently deletes everything it has stored, including the entire audit trail. Atlassian performs that deletion and it cannot be undone. If you need to keep the audit trail, export it before uninstalling.
7. Personal data
The Atlassian account IDs described above are personal data under GDPR and comparable laws. The App stores them to record who requested, approved, rejected, or unlocked a page, which is the whole point of an approval trail.
Atlassian acts as the data controller for your site's Confluence data. We process the data listed above on your behalf as part of providing the App.
To access, correct, or delete this data: your site administrator controls all of it and can remove it entirely by uninstalling the App. If you use a site operated by someone else, contact that site's administrator first. You can also reach us at support@scritt.com.
8. Security
Data stays inside your Confluence instance and inherits its permission model. Wherever it can, the App reads with the permissions of the person using it, so it cannot show anyone something they could not already open in Confluence. Audit records are linked by a hash chain, so tampering can be detected.
9. Children
The App is not directed at children and we do not knowingly collect data from them.
10. Changes to this policy
We will update this page when the App's data handling changes, and we will change the date at the top. Material changes will also appear in the App's Marketplace release notes.
11. Contact
Questions about this policy or your data: support@scritt.com