← Footfall

Footfall for Confluence: Privacy Policy

Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company

This policy explains what information the Footfall app for Confluence Cloud (the "App") processes, where it is kept, and the choices people have. It covers only the App, not Atlassian's products, which are governed by Atlassian's own privacy policy.

1. Summary

  • The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). It has no servers of its own and sends no data to Great Work or to any third party, including analytics or AI services.
  • It counts page and blog post views from Confluence's own view events and stores the counts in Forge storage for your site.
  • Your Confluence admins decide whether the App records who viewed a page or only counts views. Every person can opt out of having their views linked to them.
  • Great Work LLC cannot see your pages, your counts, or who viewed anything.

2. What the App processes

DataWhyWhere it lives
Per page, per UTC day, per viewer: page id, space key, page or blog post, number of views, time of the last view, version number last viewedViews, unique viewers, trends, last viewed, stale page reportsForge SQL for your site, until the retention period your admin set (90 days to 3 years)
The viewer, stored as: the Atlassian account id (when your admin chose to record names), or a salted hash that changes every month (aggregate-only mode), or nothing (anonymous visitors and people who opted out)Unique viewers, and who viewed for people allowed to see namesSame row as above
Hash salts (aggregate-only mode): one random value per monthSo one person counts once per month without storing who they areForge SQL; deleted once the month is over, after which stored hashes can't be linked to anyone
Opt-out list: account id and when the person opted outTo honor "Don't link my views to me"Forge SQL until the person opts back in or the App is uninstalled
Settings: privacy mode, who sees counts and names, report group ids and names, account ids of people whose views are not counted, creator exclusion, retention, stale page thresholdConfigurationForge SQL until changed or uninstall
Page titles, last update dates and authors, space names, group memberships, display namesShown on screen and in CSV exportsRead from Confluence when a report is opened, as the person opening it; not stored

The App does not store page titles or content, and does not collect email addresses, IP addresses, browser or device data, time on page, clicks, passwords, API tokens or payment information. It sets no cookies and loads no third-party scripts.

3. Where data is stored

All App data is stored by Atlassian in Forge storage for your site, subject to Atlassian's data residency settings. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors.

4. Who can see what

  • View counts and trends: everyone who can see the page, or only page editors and report viewers, as your admin chose.
  • Who viewed a page: only when your admin chose to record names, and then only Confluence admins, members of the report groups your admin picked, and (if your admin turned it on) people who can edit that page. Never in aggregate-only mode.
  • Space reports list pages and counts, never people, and only pages the person opening the report can see. Space admins see their own space; report viewers see any space they can see.
  • Settings: Confluence admins only.
  • Great Work LLC: no access. If you open a support request, we see only what you send us.
  • Atlassian: as the platform operator, under Atlassian's privacy policy.

5. Your choices

  • Opt out (everyone): turn on "Don't link my views to me" in the Views dialog on any page or in Apps > Footfall page analytics. Your account id is no longer stored with views, and views already stored lose your name (they become anonymous counts, or are deleted if your admin chose that). You can opt back in at any time; this affects only future views.
  • Admins: switch to aggregate-only mode (this also converts names already stored), leave out chosen people or page creators, shorten retention, or delete all view data.
  • Requests about personal data held by the App go to your Confluence admins, who control it. Great Work LLC will help them on request at hello@greatwork.company.

6. Retention and deletion

View history older than the retention period is deleted automatically every hour. Uninstalling the App removes its Forge storage according to Atlassian's Forge data deletion process.

7. Security

Data is protected by Atlassian's Forge platform (encryption in transit and at rest, tenant isolation). Every report checks permissions on the server and reads Confluence as the person asking. See our security self-assessment on request.

8. Changes

We will post changes to this policy on this page and update the effective date. Material changes will be noted in the App's release notes.

9. Contact

Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company.