Item Move Audit Ledger privacy
Effective August 29, 2026
Data processed and stored
We store the installing monday account ID and scoped OAuth token; watched item and board IDs and item names; move timestamps and surrounding activity metadata; append-only hashes; generated JSON/PDF artifacts; bounded AI explanations; and minimal audit events. We do not request customer data, messages, files, or write access to boards.
Purpose
This data is used only to detect a watched item’s first verified board change, build its tamper-evident ledger, explain the recorded move, and produce requested exports.
Retention and deletion
Ledger entries, generated artifacts, AI cache, and audit events are retained for 365 days. Uninstall or an authenticated deletion request tombstones the account immediately and schedules removal from Cloudflare D1 and R2.
Processors
Cloudflare hosts the Worker, D1 database, Durable Object locks, logs, and R2 artifacts. monday.com supplies board data and, when permitted, its Models API. No analytics, advertising, or tracking service receives app data.
Security
Requests use HTTPS and signed monday sessions. Data is tenant-isolated, API routes are authorized per account, mutations are parameterized, and downloads require the installing account’s session.
Privacy requests: [email protected]