Item Move Audit Ledger privacy

Effective August 29, 2026

Data processed and stored

We store the installing monday account ID and scoped OAuth token; watched item and board IDs and item names; move timestamps and surrounding activity metadata; append-only hashes; generated JSON/PDF artifacts; bounded AI explanations; and minimal audit events. We do not request customer data, messages, files, or write access to boards.

Purpose

This data is used only to detect a watched item’s first verified board change, build its tamper-evident ledger, explain the recorded move, and produce requested exports.

Retention and deletion

Ledger entries, generated artifacts, AI cache, and audit events are retained for 365 days. Uninstall or an authenticated deletion request tombstones the account immediately and schedules removal from Cloudflare D1 and R2.

Processors

Cloudflare hosts the Worker, D1 database, Durable Object locks, logs, and R2 artifacts. monday.com supplies board data and, when permitted, its Models API. No analytics, advertising, or tracking service receives app data.

Security

Requests use HTTPS and signed monday sessions. Data is tenant-isolated, API routes are authorized per account, mutations are parameterized, and downloads require the installing account’s session.

Privacy requests: [email protected]