Privacy policy

Selected data stays inside the active handoff.

Carryover processes selected monday content in the active app window and the server-authoritative backend only for authenticated rereads, verification, and the controlled move. It does not collect unrelated content or use handoff data for analytics.

Last updated 2026-08-10Public-preview policy
Review status: This policy matches the current public preview but still requires responsible-entity and legal review before Marketplace submission.

Scope and responsible contact

This policy explains how Carryover processes information when an authorized monday.com user runs the Carryover item action or contacts support. The verified same-domain support contact is Bennett Hilberg at me@bennetthilberg.com. The final responsible legal entity and mailing details will be published before Marketplace submission.

What Carryover processes

Selected monday content

For one operator-selected handoff, the app reads the source and destination board identities and schemas, selected destination group, selected parent item name and supported text value, and an available source-board activity window filtered to that item. The current window is 24 hours with a maximum of 25 returned rows.

Carryover does not read update conversations, replies, files, documents, subitems, user profiles, email addresses, or unrelated item content in the first release.

Session and authorization data

The backend receives a monday-signed session assertion to verify the current app, account, user, expiry, and entitlement. The active server-authoritative flow also receives selected board, group, item, and column identifiers plus bounded mapping selectors so it can reread monday, verify the destination, and control the move or receipt. Selected names, mapped values, and the bounded activity summary may exist in transient backend operation memory for those checks; they are not used for analytics or free-form logging. The backend never accepts monday access tokens from the browser or raw GraphQL bodies.

Native receipt

After destination verification, Carryover writes a native monday update containing the source and destination, selected item, exact mapping, capture bounds, represented and omitted activity, verification result, privacy notice, and native Undo instructions. That receipt is controlled by the monday account and visible under the destination item’s existing permissions.

Important: Uninstalling Carryover does not delete receipts already written into the customer’s monday account. Account administrators can manage those native updates with monday’s tools.

Operational events and support

The current application event path emits only a fixed safety classification: event class, optional move or receipt operation, allow or deny outcome, and fixed reason code. It excludes tenant, user, board, item, token, URL, request, and free-form content. Activation analytics and advertising trackers are disabled.

If you contact support, send only the reason code, UTC time, app version, and a redacted description. Do not send credentials, exports, full URLs, or unrelated item content.

Where data lives and how long

DataLocationCurrent retention
Selected item, mapping, and activity contextmonday API, Carryover iframe, and transient backend operation memoryActive command only; raw customer content is not written to the durable journal and pre-move confirmation expires after five minutes
monday-signed session tokenEncrypted transit and backend memoryVerification request only
Native receiptCustomer’s monday itemControlled by the customer through monday
Content-free lifecycle deny marker and deletion certificatemonday Code Secure StorageOnly as needed for revocation/deletion proof and within the applicable deletion ceiling
Fixed content-free operational eventsmonday Code logsSubject to the host’s verified retention settings; no customer-content fields are emitted
Support caseSupport mailboxOnly as long as needed to resolve and document the case; accidental customer content is removed promptly

If the app window closes after a move is dispatched, Carryover cannot restore the in-memory command. It does not persist a customer-content move journal and will not offer a blind automatic retry.

Service providers and transfers

The first release uses monday.com and monday Code for the app surface, API access, hosting, secret storage, lifecycle state, and operational logging. Carryover does not use third-party advertising, session replay, or customer-content analytics. The legally reviewed Marketplace policy will name the responsible legal entity and any additional provider before submission.

Deletion, uninstall, and your choices

A valid uninstall or deauthorization disables new entitlement, removes tenant-linked allow state, and records only a content-free deletion certificate. Carryover’s internal target is completion within 24 hours and no later than the applicable 10-day Marketplace ceiling unless law or written consent requires otherwise.

To request deletion of Carryover-held metadata or support records, email me@bennetthilberg.com. We will verify authority without asking you to send item content or credentials. Native monday receipts remain under the customer account’s control.

Security practices

  • Least-purpose scopes: boards:read, boards:write, and updates:write.
  • No request or response body logging for monday GraphQL or authorization routes.
  • Independent move and receipt kill switches, checked immediately before each write.
  • Exact app/session verification and fail-closed entitlement decisions.
  • No customer-content database, background access token, third-party analytics, or advertising pixels in the first release.

No security measure is absolute. Please report suspected unauthorized access, mutation, token exposure, or data disclosure through the security contact path.

Questions and policy changes

Questions may be sent to me@bennetthilberg.com. Material changes will be dated on this page. Carryover will not use app access to send marketing messages; any future optional product communications will require a separate disclosed choice.