Privacy policy

Selected data stays inside the active handoff.

Carryover is designed so monday item content is processed in the active app window and written only to the destination’s native receipt—not sent to Carryover’s authorization backend.

Last updated 2026-08-10Public-preview policy
Review status: This policy matches the current public preview but still requires responsible-entity and legal review before Marketplace submission.

Scope and responsible contact

This policy explains how Carryover processes information when an authorized monday.com user runs the Carryover item action or contacts support. The verified same-domain support contact is Bennett Hilberg at me@bennetthilberg.com. The final responsible legal entity and mailing details will be published before Marketplace submission.

What Carryover processes

Selected monday content

For one operator-selected handoff, the app reads the source and destination board identities and schemas, selected destination group, selected parent item name and supported text value, and an available source-board activity window filtered to that item. The current window is 24 hours with a maximum of 25 returned rows.

Carryover does not read update conversations, replies, files, documents, subitems, user profiles, email addresses, or unrelated item content in the first release.

Session and authorization data

The backend receives a monday-signed session token only to verify the current app, account, user, expiry, and subscription status. Immediately before a move or receipt, it also receives the operation class—move or receipt. The backend does not receive board IDs, item IDs, column IDs, names, the mapped value, activity rows, fingerprints, receipt text, monday access tokens, or raw GraphQL bodies.

Native receipt

After destination verification, Carryover writes a native monday update containing the source and destination, selected item, exact mapping, capture bounds, represented and omitted activity, verification result, privacy notice, and native Undo instructions. That receipt is controlled by the monday account and visible under the destination item’s existing permissions.

Important: Uninstalling Carryover does not delete receipts already written into the customer’s monday account. Account administrators can manage those native updates with monday’s tools.

Operational events and support

The current application event path emits only a fixed safety classification: event class, optional move or receipt operation, allow or deny outcome, and fixed reason code. It excludes tenant, user, board, item, token, URL, request, and free-form content. Activation analytics and advertising trackers are disabled.

If you contact support, send only the reason code, UTC time, app version, and a redacted description. Do not send credentials, exports, full URLs, or unrelated item content.

Where data lives and how long

DataLocationCurrent retention
Selected item, mapping, and activity contextCarryover iframe memoryActive command only; pre-move confirmation expires after five minutes
monday-signed session tokenEncrypted transit and backend memoryVerification request only
Native receiptCustomer’s monday itemControlled by the customer through monday
Content-free lifecycle deny marker and deletion certificatemonday Code Secure StorageOnly as needed for revocation/deletion proof and within the applicable deletion ceiling
Fixed content-free operational eventsmonday Code logsSubject to the host’s verified retention settings; no customer-content fields are emitted
Support caseSupport mailboxOnly as long as needed to resolve and document the case; accidental customer content is removed promptly

If the app window closes after a move is dispatched, Carryover cannot restore the in-memory command. It does not persist a customer-content move journal and will not offer a blind automatic retry.

Service providers and transfers

The first release uses monday.com and monday Code for the app surface, API access, hosting, secret storage, lifecycle state, and operational logging. Carryover does not use third-party advertising, session replay, or customer-content analytics. The legally reviewed Marketplace policy will name the responsible legal entity and any additional provider before submission.

Deletion, uninstall, and your choices

A valid uninstall or deauthorization disables new entitlement, removes tenant-linked allow state, and records only a content-free deletion certificate. Carryover’s internal target is completion within 24 hours and no later than the applicable 10-day Marketplace ceiling unless law or written consent requires otherwise.

To request deletion of Carryover-held metadata or support records, email me@bennetthilberg.com. We will verify authority without asking you to send item content or credentials. Native monday receipts remain under the customer account’s control.

Security practices

  • Least-purpose scopes: boards:read, boards:write, and updates:write.
  • No request or response body logging for monday GraphQL or authorization routes.
  • Independent move and receipt kill switches, checked immediately before each write.
  • Exact app/session verification and fail-closed entitlement decisions.
  • No customer-content database, background access token, third-party analytics, or advertising pixels in the first release.

No security measure is absolute. Please report suspected unauthorized access, mutation, token exposure, or data disclosure through the security contact path.

Questions and policy changes

Questions may be sent to me@bennetthilberg.com. Material changes will be dated on this page. Carryover will not use app access to send marketing messages; any future optional product communications will require a separate disclosed choice.