Scope and responsible contact
This policy explains how Carryover processes information when an authorized monday.com user runs the Carryover item action or contacts support. The verified same-domain support contact is Bennett Hilberg at me@bennetthilberg.com. The final responsible legal entity and mailing details will be published before Marketplace submission.
What Carryover processes
Selected monday content
For one operator-selected handoff, the app reads the source and destination board identities and schemas, selected destination group, selected parent item name and supported text value, and an available source-board activity window filtered to that item. The current window is 24 hours with a maximum of 25 returned rows.
Carryover does not read update conversations, replies, files, documents, subitems, user profiles, email addresses, or unrelated item content in the first release.
Session and authorization data
The backend receives a monday-signed session token only to verify the current app, account, user, expiry, and subscription status. Immediately before a move or receipt, it also receives the operation class—move or receipt. The backend does not receive board IDs, item IDs, column IDs, names, the mapped value, activity rows, fingerprints, receipt text, monday access tokens, or raw GraphQL bodies.
Native receipt
After destination verification, Carryover writes a native monday update containing the source and destination, selected item, exact mapping, capture bounds, represented and omitted activity, verification result, privacy notice, and native Undo instructions. That receipt is controlled by the monday account and visible under the destination item’s existing permissions.
Operational events and support
The current application event path emits only a fixed safety classification: event class, optional move or receipt operation, allow or deny outcome, and fixed reason code. It excludes tenant, user, board, item, token, URL, request, and free-form content. Activation analytics and advertising trackers are disabled.
If you contact support, send only the reason code, UTC time, app version, and a redacted description. Do not send credentials, exports, full URLs, or unrelated item content.
Where data lives and how long
| Data | Location | Current retention |
|---|---|---|
| Selected item, mapping, and activity context | Carryover iframe memory | Active command only; pre-move confirmation expires after five minutes |
| monday-signed session token | Encrypted transit and backend memory | Verification request only |
| Native receipt | Customer’s monday item | Controlled by the customer through monday |
| Content-free lifecycle deny marker and deletion certificate | monday Code Secure Storage | Only as needed for revocation/deletion proof and within the applicable deletion ceiling |
| Fixed content-free operational events | monday Code logs | Subject to the host’s verified retention settings; no customer-content fields are emitted |
| Support case | Support mailbox | Only as long as needed to resolve and document the case; accidental customer content is removed promptly |
If the app window closes after a move is dispatched, Carryover cannot restore the in-memory command. It does not persist a customer-content move journal and will not offer a blind automatic retry.
Service providers and transfers
The first release uses monday.com and monday Code for the app surface, API access, hosting, secret storage, lifecycle state, and operational logging. Carryover does not use third-party advertising, session replay, or customer-content analytics. The legally reviewed Marketplace policy will name the responsible legal entity and any additional provider before submission.
Deletion, uninstall, and your choices
A valid uninstall or deauthorization disables new entitlement, removes tenant-linked allow state, and records only a content-free deletion certificate. Carryover’s internal target is completion within 24 hours and no later than the applicable 10-day Marketplace ceiling unless law or written consent requires otherwise.
To request deletion of Carryover-held metadata or support records, email me@bennetthilberg.com. We will verify authority without asking you to send item content or credentials. Native monday receipts remain under the customer account’s control.
Security practices
- Least-purpose scopes:
boards:read,boards:write, andupdates:write. - No request or response body logging for monday GraphQL or authorization routes.
- Independent move and receipt kill switches, checked immediately before each write.
- Exact app/session verification and fail-closed entitlement decisions.
- No customer-content database, background access token, third-party analytics, or advertising pixels in the first release.
No security measure is absolute. Please report suspected unauthorized access, mutation, token exposure, or data disclosure through the security contact path.
Questions and policy changes
Questions may be sent to me@bennetthilberg.com. Material changes will be dated on this page. Carryover will not use app access to send marketing messages; any future optional product communications will require a separate disclosed choice.