Approval Trail: privacy
Last updated 7 September 2026.
Approval Trail records approval decisions on monday.com items. This page says exactly what
it stores, where, for how long, and how to get rid of it.
What is stored
- The account id, taken from the session token monday signs. Never from the request.
- The board id and item id an approval belongs to.
- For each event: the monday user id of the person who acted, the time, the type of
event, the approvers named on the round, its name, step and due date, the decision, and any
comment or reason that person typed when deciding, calling a round off, or
reopening one.
- One OAuth access token per account, used only to ask monday who may see a board.
Approval Trail does not read, copy or store the contents of your items, columns,
updates, files or boards. It stores the ids it needs and the decisions people record in it.
What is never stored
- Names and email addresses. The app shows names by asking monday for them in your browser,
with your own permissions, each time a screen is drawn. They are not written down here.
- Passwords. There is nothing to sign into.
- Anything about people outside your monday account.
monday's assistant
This app provides tools that monday's own assistant can run when you ask it something about
approvals, such as starting an approval round or asking what is waiting on you.
- monday runs the model, not this app. The assistant is monday's. This app has no
model of its own and no account with any AI provider.
- This app sends nothing to a model. Not your items, not your approvals, not your
names. The values arrive here already worked out by monday; the app reads its own record
and answers with facts from it.
- What arrives is the ids and values monday derived from what you asked, plus a
short-lived credential belonging to you. That credential is used for one thing: to ask
monday whether you may open the board in question. The assistant can never reach a board
you could not open yourself.
Where it is stored
In monday's own hosting (monday code) and its managed database, in the region monday assigns
to the app. It is not copied to any other provider, and it is not used to train anything.
Who can read it
Every request is checked twice: the session token proves who is asking, and monday is asked
whether that person can open the board in question. A member of your account who cannot open a
board cannot read its approvals, and a guest is only ever shown the boards they were invited
to, never the ones that are open to your staff. Records never cross between accounts.
How long it is kept
- While the app is installed: for as long as you keep it.
- When the app is uninstalled: the access token is deleted immediately, and the
records are deleted 30 days later. Reinstalling inside those 30 days cancels the
deletion, because an uninstall is often a mistake and an approval record cannot be rebuilt.
- On request: an account admin can erase everything at once from the account dashboard
widget, or by asking us. That does not wait for the 30 days.
Getting your data out
Any item's own record can be exported as CSV on every plan, including the free one, with the
hash of every event so it can be checked without this app. Whole boards and whole accounts can
be exported on the paid plan.
Sub-processors
monday.com, which hosts the app and its database. There are no others.
Contact
Questions, deletion requests, or anything else: globalmatchhub@gmail.com.
We answer within two business days.