Effective date: August 6, 2026
The short version: this product's job is to remember what happened on your board, so — unlike most Power-Ups — it does store data on our servers: action metadata (what kind of change, when), the titles of cards and lists, and the acting member's Trello id. It never stores anyone's name, email, or avatar; never card descriptions, comment text, or attachments; and names you see in the timeline are resolved in your own browser, from the board itself. Recording is switched on by a board or workspace admin, everything we hold can be exported and deleted from settings, and every deletion — including our own automatic pruning — leaves a visible record.
1. Who We Are
Audit Log & Board History is a Trello Power-Up operated by Macon Apps, a trade name of Investor Direction LLC, an Ohio (USA) entity. Contact: [email protected] or 937-217-7327.
2. What the Power-Up Accesses
When an admin connects a board, Trello asks them to authorize the Power-Up. The token Trello issues is read-only, expires after 30 days, and is used transiently — to register the board's activity listener and to verify admin permissions — then discarded. It is never stored on our servers. After that, board activity reaches us through Trello's webhook system: Trello sends each action to our server as it happens, and our server keeps only the reduced record described below.
3. What We Store
For each recorded action on a connected board, our server stores:
- the action type (e.g. "card created", "card deleted", "card moved");
- the acting member's Trello member id — a pseudonymous identifier, never their name;
- the card and list ids involved, and their titles (also checklist, check-item, and label titles where relevant);
- the timestamp;
- a restricted summary of which fields changed — old/new values for dates, positions, and flags; free text (descriptions, comments) is reduced to a character count.
Explicitly never stored:
- card or board descriptions and comment text (lengths at most);
- attachments — contents, URLs, and even filenames;
- member display names, usernames, emails, or avatars. The names you see in the timeline are looked up by your own browser from the board you're viewing — they never reach our database.
Alongside the timeline we keep small operational records: which boards are connected and which admin switched recording on or off; a per-workspace billing record (Stripe customer and subscription references, plan, seat count — never card details); and permanent deletion records ("who deleted how much history, when" — never the deleted content itself).
4. Who Can See the Timeline
Every member of a connected board can read that board's whole timeline, including filtering it by person. That matches Trello's own activity feed and the product's purpose — a shared record the whole team can trust — but it does mean a searchable, per-person history of activity on that board. Because of that:
- turning recording on requires a board or workspace admin, verified against Trello — not just anyone who can open the board;
- who turned it on (and who turned it off) is shown to every board member in settings;
- a workspace that doesn't want a colleague-filterable activity history should not enable this Power-Up.
5. How Long We Keep It
| Situation | Retention |
|---|---|
| Free plan | Rolling 7-day window, enforced on our servers by a nightly job. The automatic pruning itself leaves a visible record. |
| Pro plan | History kept for as long as the workspace is subscribed. A failed payment does not destroy history — paid history is protected for 30 days past any billing lapse, longer than Stripe's full retry cycle. |
| Recording stopped / Power-Up disconnected | History kept 30 days, then automatically purged — with a deletion record naming the admin who stopped recording. Within those 30 days an admin can export, delete sooner, or re-connect to keep it. |
| Deletion records | Kept permanently — they are the tamper-evidence that makes the log trustworthy. They contain counts, dates, and (until an erasure request) the acting admin's member id — never deleted content. |
| Billing records | Retained while the Stripe relationship exists; Stripe is the system of record. Cancel via the billing portal to end it. |
6. How Deletion Works
- Delete a board's history (settings → admin only): offers a CSV export first, requires typing the board id to confirm, then permanently deletes the board's recorded events. A deletion record — who, when, how many events, covering which date range, and whether an export was taken — remains visible to every board member.
- Erase everything for a workspace (settings → workspace admin): shows a summary of what we hold, then deletes all recorded events and board records for the workspace, and anonymises the workspace's existing deletion records.
- Individual erasure (GDPR): we poll Trello's member-privacy compliance API at least every 14 days. When a member deletes their Atlassian account or revokes the Power-Up's access, every reference to their member id in our data — as actor, as target, as the admin on a record — is removed. The timeline rows remain (an audit log with holes is worse than useless) but no longer identify anyone.
- "Remove personal settings" in Trello clears your own per-member state. It deliberately does not stop the board's recording — that is an admin action — because an audit log any single member could switch off would not be an audit log.
- You can also email [email protected] with any erasure request and we will honor it within 30 days.
7. Payments
Checkout and billing are handled entirely by Stripe. Your card number and billing details go to Stripe, not to us; we never see or store them. A workspace admin can view invoices, change seats, update the payment method, or cancel anytime via settings → Manage billing.
8. Cookies, Analytics & Tracking
The Power-Up sets no cookies of its own, embeds no analytics, and does no ad tracking. Its pages talk only to Trello's API and to our own service — and, during checkout only, to Stripe.
9. Security
- All traffic is encrypted in transit (TLS, with HSTS).
- Every request to our service is authenticated with a Trello-signed token verified on our servers, pinned to this specific Power-Up and to the specific board being viewed.
- Destructive and billing actions additionally verify board/workspace-admin status live against Trello, under the caller's own credential.
- Authorization tokens are never stored; credentials never appear in URLs or logs.
10. Third Parties We Rely On
- Atlassian / Trello — hosts your boards, the Power-Up platform, and delivers board activity to us (Atlassian privacy policy).
- Stripe — payment processing (Stripe privacy policy).
- Cloudflare — hosts our service and its database (US/global edge) (Cloudflare privacy policy).
11. Your Rights
For your Trello account and board content, contact Atlassian. For the data this Power-Up holds: access and portability are served by the CSV export; deletion by the settings described in Section 6 or by email. If you're in a jurisdiction with specific privacy rights (GDPR, UK GDPR, CCPA, and similar), email [email protected] and we'll honor them.
12. Changes to This Policy
If we change this policy — for example, if a future feature (like scheduled digests or historic backfill) changes what we store — we'll update this page, adjust the effective date above, and describe the change in the Power-Up's listing. Material changes will be called out in the app itself.
13. Contact
Questions about this policy or your data: [email protected] · 937-217-7327 · or via the support portal.