About This Policy
INVESTOR DIRECTION LLC dba MACON APPS ("Company", "we", "us") respects your privacy and is committed to protecting it through our compliance with this policy. This document consolidates, into one place, the privacy policy for our websites and the individual privacy policies we previously published for each of our products. The product commitments set out in Part II are carried over from those individual policies without change in substance; each product section shows the date its terms were last revised.
This same document is published at each product's original privacy-policy address (the links you may have followed from the Trello or Atlassian Marketplace). Wherever you arrived from, you are reading the complete, current policy.
How to read this policy. Part I covers our websites and the things that are true of every product: who we are, how to reach us, your rights, and how we handle changes. Part II has one section per product describing exactly what that product accesses, what it stores, who can see it, how long it is kept, and how to delete it. Where Part II says something more specific than Part I about a product, the Part II section governs for that product.
Index
- Part I — General Policy (Websites and All Products)
- Who We Are and How to Contact Us
- Scope: Which Part Applies to You
- Children Under the Age of 18
- Information We Collect on Our Websites
- Lex Cygnus Activity Logging (Search and AI Chat) Lex Cygnus only
- Sale and Commercialization of Lex Cygnus Search and Chat Data Lex Cygnus only
- How We Use Your Information
- Disclosure of Your Information
- Choices About How We Use and Disclose Your Information
- Data Security
- Commitments Common to All Marketplace Products
- Your Privacy Rights
- Changes to This Policy
- Part II — Product-Specific Practices
- Product Index and At-a-Glance Comparison
- Checklist All HQ Trello
- Audit Log & Board History Trello
- Find and Replace + Banned Term Watch Trello
- Board Merge & Split Trello
- ConfigMonitor Jira Cloud
- Products Governed by Separate Documents (Rule Vault, Release Sync & Notes, Shift Handover Log, Assurance Map)
General Policy — Websites and All Products
1. Who We Are and How to Contact Us
Macon Apps is a trade name of Investor Direction LLC, an Ohio (USA) entity based in Lancaster, Ohio. Every product and website covered by this policy is operated by us unless a section below says otherwise.
To ask questions or comment about this policy, our privacy practices, or your data, contact us at [email protected], by phone at 937-217-7327, or through our support portal.
2. Scope: Which Part Applies to You
This policy describes the types of information we may collect from you or that you may provide, and our practices for collecting, using, maintaining, protecting, and disclosing that information, when you:
- Visit our websites — MACONAPPS.COM, AIJUDGE.IO, PLANTERMONITOR.COM, LEXCYGNUS.COM, and INVESTORDIRECTION.COM (together, our "Website"), including in email, text, and other electronic messages between you and the Website. Sections 3 through 10 of Part I apply. Sections 5 and 6 apply only to the Lex Cygnus product at LEXCYGNUS.COM, the one website that offers search and AI chat.
- Use one of our marketplace products — the Trello Power-Ups and Jira Cloud app listed in Part II. Sections 1, 2, 11, 12 and 13 of Part I apply, together with that product's own section in Part II.
It does not apply to information collected by:
- Us offline or through any other means, including on any other website operated by Company or any third party; or
- Any third party, including through any application or content (including advertising) that may link to or be accessible from the Website; or
- Atlassian, Trello, Microsoft, Stripe, or Cloudflare in their own right. Their handling of your account and of the platforms our products run on is governed by their own policies, linked from the relevant product section.
Please read this policy carefully to understand our policies and practices regarding your information and how we will treat it. If you do not agree with our policies and practices, your choice is not to use our Website or products. By accessing or using them, you agree to this privacy policy. This policy may change from time to time (see Changes to This Policy). Your continued use after we make changes is deemed to be acceptance of those changes, so please check the policy periodically for updates.
3. Children Under the Age of 18
Our Website and products are not intended for children under 18 years of age. No one under age 18 may provide any information to the Website. We do not knowingly collect personal information from children under 18. If you are under 18, do not use or provide any information on this Website. If we learn we have collected or received personal information from a child under 18 without verification of parental consent, we will delete that information. If you believe we might have any information from or about a child under 18, please contact us at [email protected].
4. Information We Collect on Our Websites
We collect several types of information from and about users of our Website, including information:
- By which you may be personally identified, such as name, postal address, e-mail address, telephone number, or any other identifier by which you may be contacted online or offline ("personal information");
- That is about you but individually does not identify you; and/or
- About your internet connection, the equipment you use to access our Website, and usage details.
- On Lex Cygnus (LEXCYGNUS.COM) only: search queries you submit and the results returned, including the text of your search.
- On Lex Cygnus only: AI chat messages you send and the responses generated, including the full text of conversations with our AI assistant.
- Your IP address and browser or device User-Agent string, collected automatically on each request to our servers.
We collect this information:
- Directly from you when you provide it to us.
- Automatically as you navigate through the site. Information collected automatically may include usage details, IP addresses, and information collected through cookies.
Information You Provide to Us
The information we collect on or through our Website may include:
- Information that you provide by filling in forms on our Website. We may also ask you for information when you report a problem with our Website.
- Records and copies of your correspondence (including email addresses), if you contact us.
- Your account credentials and authentication information when you sign in using Google or Apple sign-in.
You also may provide information to be published or displayed (hereinafter, "posted") on public areas of the Website, or transmitted to other users of the Website or third parties (collectively, "User Contributions"). Your User Contributions are posted on and transmitted to others at your own risk. Please be aware that no security measures are perfect or impenetrable. Additionally, we cannot control the actions of other users of the Website with whom you may choose to share your User Contributions. Therefore, we cannot and do not guarantee that your User Contributions will not be viewed by unauthorized persons.
Information We Collect Through Automatic Data Collection Technologies
As you navigate through and interact with our Website, we may use automatic data collection technologies to collect certain information about your equipment, browsing actions, and patterns, including:
- Details of your visits to our Website and other communication data and the resources that you access and use on the Website.
- Information about your computer and internet connection, including your IP address, operating system, and browser type.
The information we collect automatically may include personal information, and we may maintain it or associate it with personal information we collect in other ways or receive from third parties. It helps us to improve our Website and to deliver a better and more personalized service, including by enabling us to:
- Estimate our audience size and usage patterns.
- Store information about your preferences, allowing us to customize our Website according to your individual interests.
- Speed up your searches.
- Recognize you when you return to our Website.
5. Lex Cygnus Activity Logging (Search and AI Chat) Lex Cygnus only
This section applies only to Lex Cygnus, the legal research product at LEXCYGNUS.COM, which is the only product we offer with search and AI chat features. It does not apply to our other websites, and it does not apply to the marketplace products in Part II, none of which has a search or chat feature that reports to us (see Section 11).
When you use Lex Cygnus, we automatically log certain activity data for security, abuse prevention, and service improvement purposes. This logged data includes:
- Search queries: the text of each search you submit and the results our system returns.
- AI chat conversations: messages you send to our AI assistant and the responses generated, including timestamps.
- IP address: the Internet Protocol address of the device used to make each request to our servers.
- User-Agent string: the browser or application identifier sent automatically by your device, which may indicate your browser type, operating system, and device category.
- Authentication events: records of sign-in and sign-out actions associated with your account.
This information is retained in our secure database and is used solely for the purposes of:
- Detecting and blocking automated abuse (bots and scrapers).
- Diagnosing technical problems and improving service reliability.
- Understanding how our features are used in aggregate.
- Complying with legal obligations and responding to lawful requests.
We do not sell activity log data in a form that personally identifies you. However, as described in Section 6 below, we reserve the right to sell, license, or otherwise commercialize anonymized or aggregated search and chat data. IP addresses and User-Agent strings are used for security and abuse prevention and are not sold as standalone advertising identifiers.
6. Sale and Commercialization of Lex Cygnus Search and Chat Data Lex Cygnus only
This section, like Section 5, applies only to the search and AI chat features of Lex Cygnus (LEXCYGNUS.COM). It does not apply to any other website we operate, and data from the marketplace products in Part II is never sold, shared, or used for training (see Section 11).
In addition to the uses described above, and as set forth in the Lex Cygnus Terms of Service, when you use Lex Cygnus you acknowledge and consent to the following data practices:
- We reserve the right to sell, license, share, or otherwise commercialize your anonymized or aggregated Lex Cygnus search and chat data to third parties, including for research, analytics, advertising, and artificial intelligence (AI) model training purposes.
- This data may include the text of your search queries, the results returned, and the content of your AI chat conversations, provided in de-identified or aggregated form.
- Before any such sale, license, or sharing, search queries and chat content are anonymized or aggregated so that they are not intended to identify you individually.
Important — Do Not Submit Personal Information in Lex Cygnus Searches or Chats. Because your Lex Cygnus search queries and chat messages may be logged, retained, and commercialized in anonymized or aggregated form, you should NOT include personally identifiable information (PII) — such as your name, address, Social Security number, financial account numbers, health information, or other sensitive data — in your searches or chat messages. We are not responsible for any harm resulting from PII you voluntarily submit through the search or chat features.
7. How We Use Your Information
We use information that we collect about you or that you provide to us, including any personal information:
- To present our Website and its contents to you.
- To provide you with information, products, or services that you request from us.
- To fulfill any other purpose for which you provide it.
- To carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collection.
- To notify you about changes to our Website or any products or services we offer or provide through it.
- In any other way we may describe when you provide the information.
- For any other purpose with your consent.
If you do not want us to use your information in this way, please adjust your user preferences in your account profile. For more information, see Section 9, Choices About How We Use and Disclose Your Information.
We may use the information we have collected from you on our Website to enable us to display advertisements to our advertisers' target audiences. Even though we do not disclose your personal information for these purposes without your consent, if you click on or otherwise interact with an advertisement, the advertiser may assume that you meet its target criteria.
8. Disclosure of Your Information
We may disclose aggregated information about our users without restriction.
We may disclose personal information that we collect or you provide as described in this privacy policy:
- To our subsidiaries and affiliates.
- To contractors, service providers, and other third parties we use to support our business. For the marketplace products, the complete list of such providers is stated in each product's section in Part II.
- To a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of INVESTOR DIRECTION LLC dba MACON APPS's assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by INVESTOR DIRECTION LLC dba MACON APPS about our users is among the assets transferred.
- To fulfill the purpose for which you provide it.
- For any other purpose disclosed by us when you provide the information.
- With your consent.
We may also disclose your personal information:
- To comply with any court order, law, or legal process, including to respond to any government or regulatory request.
- To enforce or apply our terms of use and other agreements, including for billing and collection purposes.
- If we believe disclosure is necessary or appropriate to protect the rights, property, or safety of INVESTOR DIRECTION LLC dba MACON APPS, our customers, or others.
9. Choices About How We Use and Disclose Your Information
We strive to provide you with choices regarding the personal information you provide to us. We have created mechanisms to provide you with the following control over your information:
- Tracking Technologies and Advertising. You can set your browser to refuse all or some browser cookies, or to alert you when cookies are being sent. If you disable or refuse cookies, please note that some parts of our Website may then be inaccessible or not function properly. (Our marketplace products set no cookies of their own; see Section 11.)
- You can also always opt-out by sending us an email with your request to [email protected].
We do not control third parties' collection or use of your information to serve interest-based advertising. However, these third parties may provide you with ways to choose not to have your information collected or used in this way. You can opt out of receiving targeted ads from members of the Network Advertising Initiative ("NAI") on the NAI's website.
10. Data Security
The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of our Website, you are responsible for keeping this password confidential. We ask you not to share your password with anyone.
Unfortunately, the transmission of information via the internet is not completely secure. Although we do our best to protect your personal information, we cannot guarantee the security of your personal information transmitted to our Website. Any transmission of personal information is at your own risk. We are not responsible for circumvention of any privacy settings or security measures contained on the Website.
Each marketplace product's section in Part II describes the specific technical measures (transport encryption, request authentication, admin verification, credential handling) that product applies.
11. Commitments Common to All Marketplace Products
The following is true of every product listed in Part II. Each product section adds the detail specific to that product and, where it says something more specific, governs.
- No sale, sharing, advertising, or AI training. Data our products access or store is used only to provide that product to your workspace or site. It is never sold, shared with advertisers, or used to train AI models. Sections 5 and 6 of this Part apply only to Lex Cygnus and not to any product in Part II.
- No cookies, analytics, or tracking. None of the products sets cookies of its own, embeds analytics, or does ad tracking. Each product's network calls are limited to the platform it runs on (Trello or Atlassian), our own service where one exists, and Stripe during checkout only.
- No credentials stored. No product stores your Trello or Atlassian API tokens, passwords, or any other credential on our servers. Tokens are used within the request that carries them (or, for Checklist All HQ, stay in your own browser) and never appear in URLs or logs.
- No names or emails, unless the platform holds them. Products that keep any record of who did something record only a pseudonymous Trello member id. Names shown in a product's interface are resolved by your own browser from Trello. The one exception is ConfigMonitor, which stores admin display names taken from Jira's audit log, and only inside your own Atlassian environment.
- Payments never reach us. Card numbers and billing details go to Stripe (Trello Power-Ups) or to Atlassian (Jira Cloud apps), never to us. We hold only the opaque customer, subscription, and plan references needed to know what a workspace is entitled to.
- Admin-verified destructive actions. Where a product offers data deletion, billing changes, or other destructive actions, it verifies board, workspace, or site admin status live against the platform at the time of the request.
- Erasure requests honoured. Any erasure or access request sent to [email protected] is honoured within 30 days and without charge.
12. Your Privacy Rights
If you are in a jurisdiction with specific privacy rights (GDPR, UK GDPR, CCPA/CPRA, and similar), you may request access to, correction of, portability of, or deletion of the personal data we hold about you by emailing [email protected]. We honour such requests without charge and within 30 days.
- For our Website, requests concern the information described in Sections 4 and 5.
- For a marketplace product, the personal data we may hold is set out in that product's section; each section explains the self-service, automatic, and on-request routes to deletion. Requests about your Trello or Atlassian account itself, and about board or issue content those platforms hold, should be directed to Atlassian.
13. Changes to This Policy
It is our policy to post any changes we make to our privacy policy on this page and to adjust the effective date at the top. If a change affects what a product stores or how long it keeps it — for example a future feature such as scheduled digests, historic backfill, or external notifications — we will update that product's section and its "last revised" date before the change ships, describe the change in the product's marketplace listing, and call material changes out in the product itself. A product's storage behaviour and its section here are maintained together; if they ever disagree, we treat that as a bug and fix it.
Product-Specific Practices
Each section below is self-contained: it tells you what the product accesses, what it stores and where, who can see it, how long it is kept, how it is deleted, and which third parties are involved. Read the section for the product you use together with Part I.
Product Index and At-a-Glance Comparison
| Product | Platform | Where it runs | Stores your content? | Personal data we hold | Billing via |
|---|---|---|---|---|---|
| Checklist All HQ | Trello Power-Up | Your browser; Cloudflare license service | No. Card and checklist data never leaves your browser. | None (workspace id and Stripe references only) | Stripe |
| Audit Log & Board History | Trello Power-Up | Cloudflare | Metadata and titles only. Never descriptions, comments, or attachments. | Trello member ids on recorded actions | Stripe |
| Find and Replace + Banned Term Watch | Trello Power-Up | Cloudflare (Workers, D1, KV) | Briefly. Match snippets and the undo journal, 7 days. | Trello member ids on records of actions | Stripe |
| Board Merge & Split | Trello Power-Up | Cloudflare (Workers, D1, KV) | No card content. Board and list metadata plus card ids for undo. | Trello member ids on records of actions | Stripe |
| ConfigMonitor | Jira Cloud app (Forge) | Entirely inside Atlassian; no Macon Apps servers | Configuration only. Snapshots and change history, never issue content. | Admin display names, inside your Atlassian environment | Atlassian Marketplace |
| Rule Vault | Jira Cloud app | Governed by its Data Processing Agreement & Written Security Policy | Atlassian Marketplace | ||
| Release Sync & Notes | Jira Cloud app | Governed by its Data Processing Agreement & Written Security Policy | Atlassian Marketplace | ||
| Shift Handover Log | Microsoft Teams app | A product of J.P. Johnson Law LLC; governed by its own privacy policy | |||
| Assurance Map | Microsoft Teams app | A product of J.P. Johnson Law LLC; governed by its own privacy policy | |||
Checklist All HQ Trello Power-Up
The short version: your Trello boards, cards, and checklists are read by your own browser, directly from Trello, using a token you grant — and are never sent to, stored on, or seen by our servers. The only thing we store is your Trello workspace ID and a Stripe subscription reference, so we know which workspace has a paid plan.
What the Power-Up Accesses
When you authorize Checklist All HQ inside Trello, Trello issues a token that lets the Power-Up act as you, limited to boards you can already access. Using that token, the Power-Up reads board names, lists, cards, checklists and checklist items (including their due dates and assignees), and board member names — and writes only one thing: checklist item completion state, when you check an item off in the console.
Where Your Data Goes (and Doesn't)
- Card and checklist data: fetched by your browser directly from Trello's API, displayed in the console, and discarded when you close it. It is never transmitted to Macon Apps servers, never stored by us, and never shared with anyone.
- Your authorization token: stored by Trello's official Power-Up client in your own browser's local storage. We cannot read it from our servers, and it never leaves your browser except in direct calls to Trello's API.
- Settings: your board selection and an authorized-yes/no flag are kept in Trello's own Power-Up storage (managed by Atlassian, removed when the Power-Up is removed).
- CSV exports: generated in your browser and saved to your own device. Nothing is uploaded.
What We Do Store
To operate paid subscriptions, our license service (hosted on Cloudflare) stores one small record per subscribed workspace:
- the Trello workspace (organization) ID — an identifier for the workspace, not any person;
- a Stripe customer ID and subscription ID — opaque references into our payment processor;
- a timestamp.
That's the whole record. It contains no names, no emails, no board or card content. When a subscription is canceled and its paid period ends, the record is deleted automatically.
Payments
Checkout and billing are handled entirely by Stripe. Your card number and billing details go to Stripe, not to us; we never see or store them. You can view, update, or cancel your subscription anytime through the billing portal.
Cookies, Analytics & Tracking
Checklist All HQ sets no cookies of its own, embeds no analytics, and does no ad tracking. The only network calls the Power-Up makes are to Trello's API, to our license check (which receives your workspace ID and nothing else), and — during checkout only — to Stripe.
Data Retention & Deletion
- Card data: never retained by us in the first place.
- Token & settings: use Trello's "Remove personal settings" on the Power-Up, or remove the Power-Up from your board, to clear them. You can also revoke the token anytime from your Trello account's application settings.
- License record: deleted automatically when your subscription ends. To request earlier deletion, email [email protected] and we will remove it within 30 days (this also ends the paid plan for that workspace).
- Stripe records: retained by Stripe per its own policy and legal requirements (e.g., tax and accounting).
Third Parties We Rely On
- Atlassian / Trello — hosts your boards and the Power-Up platform (Atlassian privacy policy).
- Stripe — payment processing (Stripe privacy policy).
- Cloudflare — hosts the Power-Up's static files and the license service (Cloudflare privacy policy).
Your Rights
Because we hold no personal data about you beyond what's described above, most privacy-law requests (access, correction, portability, deletion) are satisfied either by Trello/Atlassian (for your board content and account) or by a quick email to us for the license record. See Part I, Section 12.
Audit Log & Board History Trello Power-Up
The short version: this product's job is to remember what happened on your board, so — unlike most Power-Ups — it does store data on our servers: action metadata (what kind of change, when), the titles of cards and lists, and the acting member's Trello id. It never stores anyone's name, email, or avatar; never card descriptions, comment text, or attachments; and names you see in the timeline are resolved in your own browser, from the board itself. Recording is switched on by a board or workspace admin, everything we hold can be exported and deleted from settings, and every deletion — including our own automatic pruning — leaves a visible record.
What the Power-Up Accesses
When an admin connects a board, Trello asks them to authorize the Power-Up. The token Trello issues is read-only, expires after 30 days, and is used transiently — to register the board's activity listener and to verify admin permissions — then discarded. It is never stored on our servers. After that, board activity reaches us through Trello's webhook system: Trello sends each action to our server as it happens, and our server keeps only the reduced record described below.
What We Store
For each recorded action on a connected board, our server stores:
- the action type (e.g. "card created", "card deleted", "card moved");
- the acting member's Trello member id — a pseudonymous identifier, never their name;
- the card and list ids involved, and their titles (also checklist, check-item, and label titles where relevant);
- the timestamp;
- a restricted summary of which fields changed — old/new values for dates, positions, and flags; free text (descriptions, comments) is reduced to a character count.
Explicitly never stored:
- card or board descriptions and comment text (lengths at most);
- attachments — contents, URLs, and even filenames;
- member display names, usernames, emails, or avatars. The names you see in the timeline are looked up by your own browser from the board you're viewing — they never reach our database.
Alongside the timeline we keep small operational records: which boards are connected and which admin switched recording on or off; a per-workspace billing record (Stripe customer and subscription references, plan — never card details); and permanent deletion records ("who deleted how much history, when" — never the deleted content itself).
Who Can See the Timeline
Every member of a connected board can read that board's whole timeline, including filtering it by person. That matches Trello's own activity feed and the product's purpose — a shared record the whole team can trust — but it does mean a searchable, per-person history of activity on that board. Because of that:
- turning recording on requires a board or workspace admin, verified against Trello — not just anyone who can open the board;
- who turned it on (and who turned it off) is shown to every board member in settings;
- a workspace that doesn't want a colleague-filterable activity history should not enable this Power-Up.
How Long We Keep It
| Situation | Retention |
|---|---|
| Free plan | Rolling 7-day window, enforced on our servers by a nightly job. The automatic pruning itself leaves a visible record. |
| Pro plan | History kept for as long as the workspace is subscribed. A failed payment does not destroy history — paid history is protected for 30 days past any billing lapse, longer than Stripe's full retry cycle. |
| Recording stopped / Power-Up disconnected | History kept 30 days, then automatically purged — with a deletion record naming the admin who stopped recording. Within those 30 days an admin can export, delete sooner, or re-connect to keep it. |
| Deletion records | Kept permanently — they are the tamper-evidence that makes the log trustworthy. They contain counts, dates, and (until an erasure request) the acting admin's member id — never deleted content. |
| Billing records | Retained while the Stripe relationship exists; Stripe is the system of record. Cancel via the billing portal to end it. |
How Deletion Works
- Delete a board's history (settings → admin only): offers a CSV export first, requires typing the board id to confirm, then permanently deletes the board's recorded events. A deletion record — who, when, how many events, covering which date range, and whether an export was taken — remains visible to every board member.
- Erase everything for a workspace (settings → workspace admin): shows a summary of what we hold, then deletes all recorded events and board records for the workspace, and anonymises the workspace's existing deletion records.
- Individual erasure (GDPR): we poll Trello's member-privacy compliance API at least every 14 days. When a member deletes their Atlassian account or revokes the Power-Up's access, every reference to their member id in our data — as actor, as target, as the admin on a record — is removed. The timeline rows remain (an audit log with holes is worse than useless) but no longer identify anyone.
- "Remove personal settings" in Trello clears your own per-member state. It deliberately does not stop the board's recording — that is an admin action — because an audit log any single member could switch off would not be an audit log.
- You can also email [email protected] with any erasure request and we will honor it within 30 days.
Payments
Checkout and billing are handled entirely by Stripe. Your card number and billing details go to Stripe, not to us; we never see or store them. A workspace admin can view invoices, switch between monthly and annual, update the payment method, or cancel anytime via settings → Manage billing.
Cookies, Analytics & Tracking
The Power-Up sets no cookies of its own, embeds no analytics, and does no ad tracking. Its pages talk only to Trello's API and to our own service — and, during checkout only, to Stripe.
Security
- All traffic is encrypted in transit (TLS, with HSTS).
- Every request to our service is authenticated with a Trello-signed token verified on our servers, pinned to this specific Power-Up and to the specific board being viewed.
- Destructive and billing actions additionally verify board/workspace-admin status live against Trello, under the caller's own credential.
- Authorization tokens are never stored; credentials never appear in URLs or logs.
Third Parties We Rely On
- Atlassian / Trello — hosts your boards, the Power-Up platform, and delivers board activity to us (Atlassian privacy policy).
- Stripe — payment processing (Stripe privacy policy).
- Cloudflare — hosts our service and its database (US/global edge) (Cloudflare privacy policy).
Your Rights
For your Trello account and board content, contact Atlassian. For the data this Power-Up holds: access and portability are served by the CSV export; deletion by the settings described above or by email. See Part I, Section 12.
Find and Replace + Banned Term Watch Trello Power-Up
What the Power-Up Accesses
The Power-Up works entirely through your own Trello authorization. When you authorize it (read and write), it reads card titles, card descriptions and checklist items on the boards you point it at, and — when you run a rewrite — edits those same fields under your own Trello permissions. It cannot change anything you could not change by hand, and a card you cannot edit is reported as refused rather than modified.
Board and workspace membership is read with Trello's member=false option,
which returns member identifiers and roles only — names, usernames, email addresses,
avatars and bios are never requested from the Trello API, so they never enter the service
at all.
What We Store
Most of what the Power-Up touches is read, matched in memory, and discarded within the same request. It stores a small, deliberate set of data outside Trello, because preview and undo are impossible without it:
- Match snippets — roughly 30 characters of card text on either side of each match, so the results list and the before/after preview can show you what you are about to change. Kept 7 days.
- The undo journal — the complete before and after text of every field a rewrite changed, including full card descriptions. This exists so undo can restore a field exactly, and so a field a colleague edited afterwards is detected and left alone rather than overwritten. Kept 7 days, after which undo for that job is no longer offered.
- Your search and replacement strings, including saved and watched terms — user-authored text, kept with the records they belong to (see the schedule below).
- Identifiers and bookkeeping — card, board and checklist ids, card short links, board titles, match counts and job statuses, which make up the change logs and progress reporting.
- Trello member ids on the rows recording who ran a search or rewrite or saved a term. These are pseudonymous but re-identifiable through Trello, so we treat them as personal data (see Your Rights below).
- Billing records — your workspace's Stripe customer id, plan and subscription status.
What we never store: member names, usernames, email addresses, avatars or bios; Trello API tokens or any other credential (your token is used within each request and never written to storage or logs); card comments, attachments, custom fields or labels; and no card content beyond the two items above.
Who Can See What
Search results and their snippets are visible to the member who ran the search and, for a single-board search, to members of that board. Rewrite change logs are scoped the same way. A workspace admin can see the workspace's rewrite history. The banned-term watch list and its alerts are visible to subscribed members of the workspace, but an alert carries references only — which card, which field, which term — and the card itself is fetched live under the viewer's own Trello permissions, so a member who cannot open a board sees nothing beyond an identifier.
How Long We Keep It
| Data | Retention |
|---|---|
| Card text — match snippets | 7 days |
| Card text — undo journal (complete before/after values) | 7 days |
| Search worklists, board titles, match counts | 30 days |
| Rewrite plans never executed | 7 days |
| Rewrite plans executed | the card list inside them is deleted the moment the job starts; the remaining record is deleted with its job |
| Job change logs (identifiers, counts, statuses — no card text) | 365 days |
| Watch alerts | 90 days once dismissed; 365 days if never dismissed |
| Webhook idempotency records | 30 days |
| Saved terms and watched boards | while the workspace is subscribed, then 90 days after the subscription ends |
| Billing records (Stripe customer id, plan, status) | retained — Stripe is the system of record, and deleting the local copy would misreport what the workspace is entitled to |
These periods are enforced automatically by a nightly job. Trello does not notify Power-Ups when they are removed from a board, so removal is not an event we can act on — but nothing further is written after removal, and the schedule above applies from that point: all card content is gone within 7 days, and everything except the billing record within 365 days.
How Deletion Works
- Self-service, immediate: a Trello workspace admin opens the Power-Up and uses the data deletion action, which erases every record we hold for that workspace. The request must echo the workspace id as confirmation, so a mis-click cannot destroy data. Billing records are retained as described above; cancel the subscription in the billing portal to end that relationship.
- Automatic, per member: we poll Trello's member privacy endpoint nightly and honour account-deleted, account-updated, token-revoked and token-expired events by removing that member's identifier from every record that holds it.
- Automatic, time-based: the retention schedule above.
- On request: email [email protected] and we will run the workspace purge for you.
Payments
Subscriptions are processed by Stripe. Card details are entered on Stripe's hosted checkout page and managed in Stripe's customer portal — they never reach us and we never see them. We store only the Stripe customer id, plan and subscription status needed to know what your workspace is entitled to.
Cookies, Analytics & Tracking
The Power-Up sets no cookies and uses no analytics, advertising or tracking of any kind. There is no analytics provider, no advertising provider, and no sub-processor beyond the two named below. No customer data is sold, shared, or used for training.
Security
- All traffic is HTTPS with HSTS (one-year max-age, including subdomains). Data at rest is encrypted by Cloudflare D1 and KV.
- Every request is authenticated with the Trello-signed token for this specific Power-Up, verified server-side against Trello's public keys and pinned to this Power-Up's own id — a token issued for a different Power-Up is rejected.
- Your Trello REST token is additionally checked to belong to you, used within the request, and never stored or logged.
- Billing, data deletion and workspace-wide rewrites additionally require Trello workspace admin, verified live against Trello.
- The Power-Up iframe is served with a Content-Security-Policy containing no unsafe-inline, unsafe-eval or unsafe-hashes, and can only be framed by trello.com.
Third Parties We Rely On
- Cloudflare (Workers, D1, KV) — application hosting and data storage (Cloudflare privacy policy).
- Stripe — payment processing (Stripe privacy policy).
No other sub-processor is used.
Your Rights
The only personal data we hold is your Trello member id on records of actions you took. You can have it removed at any time: through a Trello account deletion or token revocation (honoured automatically, nightly), through your workspace admin running the data deletion action, or by emailing us. See Part I, Section 12.
Board Merge & Split Trello Power-Up
What the Power-Up Accesses
The Power-Up works entirely through your own Trello authorization. When you authorize it, it reads the structure of the boards you point it at — lists, labels, and card counts — to build a merge or split preview, and when you execute one, it moves lists and cards under your own Trello permissions. It can never change anything you could not change by hand, and an operation Trello refuses under your permissions is recorded as refused rather than performed.
Board and workspace membership is read with Trello's member=false option,
which returns member identifiers and roles only — names, usernames, email addresses,
avatars and bios are never requested from the Trello API, so they never enter the service
at all.
Card content is never requested, so it cannot be stored. The only card-shaped data the service ever handles is card ids — the minimum needed to count cards for the preview and to record which cards a merge moved so the merge can be undone. No titles, descriptions, comments, checklists, attachments, custom-field values or card members, ever.
What We Store
Most of what the Power-Up reads is used to answer the request and discarded. It stores a small, deliberate set of data outside Trello, because a previewed, resumable, undoable merge is impossible without it:
- Merge/split plans — board ids and names, the ordered operations (list ids, list names, label names and colours, positions, card counts), so execution runs exactly what you previewed.
- Job receipts — one row per operation performed, with its outcome, forming the audit history and CSV export.
- The undo record — the inverse of every destructive operation, including the card ids a drained list held before its cards were merged into another list. This is what makes a merge reversible; without the id set the cards are indistinguishable afterwards.
- Trello member ids on the rows recording who created each plan and job. These are pseudonymous but re-identifiable through Trello, so we treat them as personal data (see Your Rights below).
- Billing records — your workspace's Stripe customer id, plan and subscription status.
What we never store: card content of any kind; member names, usernames, email addresses, avatars or bios; Trello API tokens or any other credential (your token is used within each request and never written to storage or logs).
Who Can See What
You see the merges and splits you ran. A Trello workspace admin — verified live against Trello, never assumed — can see the workspace's job history and receipts. Receipts carry board and list names and operation outcomes; they never carry card content. Running, executing or undoing a merge requires admin rights on both boards involved, verified against Trello at the time of the request.
How Long We Keep It
| Data | Retention |
|---|---|
| Plans never executed | 7 days (and executable for only 24 hours) |
| Executed plans, job receipts, and undo records (card ids included) | 365 days — a year of change-management history, then pruned |
| Webhook idempotency records | 30 days |
| Short-lived caches (entitlement, membership decisions) | 5 minutes |
| Billing records (Stripe customer id, plan, status) | retained — Stripe is the system of record, and deleting the local copy would misreport what the workspace is entitled to |
These periods are enforced automatically by a nightly job. Trello does not notify Power-Ups when they are removed from a board, so removal is not an event we can act on — but nothing further is written after removal, and the schedule above applies from that point: everything except the billing record is gone within 365 days of its creation.
How Deletion Works
- Self-service, immediate: a Trello workspace admin opens the Power-Up and uses the data deletion action, which erases every plan, job, receipt and undo record we hold for that workspace. The request must echo the workspace id as confirmation, so a mis-click cannot destroy data. Billing records are retained as described above; cancel the subscription in the billing portal to end that relationship.
- Automatic, per member: we poll Trello's member privacy endpoint nightly and honour account-deleted, account-updated, token-revoked and token-expired events by removing that member's identifier from every record that holds it.
- Automatic, time-based: the retention schedule above.
- On request: email [email protected] and we will run the workspace purge for you.
Payments
Subscriptions are processed by Stripe. Card details are entered on Stripe's hosted checkout page and managed in Stripe's customer portal — they never reach us and we never see them. We store only the Stripe customer id, plan and subscription status needed to know what your workspace is entitled to. Undoing a merge is deliberately never gated on an active subscription: a lapsed plan can always put a board back the way it was.
Cookies, Analytics & Tracking
The Power-Up sets no cookies and uses no analytics, advertising or tracking of any kind. There is no analytics provider, no advertising provider, and no sub-processor beyond the two named below. No customer data is sold, shared, or used for training.
Security
- All traffic is HTTPS with HSTS (one-year max-age, including subdomains). Data at rest is encrypted by Cloudflare D1 and KV.
- Every request is authenticated with the Trello-signed token for this specific Power-Up, verified server-side against Trello's public keys and pinned to this Power-Up's own id — a token issued for a different Power-Up is rejected.
- Your Trello REST token is additionally checked to belong to you, used within the request, and never stored or logged.
- Merging, splitting and undoing require admin rights on both boards involved, verified live against Trello; billing and data deletion require workspace admin.
- Destructive actions sit behind a typed confirmation (the source board's name), enforced on the server — and closing a source board only ever happens because someone explicitly chose it.
- The Power-Up iframe is served with a Content-Security-Policy containing no unsafe-inline, unsafe-eval or unsafe-hashes, and can only be framed by trello.com.
- CSV exports neutralise spreadsheet formula injection, so a hostile list name cannot execute when an admin opens the audit export.
Third Parties We Rely On
- Cloudflare (Workers, D1, KV) — application hosting and data storage (Cloudflare privacy policy).
- Stripe — payment processing (Stripe privacy policy).
No other sub-processor is used.
Your Rights
The only personal data we hold is your Trello member id on records of actions you took. You can have it removed at any time: through a Trello account deletion or token revocation (honoured automatically, nightly), through your workspace admin running the data deletion action, or by emailing us. See Part I, Section 12.
ConfigMonitor Jira Cloud app
The short version: ConfigMonitor runs entirely on Atlassian's Forge platform, inside your Atlassian cloud environment. Everything it reads and everything it stores stays with Atlassian — the app makes no network calls to Macon Apps or to any other external service. We operate no servers for ConfigMonitor, so there is no place your data could reach us. The app never asks for, collects, or stores an API token, password, or any other credential.
What ConfigMonitor Accesses
ConfigMonitor reads your Jira site's configuration: workflows, custom field definitions, field configurations, screens and screen schemes, permission schemes, notification schemes, and issue type schemes. To show who made a change, it also reads Jira's built-in audit log records. All reads use the app permissions a site admin approves at install — Atlassian's Forge platform enforces that boundary.
ConfigMonitor does not read the content of your issues, comments, attachments, or user directories, and it writes nothing to your Jira configuration — it is a read-only observer.
What ConfigMonitor Stores, and Where
To detect and display changes, ConfigMonitor keeps the following in Forge storage — Atlassian-hosted storage that lives inside Atlassian's cloud, alongside your Jira data:
- Configuration snapshots: the current shape of each tracked configuration object, used to compute the next diff.
- Change events: the history you see in the timeline — timestamps, object names, before/after diffs, and plain-language summaries.
- Actor names: where Jira's audit log identifies the admin who made a change, that display name is stored on the change event. This is the only personal data ConfigMonitor holds, and it never leaves Atlassian's platform.
Because storage is provided by Atlassian's Forge platform, it inherits Atlassian's hosting, security, and data-residency arrangements for your site. Macon Apps has no independent copy and no way to access your site's data outside the app itself.
No API Tokens, Ever
ConfigMonitor authenticates through Forge's built-in app identity, granted once at install by your site admin. It has no setup screen requesting an email-plus-token, no credential field of any kind, and it does not collect, transmit, or store Atlassian user API tokens — in line with Atlassian Marketplace security requirements. If any screen ever appears to ask you for a credential, it is not ours: stop and contact us.
Payments
ConfigMonitor is sold through the Atlassian Marketplace. Billing, invoicing, and payment details are handled entirely by Atlassian on your existing Atlassian bill — Macon Apps never sees your payment information. Atlassian shares standard sales reporting with us (site-level license status), not personal payment data.
Cookies, Analytics & Tracking
ConfigMonitor sets no cookies of its own, embeds no analytics, and does no tracking of any kind. The app's user interface is served by Atlassian inside Jira, and the app makes no network egress to any non-Atlassian destination.
Data Retention & Deletion
- While installed: snapshots and change history are retained so the timeline and compliance exports keep working.
- On uninstall: the app's Forge storage is removed under Atlassian's platform rules for uninstalled apps. Nothing persists with Macon Apps, because nothing was ever sent to Macon Apps.
- Earlier deletion: to clear history while keeping the app installed, contact us at [email protected] and we'll walk you through it or ship it as a supported action.
- CSV exports are generated on demand and saved to your own device; you control those copies.
Third Parties We Rely On
- Atlassian — hosts Jira, the Forge platform the app runs on, the app's storage, and Marketplace billing (Atlassian privacy policy).
That's the whole list. ConfigMonitor uses no other processor, host, or service.
Your Rights
The only personal data ConfigMonitor holds is admin display names on change events, stored inside your own Atlassian environment and visible only to your site's admins. Requests about your Atlassian account and its data are handled by Atlassian; for anything about ConfigMonitor's stored history, see Part I, Section 12.
Products Governed by Separate Documents
The following products are listed here so this index is a complete map of everything we publish, but their data practices are set out in their own documents rather than in this policy:
- Rule Vault Jira Cloud app — governed by the Rule Vault Data Processing Agreement & Written Security Policy. For data we collect for our own business operations (support tickets, billing), Part I of this policy applies.
- Release Sync & Notes Jira Cloud app — governed by the Release Sync & Notes Data Processing Agreement & Written Security Policy. For data we collect for our own business operations (support tickets, billing), Part I of this policy applies.
- Shift Handover Log Microsoft Teams — a product of J.P. Johnson Law LLC, governed by its own privacy policy and terms of use.
- Assurance Map Microsoft Teams — a product of J.P. Johnson Law LLC, governed by its own privacy policy and terms of use.