Privacy Policy

One policy for everything Macon Apps publishes: our websites, and each of our marketplace products. Part I applies to everyone. Part II adds the product-specific practices for the product you use.

Effective: September 9, 2026 · Investor Direction LLC dba Macon Apps

About This Policy

INVESTOR DIRECTION LLC dba MACON APPS ("Company", "we", "us") respects your privacy and is committed to protecting it through our compliance with this policy. This document consolidates, into one place, the privacy policy for our websites and the individual privacy policies we previously published for each of our products. The product commitments set out in Part II are carried over from those individual policies without change in substance; each product section shows the date its terms were last revised.

This same document is published at each product's original privacy-policy address (the links you may have followed from the Trello or Atlassian Marketplace). Wherever you arrived from, you are reading the complete, current policy.

How to read this policy. Part I covers our websites and the things that are true of every product: who we are, how to reach us, your rights, and how we handle changes. Part II has one section per product describing exactly what that product accesses, what it stores, who can see it, how long it is kept, and how to delete it. Where Part II says something more specific than Part I about a product, the Part II section governs for that product.

Index

  1. Part I — General Policy (Websites and All Products)
    1. Who We Are and How to Contact Us
    2. Scope: Which Part Applies to You
    3. Children Under the Age of 18
    4. Information We Collect on Our Websites
    5. Lex Cygnus Activity Logging (Search and AI Chat) Lex Cygnus only
    6. Sale and Commercialization of Lex Cygnus Search and Chat Data Lex Cygnus only
    7. How We Use Your Information
    8. Disclosure of Your Information
    9. Choices About How We Use and Disclose Your Information
    10. Data Security
    11. Commitments Common to All Marketplace Products
    12. Your Privacy Rights
    13. Changes to This Policy
  2. Part II — Product-Specific Practices
    1. Product Index and At-a-Glance Comparison
    2. Checklist All HQ Trello
    3. Audit Log & Board History Trello
    4. Find and Replace + Banned Term Watch Trello
    5. Board Merge & Split Trello
    6. ConfigMonitor Jira Cloud
    7. Products Governed by Separate Documents (Rule Vault, Release Sync & Notes, Shift Handover Log, Assurance Map)
Part I

General Policy — Websites and All Products

1. Who We Are and How to Contact Us

Macon Apps is a trade name of Investor Direction LLC, an Ohio (USA) entity based in Lancaster, Ohio. Every product and website covered by this policy is operated by us unless a section below says otherwise.

To ask questions or comment about this policy, our privacy practices, or your data, contact us at [email protected], by phone at 937-217-7327, or through our support portal.

2. Scope: Which Part Applies to You

This policy describes the types of information we may collect from you or that you may provide, and our practices for collecting, using, maintaining, protecting, and disclosing that information, when you:

It does not apply to information collected by:

Please read this policy carefully to understand our policies and practices regarding your information and how we will treat it. If you do not agree with our policies and practices, your choice is not to use our Website or products. By accessing or using them, you agree to this privacy policy. This policy may change from time to time (see Changes to This Policy). Your continued use after we make changes is deemed to be acceptance of those changes, so please check the policy periodically for updates.

3. Children Under the Age of 18

Our Website and products are not intended for children under 18 years of age. No one under age 18 may provide any information to the Website. We do not knowingly collect personal information from children under 18. If you are under 18, do not use or provide any information on this Website. If we learn we have collected or received personal information from a child under 18 without verification of parental consent, we will delete that information. If you believe we might have any information from or about a child under 18, please contact us at [email protected].

4. Information We Collect on Our Websites

We collect several types of information from and about users of our Website, including information:

We collect this information:

Information You Provide to Us

The information we collect on or through our Website may include:

You also may provide information to be published or displayed (hereinafter, "posted") on public areas of the Website, or transmitted to other users of the Website or third parties (collectively, "User Contributions"). Your User Contributions are posted on and transmitted to others at your own risk. Please be aware that no security measures are perfect or impenetrable. Additionally, we cannot control the actions of other users of the Website with whom you may choose to share your User Contributions. Therefore, we cannot and do not guarantee that your User Contributions will not be viewed by unauthorized persons.

Information We Collect Through Automatic Data Collection Technologies

As you navigate through and interact with our Website, we may use automatic data collection technologies to collect certain information about your equipment, browsing actions, and patterns, including:

The information we collect automatically may include personal information, and we may maintain it or associate it with personal information we collect in other ways or receive from third parties. It helps us to improve our Website and to deliver a better and more personalized service, including by enabling us to:

5. Lex Cygnus Activity Logging (Search and AI Chat) Lex Cygnus only

This section applies only to Lex Cygnus, the legal research product at LEXCYGNUS.COM, which is the only product we offer with search and AI chat features. It does not apply to our other websites, and it does not apply to the marketplace products in Part II, none of which has a search or chat feature that reports to us (see Section 11).

When you use Lex Cygnus, we automatically log certain activity data for security, abuse prevention, and service improvement purposes. This logged data includes:

This information is retained in our secure database and is used solely for the purposes of:

We do not sell activity log data in a form that personally identifies you. However, as described in Section 6 below, we reserve the right to sell, license, or otherwise commercialize anonymized or aggregated search and chat data. IP addresses and User-Agent strings are used for security and abuse prevention and are not sold as standalone advertising identifiers.

6. Sale and Commercialization of Lex Cygnus Search and Chat Data Lex Cygnus only

This section, like Section 5, applies only to the search and AI chat features of Lex Cygnus (LEXCYGNUS.COM). It does not apply to any other website we operate, and data from the marketplace products in Part II is never sold, shared, or used for training (see Section 11).

In addition to the uses described above, and as set forth in the Lex Cygnus Terms of Service, when you use Lex Cygnus you acknowledge and consent to the following data practices:

Important — Do Not Submit Personal Information in Lex Cygnus Searches or Chats. Because your Lex Cygnus search queries and chat messages may be logged, retained, and commercialized in anonymized or aggregated form, you should NOT include personally identifiable information (PII) — such as your name, address, Social Security number, financial account numbers, health information, or other sensitive data — in your searches or chat messages. We are not responsible for any harm resulting from PII you voluntarily submit through the search or chat features.

7. How We Use Your Information

We use information that we collect about you or that you provide to us, including any personal information:

If you do not want us to use your information in this way, please adjust your user preferences in your account profile. For more information, see Section 9, Choices About How We Use and Disclose Your Information.

We may use the information we have collected from you on our Website to enable us to display advertisements to our advertisers' target audiences. Even though we do not disclose your personal information for these purposes without your consent, if you click on or otherwise interact with an advertisement, the advertiser may assume that you meet its target criteria.

8. Disclosure of Your Information

We may disclose aggregated information about our users without restriction.

We may disclose personal information that we collect or you provide as described in this privacy policy:

We may also disclose your personal information:

9. Choices About How We Use and Disclose Your Information

We strive to provide you with choices regarding the personal information you provide to us. We have created mechanisms to provide you with the following control over your information:

We do not control third parties' collection or use of your information to serve interest-based advertising. However, these third parties may provide you with ways to choose not to have your information collected or used in this way. You can opt out of receiving targeted ads from members of the Network Advertising Initiative ("NAI") on the NAI's website.

10. Data Security

The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of our Website, you are responsible for keeping this password confidential. We ask you not to share your password with anyone.

Unfortunately, the transmission of information via the internet is not completely secure. Although we do our best to protect your personal information, we cannot guarantee the security of your personal information transmitted to our Website. Any transmission of personal information is at your own risk. We are not responsible for circumvention of any privacy settings or security measures contained on the Website.

Each marketplace product's section in Part II describes the specific technical measures (transport encryption, request authentication, admin verification, credential handling) that product applies.

11. Commitments Common to All Marketplace Products

The following is true of every product listed in Part II. Each product section adds the detail specific to that product and, where it says something more specific, governs.

12. Your Privacy Rights

If you are in a jurisdiction with specific privacy rights (GDPR, UK GDPR, CCPA/CPRA, and similar), you may request access to, correction of, portability of, or deletion of the personal data we hold about you by emailing [email protected]. We honour such requests without charge and within 30 days.

13. Changes to This Policy

It is our policy to post any changes we make to our privacy policy on this page and to adjust the effective date at the top. If a change affects what a product stores or how long it keeps it — for example a future feature such as scheduled digests, historic backfill, or external notifications — we will update that product's section and its "last revised" date before the change ships, describe the change in the product's marketplace listing, and call material changes out in the product itself. A product's storage behaviour and its section here are maintained together; if they ever disagree, we treat that as a bug and fix it.

Part II

Product-Specific Practices

Each section below is self-contained: it tells you what the product accesses, what it stores and where, who can see it, how long it is kept, how it is deleted, and which third parties are involved. Read the section for the product you use together with Part I.

Product Index and At-a-Glance Comparison

Product Platform Where it runs Stores your content? Personal data we hold Billing via
Checklist All HQ Trello Power-Up Your browser; Cloudflare license service No. Card and checklist data never leaves your browser. None (workspace id and Stripe references only) Stripe
Audit Log & Board History Trello Power-Up Cloudflare Metadata and titles only. Never descriptions, comments, or attachments. Trello member ids on recorded actions Stripe
Find and Replace + Banned Term Watch Trello Power-Up Cloudflare (Workers, D1, KV) Briefly. Match snippets and the undo journal, 7 days. Trello member ids on records of actions Stripe
Board Merge & Split Trello Power-Up Cloudflare (Workers, D1, KV) No card content. Board and list metadata plus card ids for undo. Trello member ids on records of actions Stripe
ConfigMonitor Jira Cloud app (Forge) Entirely inside Atlassian; no Macon Apps servers Configuration only. Snapshots and change history, never issue content. Admin display names, inside your Atlassian environment Atlassian Marketplace
Rule Vault Jira Cloud app Governed by its Data Processing Agreement & Written Security Policy Atlassian Marketplace
Release Sync & Notes Jira Cloud app Governed by its Data Processing Agreement & Written Security Policy Atlassian Marketplace
Shift Handover Log Microsoft Teams app A product of J.P. Johnson Law LLC; governed by its own privacy policy
Assurance Map Microsoft Teams app A product of J.P. Johnson Law LLC; governed by its own privacy policy

Checklist All HQ Trello Power-Up

Section last revised: August 1, 2026 Support: Checklist All HQ support page

The short version: your Trello boards, cards, and checklists are read by your own browser, directly from Trello, using a token you grant — and are never sent to, stored on, or seen by our servers. The only thing we store is your Trello workspace ID and a Stripe subscription reference, so we know which workspace has a paid plan.

What the Power-Up Accesses

When you authorize Checklist All HQ inside Trello, Trello issues a token that lets the Power-Up act as you, limited to boards you can already access. Using that token, the Power-Up reads board names, lists, cards, checklists and checklist items (including their due dates and assignees), and board member names — and writes only one thing: checklist item completion state, when you check an item off in the console.

Where Your Data Goes (and Doesn't)

  • Card and checklist data: fetched by your browser directly from Trello's API, displayed in the console, and discarded when you close it. It is never transmitted to Macon Apps servers, never stored by us, and never shared with anyone.
  • Your authorization token: stored by Trello's official Power-Up client in your own browser's local storage. We cannot read it from our servers, and it never leaves your browser except in direct calls to Trello's API.
  • Settings: your board selection and an authorized-yes/no flag are kept in Trello's own Power-Up storage (managed by Atlassian, removed when the Power-Up is removed).
  • CSV exports: generated in your browser and saved to your own device. Nothing is uploaded.

What We Do Store

To operate paid subscriptions, our license service (hosted on Cloudflare) stores one small record per subscribed workspace:

  • the Trello workspace (organization) ID — an identifier for the workspace, not any person;
  • a Stripe customer ID and subscription ID — opaque references into our payment processor;
  • a timestamp.

That's the whole record. It contains no names, no emails, no board or card content. When a subscription is canceled and its paid period ends, the record is deleted automatically.

Payments

Checkout and billing are handled entirely by Stripe. Your card number and billing details go to Stripe, not to us; we never see or store them. You can view, update, or cancel your subscription anytime through the billing portal.

Cookies, Analytics & Tracking

Checklist All HQ sets no cookies of its own, embeds no analytics, and does no ad tracking. The only network calls the Power-Up makes are to Trello's API, to our license check (which receives your workspace ID and nothing else), and — during checkout only — to Stripe.

Data Retention & Deletion

  • Card data: never retained by us in the first place.
  • Token & settings: use Trello's "Remove personal settings" on the Power-Up, or remove the Power-Up from your board, to clear them. You can also revoke the token anytime from your Trello account's application settings.
  • License record: deleted automatically when your subscription ends. To request earlier deletion, email [email protected] and we will remove it within 30 days (this also ends the paid plan for that workspace).
  • Stripe records: retained by Stripe per its own policy and legal requirements (e.g., tax and accounting).

Third Parties We Rely On

Your Rights

Because we hold no personal data about you beyond what's described above, most privacy-law requests (access, correction, portability, deletion) are satisfied either by Trello/Atlassian (for your board content and account) or by a quick email to us for the license record. See Part I, Section 12.

↑ Back to index

Audit Log & Board History Trello Power-Up

Section last revised: August 6, 2026 Support: Audit Log support page

The short version: this product's job is to remember what happened on your board, so — unlike most Power-Ups — it does store data on our servers: action metadata (what kind of change, when), the titles of cards and lists, and the acting member's Trello id. It never stores anyone's name, email, or avatar; never card descriptions, comment text, or attachments; and names you see in the timeline are resolved in your own browser, from the board itself. Recording is switched on by a board or workspace admin, everything we hold can be exported and deleted from settings, and every deletion — including our own automatic pruning — leaves a visible record.

What the Power-Up Accesses

When an admin connects a board, Trello asks them to authorize the Power-Up. The token Trello issues is read-only, expires after 30 days, and is used transiently — to register the board's activity listener and to verify admin permissions — then discarded. It is never stored on our servers. After that, board activity reaches us through Trello's webhook system: Trello sends each action to our server as it happens, and our server keeps only the reduced record described below.

What We Store

For each recorded action on a connected board, our server stores:

  • the action type (e.g. "card created", "card deleted", "card moved");
  • the acting member's Trello member id — a pseudonymous identifier, never their name;
  • the card and list ids involved, and their titles (also checklist, check-item, and label titles where relevant);
  • the timestamp;
  • a restricted summary of which fields changed — old/new values for dates, positions, and flags; free text (descriptions, comments) is reduced to a character count.

Explicitly never stored:

  • card or board descriptions and comment text (lengths at most);
  • attachments — contents, URLs, and even filenames;
  • member display names, usernames, emails, or avatars. The names you see in the timeline are looked up by your own browser from the board you're viewing — they never reach our database.

Alongside the timeline we keep small operational records: which boards are connected and which admin switched recording on or off; a per-workspace billing record (Stripe customer and subscription references, plan — never card details); and permanent deletion records ("who deleted how much history, when" — never the deleted content itself).

Who Can See the Timeline

Every member of a connected board can read that board's whole timeline, including filtering it by person. That matches Trello's own activity feed and the product's purpose — a shared record the whole team can trust — but it does mean a searchable, per-person history of activity on that board. Because of that:

  • turning recording on requires a board or workspace admin, verified against Trello — not just anyone who can open the board;
  • who turned it on (and who turned it off) is shown to every board member in settings;
  • a workspace that doesn't want a colleague-filterable activity history should not enable this Power-Up.

How Long We Keep It

SituationRetention
Free plan Rolling 7-day window, enforced on our servers by a nightly job. The automatic pruning itself leaves a visible record.
Pro plan History kept for as long as the workspace is subscribed. A failed payment does not destroy history — paid history is protected for 30 days past any billing lapse, longer than Stripe's full retry cycle.
Recording stopped / Power-Up disconnected History kept 30 days, then automatically purged — with a deletion record naming the admin who stopped recording. Within those 30 days an admin can export, delete sooner, or re-connect to keep it.
Deletion records Kept permanently — they are the tamper-evidence that makes the log trustworthy. They contain counts, dates, and (until an erasure request) the acting admin's member id — never deleted content.
Billing records Retained while the Stripe relationship exists; Stripe is the system of record. Cancel via the billing portal to end it.

How Deletion Works

  • Delete a board's history (settings → admin only): offers a CSV export first, requires typing the board id to confirm, then permanently deletes the board's recorded events. A deletion record — who, when, how many events, covering which date range, and whether an export was taken — remains visible to every board member.
  • Erase everything for a workspace (settings → workspace admin): shows a summary of what we hold, then deletes all recorded events and board records for the workspace, and anonymises the workspace's existing deletion records.
  • Individual erasure (GDPR): we poll Trello's member-privacy compliance API at least every 14 days. When a member deletes their Atlassian account or revokes the Power-Up's access, every reference to their member id in our data — as actor, as target, as the admin on a record — is removed. The timeline rows remain (an audit log with holes is worse than useless) but no longer identify anyone.
  • "Remove personal settings" in Trello clears your own per-member state. It deliberately does not stop the board's recording — that is an admin action — because an audit log any single member could switch off would not be an audit log.
  • You can also email [email protected] with any erasure request and we will honor it within 30 days.

Payments

Checkout and billing are handled entirely by Stripe. Your card number and billing details go to Stripe, not to us; we never see or store them. A workspace admin can view invoices, switch between monthly and annual, update the payment method, or cancel anytime via settings → Manage billing.

Cookies, Analytics & Tracking

The Power-Up sets no cookies of its own, embeds no analytics, and does no ad tracking. Its pages talk only to Trello's API and to our own service — and, during checkout only, to Stripe.

Security

  • All traffic is encrypted in transit (TLS, with HSTS).
  • Every request to our service is authenticated with a Trello-signed token verified on our servers, pinned to this specific Power-Up and to the specific board being viewed.
  • Destructive and billing actions additionally verify board/workspace-admin status live against Trello, under the caller's own credential.
  • Authorization tokens are never stored; credentials never appear in URLs or logs.

Third Parties We Rely On

Your Rights

For your Trello account and board content, contact Atlassian. For the data this Power-Up holds: access and portability are served by the CSV export; deletion by the settings described above or by email. See Part I, Section 12.

↑ Back to index

Find and Replace + Banned Term Watch Trello Power-Up

Section last revised: August 13, 2026 Runs on: Cloudflare (Workers, D1, KV) Support: Find and Replace support page

What the Power-Up Accesses

The Power-Up works entirely through your own Trello authorization. When you authorize it (read and write), it reads card titles, card descriptions and checklist items on the boards you point it at, and — when you run a rewrite — edits those same fields under your own Trello permissions. It cannot change anything you could not change by hand, and a card you cannot edit is reported as refused rather than modified.

Board and workspace membership is read with Trello's member=false option, which returns member identifiers and roles only — names, usernames, email addresses, avatars and bios are never requested from the Trello API, so they never enter the service at all.

What We Store

Most of what the Power-Up touches is read, matched in memory, and discarded within the same request. It stores a small, deliberate set of data outside Trello, because preview and undo are impossible without it:

  • Match snippets — roughly 30 characters of card text on either side of each match, so the results list and the before/after preview can show you what you are about to change. Kept 7 days.
  • The undo journal — the complete before and after text of every field a rewrite changed, including full card descriptions. This exists so undo can restore a field exactly, and so a field a colleague edited afterwards is detected and left alone rather than overwritten. Kept 7 days, after which undo for that job is no longer offered.
  • Your search and replacement strings, including saved and watched terms — user-authored text, kept with the records they belong to (see the schedule below).
  • Identifiers and bookkeeping — card, board and checklist ids, card short links, board titles, match counts and job statuses, which make up the change logs and progress reporting.
  • Trello member ids on the rows recording who ran a search or rewrite or saved a term. These are pseudonymous but re-identifiable through Trello, so we treat them as personal data (see Your Rights below).
  • Billing records — your workspace's Stripe customer id, plan and subscription status.

What we never store: member names, usernames, email addresses, avatars or bios; Trello API tokens or any other credential (your token is used within each request and never written to storage or logs); card comments, attachments, custom fields or labels; and no card content beyond the two items above.

Who Can See What

Search results and their snippets are visible to the member who ran the search and, for a single-board search, to members of that board. Rewrite change logs are scoped the same way. A workspace admin can see the workspace's rewrite history. The banned-term watch list and its alerts are visible to subscribed members of the workspace, but an alert carries references only — which card, which field, which term — and the card itself is fetched live under the viewer's own Trello permissions, so a member who cannot open a board sees nothing beyond an identifier.

How Long We Keep It

DataRetention
Card text — match snippets7 days
Card text — undo journal (complete before/after values)7 days
Search worklists, board titles, match counts30 days
Rewrite plans never executed7 days
Rewrite plans executedthe card list inside them is deleted the moment the job starts; the remaining record is deleted with its job
Job change logs (identifiers, counts, statuses — no card text)365 days
Watch alerts90 days once dismissed; 365 days if never dismissed
Webhook idempotency records30 days
Saved terms and watched boardswhile the workspace is subscribed, then 90 days after the subscription ends
Billing records (Stripe customer id, plan, status)retained — Stripe is the system of record, and deleting the local copy would misreport what the workspace is entitled to

These periods are enforced automatically by a nightly job. Trello does not notify Power-Ups when they are removed from a board, so removal is not an event we can act on — but nothing further is written after removal, and the schedule above applies from that point: all card content is gone within 7 days, and everything except the billing record within 365 days.

How Deletion Works

  1. Self-service, immediate: a Trello workspace admin opens the Power-Up and uses the data deletion action, which erases every record we hold for that workspace. The request must echo the workspace id as confirmation, so a mis-click cannot destroy data. Billing records are retained as described above; cancel the subscription in the billing portal to end that relationship.
  2. Automatic, per member: we poll Trello's member privacy endpoint nightly and honour account-deleted, account-updated, token-revoked and token-expired events by removing that member's identifier from every record that holds it.
  3. Automatic, time-based: the retention schedule above.
  4. On request: email [email protected] and we will run the workspace purge for you.

Payments

Subscriptions are processed by Stripe. Card details are entered on Stripe's hosted checkout page and managed in Stripe's customer portal — they never reach us and we never see them. We store only the Stripe customer id, plan and subscription status needed to know what your workspace is entitled to.

Cookies, Analytics & Tracking

The Power-Up sets no cookies and uses no analytics, advertising or tracking of any kind. There is no analytics provider, no advertising provider, and no sub-processor beyond the two named below. No customer data is sold, shared, or used for training.

Security

  • All traffic is HTTPS with HSTS (one-year max-age, including subdomains). Data at rest is encrypted by Cloudflare D1 and KV.
  • Every request is authenticated with the Trello-signed token for this specific Power-Up, verified server-side against Trello's public keys and pinned to this Power-Up's own id — a token issued for a different Power-Up is rejected.
  • Your Trello REST token is additionally checked to belong to you, used within the request, and never stored or logged.
  • Billing, data deletion and workspace-wide rewrites additionally require Trello workspace admin, verified live against Trello.
  • The Power-Up iframe is served with a Content-Security-Policy containing no unsafe-inline, unsafe-eval or unsafe-hashes, and can only be framed by trello.com.

Third Parties We Rely On

No other sub-processor is used.

Your Rights

The only personal data we hold is your Trello member id on records of actions you took. You can have it removed at any time: through a Trello account deletion or token revocation (honoured automatically, nightly), through your workspace admin running the data deletion action, or by emailing us. See Part I, Section 12.

↑ Back to index

Board Merge & Split Trello Power-Up

Section last revised: August 26, 2026 Runs on: Cloudflare (Workers, D1, KV) Support: Board Merge & Split support page

What the Power-Up Accesses

The Power-Up works entirely through your own Trello authorization. When you authorize it, it reads the structure of the boards you point it at — lists, labels, and card counts — to build a merge or split preview, and when you execute one, it moves lists and cards under your own Trello permissions. It can never change anything you could not change by hand, and an operation Trello refuses under your permissions is recorded as refused rather than performed.

Board and workspace membership is read with Trello's member=false option, which returns member identifiers and roles only — names, usernames, email addresses, avatars and bios are never requested from the Trello API, so they never enter the service at all.

Card content is never requested, so it cannot be stored. The only card-shaped data the service ever handles is card ids — the minimum needed to count cards for the preview and to record which cards a merge moved so the merge can be undone. No titles, descriptions, comments, checklists, attachments, custom-field values or card members, ever.

What We Store

Most of what the Power-Up reads is used to answer the request and discarded. It stores a small, deliberate set of data outside Trello, because a previewed, resumable, undoable merge is impossible without it:

  • Merge/split plans — board ids and names, the ordered operations (list ids, list names, label names and colours, positions, card counts), so execution runs exactly what you previewed.
  • Job receipts — one row per operation performed, with its outcome, forming the audit history and CSV export.
  • The undo record — the inverse of every destructive operation, including the card ids a drained list held before its cards were merged into another list. This is what makes a merge reversible; without the id set the cards are indistinguishable afterwards.
  • Trello member ids on the rows recording who created each plan and job. These are pseudonymous but re-identifiable through Trello, so we treat them as personal data (see Your Rights below).
  • Billing records — your workspace's Stripe customer id, plan and subscription status.

What we never store: card content of any kind; member names, usernames, email addresses, avatars or bios; Trello API tokens or any other credential (your token is used within each request and never written to storage or logs).

Who Can See What

You see the merges and splits you ran. A Trello workspace admin — verified live against Trello, never assumed — can see the workspace's job history and receipts. Receipts carry board and list names and operation outcomes; they never carry card content. Running, executing or undoing a merge requires admin rights on both boards involved, verified against Trello at the time of the request.

How Long We Keep It

DataRetention
Plans never executed7 days (and executable for only 24 hours)
Executed plans, job receipts, and undo records (card ids included)365 days — a year of change-management history, then pruned
Webhook idempotency records30 days
Short-lived caches (entitlement, membership decisions)5 minutes
Billing records (Stripe customer id, plan, status)retained — Stripe is the system of record, and deleting the local copy would misreport what the workspace is entitled to

These periods are enforced automatically by a nightly job. Trello does not notify Power-Ups when they are removed from a board, so removal is not an event we can act on — but nothing further is written after removal, and the schedule above applies from that point: everything except the billing record is gone within 365 days of its creation.

How Deletion Works

  1. Self-service, immediate: a Trello workspace admin opens the Power-Up and uses the data deletion action, which erases every plan, job, receipt and undo record we hold for that workspace. The request must echo the workspace id as confirmation, so a mis-click cannot destroy data. Billing records are retained as described above; cancel the subscription in the billing portal to end that relationship.
  2. Automatic, per member: we poll Trello's member privacy endpoint nightly and honour account-deleted, account-updated, token-revoked and token-expired events by removing that member's identifier from every record that holds it.
  3. Automatic, time-based: the retention schedule above.
  4. On request: email [email protected] and we will run the workspace purge for you.

Payments

Subscriptions are processed by Stripe. Card details are entered on Stripe's hosted checkout page and managed in Stripe's customer portal — they never reach us and we never see them. We store only the Stripe customer id, plan and subscription status needed to know what your workspace is entitled to. Undoing a merge is deliberately never gated on an active subscription: a lapsed plan can always put a board back the way it was.

Cookies, Analytics & Tracking

The Power-Up sets no cookies and uses no analytics, advertising or tracking of any kind. There is no analytics provider, no advertising provider, and no sub-processor beyond the two named below. No customer data is sold, shared, or used for training.

Security

  • All traffic is HTTPS with HSTS (one-year max-age, including subdomains). Data at rest is encrypted by Cloudflare D1 and KV.
  • Every request is authenticated with the Trello-signed token for this specific Power-Up, verified server-side against Trello's public keys and pinned to this Power-Up's own id — a token issued for a different Power-Up is rejected.
  • Your Trello REST token is additionally checked to belong to you, used within the request, and never stored or logged.
  • Merging, splitting and undoing require admin rights on both boards involved, verified live against Trello; billing and data deletion require workspace admin.
  • Destructive actions sit behind a typed confirmation (the source board's name), enforced on the server — and closing a source board only ever happens because someone explicitly chose it.
  • The Power-Up iframe is served with a Content-Security-Policy containing no unsafe-inline, unsafe-eval or unsafe-hashes, and can only be framed by trello.com.
  • CSV exports neutralise spreadsheet formula injection, so a hostile list name cannot execute when an admin opens the audit export.

Third Parties We Rely On

No other sub-processor is used.

Your Rights

The only personal data we hold is your Trello member id on records of actions you took. You can have it removed at any time: through a Trello account deletion or token revocation (honoured automatically, nightly), through your workspace admin running the data deletion action, or by emailing us. See Part I, Section 12.

↑ Back to index

ConfigMonitor Jira Cloud app

Section last revised: August 3, 2026 Runs on: Atlassian Forge, inside your Atlassian cloud environment Support: ConfigMonitor support page

The short version: ConfigMonitor runs entirely on Atlassian's Forge platform, inside your Atlassian cloud environment. Everything it reads and everything it stores stays with Atlassian — the app makes no network calls to Macon Apps or to any other external service. We operate no servers for ConfigMonitor, so there is no place your data could reach us. The app never asks for, collects, or stores an API token, password, or any other credential.

What ConfigMonitor Accesses

ConfigMonitor reads your Jira site's configuration: workflows, custom field definitions, field configurations, screens and screen schemes, permission schemes, notification schemes, and issue type schemes. To show who made a change, it also reads Jira's built-in audit log records. All reads use the app permissions a site admin approves at install — Atlassian's Forge platform enforces that boundary.

ConfigMonitor does not read the content of your issues, comments, attachments, or user directories, and it writes nothing to your Jira configuration — it is a read-only observer.

What ConfigMonitor Stores, and Where

To detect and display changes, ConfigMonitor keeps the following in Forge storage — Atlassian-hosted storage that lives inside Atlassian's cloud, alongside your Jira data:

  • Configuration snapshots: the current shape of each tracked configuration object, used to compute the next diff.
  • Change events: the history you see in the timeline — timestamps, object names, before/after diffs, and plain-language summaries.
  • Actor names: where Jira's audit log identifies the admin who made a change, that display name is stored on the change event. This is the only personal data ConfigMonitor holds, and it never leaves Atlassian's platform.

Because storage is provided by Atlassian's Forge platform, it inherits Atlassian's hosting, security, and data-residency arrangements for your site. Macon Apps has no independent copy and no way to access your site's data outside the app itself.

No API Tokens, Ever

ConfigMonitor authenticates through Forge's built-in app identity, granted once at install by your site admin. It has no setup screen requesting an email-plus-token, no credential field of any kind, and it does not collect, transmit, or store Atlassian user API tokens — in line with Atlassian Marketplace security requirements. If any screen ever appears to ask you for a credential, it is not ours: stop and contact us.

Payments

ConfigMonitor is sold through the Atlassian Marketplace. Billing, invoicing, and payment details are handled entirely by Atlassian on your existing Atlassian bill — Macon Apps never sees your payment information. Atlassian shares standard sales reporting with us (site-level license status), not personal payment data.

Cookies, Analytics & Tracking

ConfigMonitor sets no cookies of its own, embeds no analytics, and does no tracking of any kind. The app's user interface is served by Atlassian inside Jira, and the app makes no network egress to any non-Atlassian destination.

Data Retention & Deletion

  • While installed: snapshots and change history are retained so the timeline and compliance exports keep working.
  • On uninstall: the app's Forge storage is removed under Atlassian's platform rules for uninstalled apps. Nothing persists with Macon Apps, because nothing was ever sent to Macon Apps.
  • Earlier deletion: to clear history while keeping the app installed, contact us at [email protected] and we'll walk you through it or ship it as a supported action.
  • CSV exports are generated on demand and saved to your own device; you control those copies.

Third Parties We Rely On

  • Atlassian — hosts Jira, the Forge platform the app runs on, the app's storage, and Marketplace billing (Atlassian privacy policy).

That's the whole list. ConfigMonitor uses no other processor, host, or service.

Your Rights

The only personal data ConfigMonitor holds is admin display names on change events, stored inside your own Atlassian environment and visible only to your site's admins. Requests about your Atlassian account and its data are handled by Atlassian; for anything about ConfigMonitor's stored history, see Part I, Section 12.

↑ Back to index

Products Governed by Separate Documents

The following products are listed here so this index is a complete map of everything we publish, but their data practices are set out in their own documents rather than in this policy:

↑ Back to index