Skip to content

Privacy Policy for monday.com Apps

1. Introduction

This policy explains what data Yamuno apps for monday.com can access, what they do with it, and what we store. It covers Yamuno apps installed from the monday.com apps marketplace.

Our Atlassian apps and the rest of yamuno.com are covered by our main Privacy Policy. Your use of the apps is also governed by our Terms of Service for monday.com Apps.

The short version: our monday.com apps run inside monday.com, read only what you ask them to, and don't send your content to servers of ours.


2. How Our monday.com Apps Work

2.1 Where the apps run

Our monday.com apps are hosted by monday.com and run in your browser, inside monday.com. When an app needs your data, it asks the monday.com API directly, using your own monday.com session.

This means:

  • An app can only see what you can see in monday.com. It never has more access than your own account.
  • Your boards and docs are not copied to a Yamuno server. We don't operate a server that receives them.
  • Files the app creates, such as an export, are built in your browser and saved straight to your computer.

2.2 Permissions

When you install an app, monday.com shows you the permissions (scopes) it asks for, and you approve them. We ask only for the permissions an app needs to work, and our apps only read your data unless a feature clearly says it writes something back.


3. What Each App Accesses

3.1 Markdown Exporter for monday.com

What it reads The workspaces, folders and workdocs you choose to export, the names of people, docs and boards mentioned in those docs, and images embedded in them
Permissions Read workspaces, read docs, read boards, read assets, read users
What it stores Nothing. The app keeps no data between sessions and writes nothing to your monday.com account.
Where data goes From the monday.com API to your browser, then into the ZIP file you download. To include an image in the export, your browser downloads it from wherever it is hosted: monday.com's own file storage, or the website it was embedded from.

4. Data We Receive From monday.com

Installing, billing and account management for our apps are handled by monday.com, and governed by the monday.com Privacy Policy.

As an app developer, monday.com may share information with us about installations of our apps, such as the account that installed an app, its plan, and install and uninstall events. We use this only to:

  • Provide and support the app
  • Understand how the apps are used, so we can improve them
  • Contact account administrators about important changes to an app

When an app is used, it also tells monday.com that it has been used (a standard monday.com signal for apps). It contains no content from your boards or docs.


5. Sub-Processors

Sub-Processor Purpose Location
monday.com App hosting, installation, billing and authentication Per your monday.com account's data region

We'll update this list when sub-processors are added or removed.


6. Support

When you contact our support team, we see only what you choose to send us, such as your email address and a description of the problem. If you share a copy of a doc to help us reproduce an issue, we use it only for that support request and delete it once the request is closed.


7. Legal Basis for Processing (GDPR)

Where the GDPR applies, we process personal data on the basis of:

  • Contractual necessity: to provide the apps you install
  • Legitimate interests: to support, secure and improve the apps

8. Your Rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, and to receive a copy of it. California residents have the rights set out in the CCPA; we do not sell personal information.

To exercise any of these rights, email [email protected].


9. Data Retention

  • App data: our monday.com apps don't store your content, so there is nothing to delete when you uninstall.
  • Installation and billing information from monday.com is kept for as long as the app is installed, and deleted within 10 days of uninstalling, unless we must keep it longer by law.

10. Security

  • Apps request only the permissions they need.
  • All traffic between your browser, monday.com and image hosts uses HTTPS.
  • Code changes are reviewed before release, and dependencies are scanned for known vulnerabilities.

To report a security issue, email [email protected]. We aim to acknowledge reports within 48 hours.


11. Updates to This Policy

We'll update this page when an app is released or changes what it accesses, and change the date below. For material changes, we'll notify affected account administrators by email where possible.

Last Updated: September 27, 2026


Company Information

Yamuno Software services are operated by:

Yamuno
Wyoming, United States

For legal and privacy inquiries, please contact: [email protected]