Privacy policy
WhereUsed is an app for monday.com published by Dripwork, the trading name of Aqib Ilyas, a sole trader established in Finland (Business ID 3519918-7) ("WhereUsed", "we", "us"). This policy explains what WhereUsed reads, what it stores, for how long, and who else is involved.
In short: WhereUsed reads the structure of your boards (board and column settings), never your items or their values. It never changes anything in your account, never uses cookies, analytics or advertising, and never sells or shares your data. Uninstalling deletes everything it stored for your account.
What WhereUsed reads
WhereUsed asks monday.com for one permission, read boards, and uses it only to read, for each board the connected person can open:
- the board's id, name, kind (such as public or private), state (active or archived), workspace id, type and link;
- each column's id, title, type and settings. For Connect Boards columns the settings say which boards are linked; for Mirror columns, which column is mirrored; for Formula columns, the formula text.
WhereUsed never reads items, item names, column values, updates, files, docs, or people's names, email addresses or photos. It never creates, changes or deletes anything in monday.com.
Board and column names are written by your team and could contain personal information, for example a board named after a person. WhereUsed treats all of them as your confidential content.
What WhereUsed stores, and for how long
| Data | Why | How long |
|---|---|---|
| The monday.com access and refresh tokens issued when a person connects WhereUsed | To scan with that person's own access: when they open WhereUsed, and once a day while the account is subscribed | Until the app is uninstalled; replaced each time monday.com renews them |
| Scan results: the board and column information above, with the monday.com account id, user id and scan time | To show reports and detect deleted or renamed columns | 30 days, at most 40 scans per person. If the subscription ends, no new scans are made, and the stored ones are kept until the app is uninstalled or you ask us to delete them |
| A visit record: account id, user id, the last day the person opened WhereUsed, and their plan | To run daily scans only for subscribed users active in the last 30 days | One record per person, deleted after 30 days without a visit |
| A "last reviewed" marker: which scan a person last acknowledged | To show changes since their last visit | One marker per person, replaced when they acknowledge again |
| Whether the account is subscribed, and the time of the latest billing event monday.com sent | To stop daily scans when a subscription ends | One record per account, replaced by newer events |
| Single-use codes for connecting WhereUsed and for export downloads. They hold random values and the time they were issued, never account information. | To complete a connection securely, and to make each download link work once | Export links stop working after 60 seconds, and connection codes after 10 minutes or once used |
Everything in the first five rows is deleted when WhereUsed is uninstalled (see below).
Where it is stored
WhereUsed runs on monday code, monday.com's hosting platform for apps. Access tokens are kept in monday code's secure storage; everything else is kept in monday code's storage for the app. Data is currently stored in the European Union. All connections use HTTPS.
Billing information
monday.com handles subscriptions and payments; WhereUsed never sees payment details. monday.com tells WhereUsed when an account's subscription starts, changes or ends. WhereUsed keeps only the plan and the event time (see the table above). The names and email addresses those messages can contain are neither stored nor logged.
Logs
WhereUsed's own logs record monday.com account and user ids, which request was made, its outcome, and the type of any error. They never record tokens, board or column names, formula text or email addresses. monday code, the hosting platform, also keeps its own request logs under monday.com's retention; for the board view, a request's address includes the short-lived session token monday.com provides.
Cookies and tracking
The WhereUsed app uses no cookies, analytics, advertising or third-party scripts, and its fonts are bundled with it. This website also sets no cookies, runs no analytics and no scripts, and serves its fonts from this domain. Its "Add to monday.com" button image is loaded from monday.com's image service, which receives your IP address like any image request.
Who else is involved
We do not sell, rent or share your data. These services are involved in running WhereUsed:
- monday.com: the platform WhereUsed reads from (api.monday.com and auth.monday.com), its hosting (monday code), and billing.
- Cloudflare: delivers this website, and sits in front of monday code's hosting. It processes visitors' IP addresses to deliver pages and protect against abuse.
- Google: WhereUsed downloads Google's public signing keys to confirm that its daily scan was really started by monday.com's scheduler. No customer data is sent to Google.
We may disclose information if the law requires it.
Uninstalling and deleting data
When WhereUsed is uninstalled, monday.com notifies it, and WhereUsed deletes the account's tokens, scan results, visit records, markers and plan record straight away. To ask for deletion without uninstalling, for example for one person who left your team, email support@whereused.app; we complete requests within 10 days.
Security
Every request from the app carries monday.com's signed session token, which WhereUsed verifies before doing anything; the account and user always come from that verified token. Tokens are never sent to the browser or written to logs. WhereUsed requests the least access it needs: one read-only permission.
Your rights
For information in your monday.com account, your organisation decides how it is used, and WhereUsed processes it on your organisation's behalf. Depending on where you live, you may have the right to access, correct, delete or export your information, or to object to its use. Email us to exercise these rights; you can also complain to your local data protection authority. In Finland, where WhereUsed is published, that is the Office of the Data Protection Ombudsman.
Children
WhereUsed is a business tool and is not directed at children under 16.
Changes to this policy
If we change this policy, we will update the effective date above and describe significant changes on this page.
Contact
Dripwork (Aqib Ilyas, sole trader), Business ID 3519918-7, Ylioppilaantie 6, 90130 Oulu, Finland
support@whereused.app