Card Timeline+ Privacy Policy
Card Timeline+ is a Trello Power-Up operated by the independent developer behind nikaj.dev. This policy explains what Trello data we collect and store, why we process it, how long we keep it, and how users can request export, correction, or deletion.
Contact
Privacy, support, export, and deletion requests: support@nikaj.dev.
What Card Timeline+ Does
Card Timeline+ shows Trello card movement history, time in list, optional card badges, stuck-stage warnings, and short-lived export handoffs to Board Export+. It tracks list movement events after installation and does not track comments or card descriptions as product features.
Personal Data We Store
Card Timeline+ stores Trello personal data. We do not claim otherwise.
- Trello member ID, actor display name, and profile metadata needed for authorization or display.
- Board, workspace, card, and list identifiers.
- Board names, card names, card URLs, current list names, source list names, and destination list names where Trello provides them.
- Timeline movement events: action ID, event type, source list, destination list, occurrence time, card reference, and actor reference.
- Encrypted Trello API tokens and token metadata while needed for authorized operations.
- Webhook delivery metadata and short-lived export handoff metadata.
- Compliance Polling API event receipts and non-personal audit entries.
Raw Payload Minimization
Raw webhook payload storage is disabled by default. Sanitized debugging data removes tokens, secrets, authorization values, cookies, passwords, and comment text not required for timeline behavior. If raw storage is enabled for incident debugging, raw webhook and timeline payload retention defaults to 7 days.
Compliance Events
Card Timeline+ polls Trello's Compliance Polling API daily for account deletion, account update, token revocation, and token expiration events.
- For account deletion and token revocation, we remove stored account/profile/credential data, delete user-owned temporary export handoffs, scrub raw payloads, and anonymize actor identity in shared timeline history.
- For account updates, we refresh only needed profile fields or anonymize if the profile is no longer accessible.
- For token expiration, we request reauthorization and remove/anonymize personal data if authorization is not restored within the Card Timeline+ seven-day operational grace period.
Historical movement facts such as card moved, source list, destination list, and occurrence time are preserved where possible. Actor identity is replaced with "Deleted Trello member" when required.
Legal Bases
We process data needed to provide Card Timeline+ because it is necessary to provide the service requested by the user or workspace under Article 6(1)(b) GDPR. We process limited security, abuse-prevention, reliability, and compliance records under Article 6(1)(f), based on our legitimate interests in operating and protecting the service and respecting Trello privacy events.
A Trello authorization token and the relevant board identifiers are necessary for authenticated features. If they are not provided or authorization is revoked, those features will not work and stored personal data will be deleted or anonymized according to this policy.
Retention
- Encrypted Trello tokens are removed when revoked, expired beyond grace, deleted, or no longer required.
- Timeline movement events are retained while the board installation remains active. Normal board uninstall deletes board-scoped stored data.
- Webhook delivery records default to 30-day retention after payloads are cleared.
- Export handoffs are short-lived and expired records are deleted by retention cleanup.
Export And Deletion Requests
Users can request export or deletion through the Privacy & data links in Power-Up Settings or by emailing support@nikaj.dev. API-backed requests require a Trello token matching the requesting member and board/workspace access where relevant.
Your Data Protection Rights
Subject to applicable law, you may request access, correction, deletion, restriction, or portability of your personal data, and may object to processing based on legitimate interests. You may lodge a complaint with the data-protection supervisory authority responsible for your habitual residence, place of work, or the alleged infringement.
We normally respond without undue delay and within one month after verifying the request. Card Timeline+ does not use personal data for automated decision-making or profiling that produces legal or similarly significant effects.
Sharing
We use Atlassian/Trello, hosting/VPS infrastructure, PostgreSQL storage, and Board Export+ only as needed to provide the service. When enabled, PostHog Cloud EU may receive pseudonymous product analytics events that do not include Trello content, object IDs, names, tokens, or raw error messages. We do not sell Trello data or use it for advertising.
Product Analytics
When enabled, Card Timeline+ may send explicit product analytics events and session replay data to PostHog Cloud EU using a bundled SDK. Autocapture, heatmaps, and automatic exception or console capture are disabled. Users can opt out from Power-Up Settings. Operators can disable analytics and replay with environment kill switches.
For erasure requests, the operator can compute the pseudonymous PostHog distinct ID server-side and request deletion through PostHog after a separate verification step.
Security
We encrypt Trello tokens at rest, serve production traffic over HTTPS, verify Trello webhook signatures, redact secrets from logs, avoid logging full webhook/compliance payloads, minimize raw payload storage, and use scheduled retention cleanup.
We document and assess personal-data breaches and make regulatory or individual notifications where applicable.
International Transfers
Where GDPR Chapter V applies, transfers outside the EEA are made only using an applicable adequacy decision, Standard Contractual Clauses, or another lawful safeguard. Contact support@nikaj.dev for information about the safeguard applicable to a transfer.
Changes
We may update this policy as the product or legal requirements change.