Card Timeline+ Privacy Policy

Last updated: July 16, 2026

Card Timeline+ is a Trello Power-Up operated by the independent developer behind nikaj.dev. This policy explains what Trello data we collect and store, why we process it, how long we keep it, and how users can request export, correction, or deletion.

Contact

Privacy, support, export, and deletion requests: support@nikaj.dev.

What Card Timeline+ Does

Card Timeline+ shows Trello card movement history, time in list, optional card badges, stuck-stage warnings, and short-lived export handoffs to Board Export+. It tracks list movement events after installation and does not track comments or card descriptions as product features.

Personal Data We Store

Card Timeline+ stores Trello personal data. We do not claim otherwise.

Raw Payload Minimization

Raw webhook payload storage is disabled by default. Sanitized debugging data removes tokens, secrets, authorization values, cookies, passwords, and comment text not required for timeline behavior. If raw storage is enabled for incident debugging, raw webhook and timeline payload retention defaults to 7 days.

Compliance Events

Card Timeline+ polls Trello's Compliance Polling API daily for account deletion, account update, token revocation, and token expiration events.

Historical movement facts such as card moved, source list, destination list, and occurrence time are preserved where possible. Actor identity is replaced with "Deleted Trello member" when required.

Legal Bases

We process data needed to provide Card Timeline+ because it is necessary to provide the service requested by the user or workspace under Article 6(1)(b) GDPR. We process limited security, abuse-prevention, reliability, and compliance records under Article 6(1)(f), based on our legitimate interests in operating and protecting the service and respecting Trello privacy events.

A Trello authorization token and the relevant board identifiers are necessary for authenticated features. If they are not provided or authorization is revoked, those features will not work and stored personal data will be deleted or anonymized according to this policy.

Retention

Export And Deletion Requests

Users can request export or deletion through the Privacy & data links in Power-Up Settings or by emailing support@nikaj.dev. API-backed requests require a Trello token matching the requesting member and board/workspace access where relevant.

Your Data Protection Rights

Subject to applicable law, you may request access, correction, deletion, restriction, or portability of your personal data, and may object to processing based on legitimate interests. You may lodge a complaint with the data-protection supervisory authority responsible for your habitual residence, place of work, or the alleged infringement.

We normally respond without undue delay and within one month after verifying the request. Card Timeline+ does not use personal data for automated decision-making or profiling that produces legal or similarly significant effects.

Sharing

We use Atlassian/Trello, hosting/VPS infrastructure, PostgreSQL storage, and Board Export+ only as needed to provide the service. When enabled, PostHog Cloud EU may receive pseudonymous product analytics events that do not include Trello content, object IDs, names, tokens, or raw error messages. We do not sell Trello data or use it for advertising.

Product Analytics

When enabled, Card Timeline+ may send explicit product analytics events and session replay data to PostHog Cloud EU using a bundled SDK. Autocapture, heatmaps, and automatic exception or console capture are disabled. Users can opt out from Power-Up Settings. Operators can disable analytics and replay with environment kill switches.

For erasure requests, the operator can compute the pseudonymous PostHog distinct ID server-side and request deletion through PostHog after a separate verification step.

Security

We encrypt Trello tokens at rest, serve production traffic over HTTPS, verify Trello webhook signatures, redact secrets from logs, avoid logging full webhook/compliance payloads, minimize raw payload storage, and use scheduled retention cleanup.

We document and assess personal-data breaches and make regulatory or individual notifications where applicable.

International Transfers

Where GDPR Chapter V applies, transfers outside the EEA are made only using an applicable adequacy decision, Standard Contractual Clauses, or another lawful safeguard. Contact support@nikaj.dev for information about the safeguard applicable to a transfer.

Changes

We may update this policy as the product or legal requirements change.