TrueCrane

Security at TrueCrane

Stale & SLA reads your boards to measure time. Here is where that data goes, who can reach it and how it is removed. The privacy policy is the binding text; this page explains it.

In short

  • The app runs only on monday.com's own app hosting platform (monday code), in its EU region. We run no servers or databases of our own.
  • Your data is sent only to monday.com. The app uses no other third-party service, no analytics and no tracking.
  • When you uninstall, the app deletes your account's data once monday.com confirms the app has lost access.

Where your data lives

  • Hosting: monday code, monday.com's platform for apps, in its EU data region, for every account wherever it is. monday.com is our only sub-processor for the app.
  • Separation: each account's settings and timing summaries sit in monday code storage kept apart per account.
  • Access tokens: in monday code Secure Storage, separate for this app. They are never written to logs and never sent to the browser.
  • What is kept: board settings, per-item timing summaries (including item and group names and status labels), automation subscriptions and run records. The privacy policy lists every field and why it is kept.

Who can reach it

  • Least privilege: the app asks for seven monday.com permissions, each for a stated reason: me:read, account:read, boards:read, boards:write (only to create and fill its own numbers columns), updates:write and notifications:write (escalations and the digest), and users:read (to check who may see a board).
  • Board by board: every read checks that the person can see the board in monday.com. Viewers cannot open the app's views; guests can open them read-only, and only on boards they were invited to.
  • Admins decide: only an account admin can connect the app or change a board's settings. Before connecting, the admin sees what the app does with the account's data and must agree to it.
  • Every request is verified: views with monday.com's session token, workflow blocks with the app's signing secret, and install and uninstall events with the app's client secret.

How the app is built and run

  • All traffic is HTTPS, with HSTS. Pages send a strict Content Security Policy: scripts only from the app itself, no inline scripts, and only monday.com may frame the views.
  • Every input is validated, and text posted to items is HTML-escaped. The app's endpoints are rate-limited.
  • Each release is checked by automated tests and by monday code's security scan before it goes live. Changes that affect you are listed on the app's notices page.
  • We can pause all of the app's writes at once (column updates, alerts, escalations, digests) while we fix a fault; your settings are kept.

Deletion

When the app is uninstalled, monday.com tells the app. Once monday.com confirms the app has lost access to the account, the app deletes everything it stored for that account and its access token. If that confirmation cannot be had at the time, or the deletion does not finish, we complete it by hand within 30 days. You can ask for earlier deletion by email.

Reporting a security or privacy problem

Email support@truecrane.com with URGENT in the subject. We reply the same support day if your email arrives by 15:00 Israel time, otherwise on the next support day, and we notify your account's admins of any security incident that affects your account.

What we do not claim

TrueCrane is an independent developer. We do not hold SOC 2 or ISO 27001 certifications of our own; the app runs on monday.com's infrastructure and inherits its hosting security. We will say so here when that changes.