GroupMaster Privacy Policy
Last updated: 27 August 2026
GroupMaster ("the App") is published by mutherboard.com ("we", "us", or "our"). This policy describes what information the App processes when you use it inside monday.com, what we store, and your choices. It is the same policy presented for acceptance inside the App on first use.
1. What the App accesses
The App reads and writes your monday.com board data (groups, items, updates or comments, and column values) solely to perform the actions you trigger: duplicating, copying, moving, archiving or renaming groups, bulk-updating columns, creating subitems, and running the automation rules you build. All requests go through monday.com's own API using credentials monday.com provides for your session or that you grant via OAuth.
2. What we store
- Board content: none. Your items, comments, and column values are never stored on our servers; they pass through monday.com's API only for the duration of an action.
- OAuth tokens: if you connect the App, the access token is stored encrypted in monday.com's secure storage (backed by HashiCorp Vault), scoped to your monday.com account and user.
- Preferences: a flag recording that you have accepted the App's terms is stored in monday.com's app storage for your account.
- Automation rules: rules you create are stored as their definition only (board id, trigger type, column id, status label, action type and parameters).
- Logs: the App's server records operational events (action names, board and group identifiers, timestamps) within monday.com's hosting platform to support troubleshooting. Logs do not include your board content.
3. What we don't do
- No analytics, tracking, or advertising technology of any kind.
- No contact with any service other than monday.com's own (api.monday.com, auth.monday.com).
- No selling, sharing, or transferring of your information to third parties.
- No cookies.
- No collection of information from third parties.
4. Data deletion
Uninstalling the App from your monday.com account automatically deletes all stored tokens, rules, and preferences for that account. You may also request deletion at any time by emailing us, or by using monday.com's own app-data removal tools; requests are completed within one business day.
5. Security
The App runs entirely on monday.com's hosting platform ("monday code") with TLS-encrypted connections. Every incoming request is verified against the App's signing credentials; unauthenticated requests are rejected. Endpoints are rate-limited. Credentials are held in monday.com's Vault-backed secure storage, never in code or configuration files.
6. Your rights
Depending on your jurisdiction, you may have rights to access, correct, or delete personal information we process. Because the App stores almost nothing beyond an OAuth token, rule definitions, and a preference flag, the fastest route is usually uninstalling the App; for anything else, contact us and we will respond within one business day.
7. Changes to this policy
We may update this policy from time to time. We will notify you of changes by updating the "Last updated" date at the top of this page.
8. Contact
Questions about this policy: support@mutherboard.com. GroupMaster is published by mutherboard.com, a UK company.
GroupMaster · Terms of Service
© 2026 mutherboard.com. All rights reserved.
