Privacy Policy

Last updated: September 2026

Roster does not store any of the data it reads from your monday.com account. Every time it's opened, it queries the monday API, builds the view in your browser, and discards it when the tab closes. There is no database behind Roster.

1. Who this policy covers

This policy applies to Roster, a monday.com Administration view built and operated by Keel. Contact: contact@craft-palette.net.

2. What Roster reads, and why

Roster requests four read-only scopes from your monday.com account. It requests no write scopes — it cannot create, change, or delete anything on your account.

ScopeWhy it's needed
boards:readBoard ownership, subscribers, kind, and permission settings — the core of the access picture.
users:readEach person's user type and last activity, to flag dormant owners and guests.
teams:readTeam membership and team-based subscriptions, including the account-wide "everyone" team.
workspaces:readThe workspace name each board belongs to, for grouping in the board list.

3. What Roster does not do with this data

4. Where the data goes

Requests go directly from your browser to the monday API through the monday SDK. Roster's own code has no backend server that this data passes through. CSV exports are generated in your browser and download directly to your device.

5. Cookies and tracking

Roster does not set cookies and does not run third-party analytics or advertising scripts inside the app view.

6. Data retention

There is nothing to retain. Because Roster does not persist the data it reads, there is no retention period, no backup, and nothing to delete on request — closing the tab already clears it.

7. Changes to this policy

We may update this policy as Roster changes. The "last updated" date above reflects the most recent revision.

8. Contact

Questions about this policy or how Roster handles your account's data: contact@craft-palette.net.