Last updated 26 August 2026. This policy covers the Signoff app. If any sentence here needs a lawyer to interpret it, that is a defect and we would like to know about it.
Where it lives
This is the whole architecture, and it is short enough to state in a paragraph.
Every approval Signoff creates is written to monday’s own storage API, scoped to the board the app was installed on, inside your account. That is where your approvals live, and it is the only place they have ever lived.
A small service handles two jobs the panel cannot: running the workflow automation, and serving the page an outside approver opens. It is hosted on Vercel, in the United States. It stores nothing — it reads and writes your monday account using a short-lived token monday issues for that single request, and keeps no copy afterwards. Requests to it transit Vercel, who keep standard server logs including IP addresses.
The consequence is worth being blunt about: we operate no database, and there is no copy of your approvals on any machine we control. If you uninstall the app, the data goes with your monday account rather than needing to be requested back from us. We cannot export your approvals for you, because we cannot read them.
So there are exactly two companies in the chain and no more: monday.com, where your approvals live, and Vercel, who run the service that passes requests through. No analytics service, no error-reporting service, no cloud storage bucket, and nobody we have not named here.
The record
Every field, with nothing omitted. Attachments are the one that surprises people, so it is stated twice.
Stored
Never stored
On attachments. Signoff notices when a file changes after somebody has approved it, and reopens the approval so the old decision cannot travel with a new document. It does this by recording each file’s identifier and version marker — not by reading, downloading or storing the file. A drawing that has been revised twice is three version markers to us and zero bytes of drawing.
Approvers outside monday
Signoff can ask somebody without a monday seat to approve. This is exactly what that link is.
The link contains an account reference, an approval reference and an approver reference, plus an expiry and a random value, signed so it cannot be altered. It carries no name, no email address and no company information, and it grants the ability to decide one approval and nothing else.
Every link expires, and the longest one that can be issued lasts fourteen days. There is deliberately no option for a link that never expires, because a permanent link in an old email thread is a permanent way into your approvals.
Artificial intelligence
Common enough to assume the opposite in 2026, so it is worth its own section.
Signoff routes approvals using rules you configure — a value threshold, a board, a column. No large language model, no machine learning model and no third-party AI service reads your items, your comments, your attachments or your decisions, at any point. Nothing about your approvals is sent to an AI vendor, and none of it can end up in anybody’s training data.
One thing that is worth naming, because it looks like an exception and is not. Signoff publishes a skill to monday’s own assistant, sidekick, so somebody can say “send this to legal for approval” instead of opening the panel. The language understanding is monday’s, on monday’s side; what reaches Signoff is the same handful of fields the panel would have sent — which item, and who has to agree. We hold no model credentials, call no model, and send nothing to any AI vendor. If you never speak to sidekick, nothing about this touches you at all.
If anything beyond that ever changes it will be opt-in, it will be named on this page before it ships, and it will never be a condition of using anything you already pay for.
For completeness, and because it is a fair question to ask: AI tools were used to help write Signoff’s code, the way a developer uses any tool. That is a fact about how the software was built, not about what it does with your data.
Your rights
An unusual position, and the honest consequence of holding nothing.
Because every record lives in your monday account, you delete an approval by deleting it, and you delete all of them by uninstalling the app. There is no retention period on our side to wait out and no request to file, because there is nothing on our side.
If you email us we will have your email address, because you sent it, and we use it to reply to you and nothing else. Questions about this policy go to support@billboard.plus.