Upvotebell — Privacy Policy

Last updated: July 15, 2026

Upvotebell ("we") provides a customer feedback, voting, and public roadmap service for monday.com customers. This page describes what we collect, why, how we store it, and how to ask us to delete it. It covers both the monday.com account that installs the app and the visitors who use a public feedback portal.

What we store

Your ideas live on your monday.com boards, which are the source of truth. We key all data by numeric monday.com IDs — never by the installer's name or email. We store only:

  • Account metadata: the monday.com account id, name, slug, plan, and seat count — the minimum needed to operate the app and enforce plan limits.
  • Portal configuration: the portal slug, name, chosen roadmap status column, public statuses, branding color, and moderation settings you set per board.
  • Ideas & engagement data: idea titles and descriptions submitted on the portal, vote and comment counts, publish state, and source.
  • Voter email addresses: the only personal data we store. A portal visitor's email is collected when they submit, vote, comment, or follow an idea, so we can prevent double-voting and notify them about that idea. It is stored encrypted with AES-256-GCM, alongside a one-way keyed hash used only for de-duplication — we never store it in plain text. Because a portal is operated by the monday.com account that installed the app, that account's admins and members can see the email addresses of the people who voted on or commented on their own ideas (so they can follow up on feedback). Voter emails are never shown publicly on the portal and are never shared with any other account.
  • Votes, comments, and follow subscriptions: keyed by an internal idea id and voter id.

What we don't do

  • We never sell, rent, or share your data with advertisers.
  • We never store the installer's name or email, or any monday.com board content beyond what is needed to render the portal.
  • We don't store passwords, and we never store a monday.com access token — the app is token-free and acts on your board only through your own short-lived monday.com session while you use it.
  • We never show a voter's email publicly on the portal; comments display a generic label, not the author's email.

Portal visitors & email notifications

When a visitor votes, comments, or follows an idea, we email them only about that idea's status changes. Every notification explains why it was sent, and visitors can stop receiving updates for an idea at any time. Email is sent through our email provider solely to deliver these notifications.

Third-party processors

  • monday.com / monday-code — hosting of the app's embedded views, public portal, and APIs.
  • Supabase — managed Postgres database for configuration, lifecycle state, votes, comments, and encrypted voter emails (data at rest is encrypted).
  • Resend — delivery of voter status-change notification emails.
  • Vercel — hosting & TLS termination for these public legal and documentation pages.

Security

All traffic is served over HTTPS with HSTS and TLS 1.2+. Voter emails are encrypted at rest with AES-256-GCM, with keys held in the monday-code Secrets Manager and never exposed to the browser. Every embedded request is authenticated with a verified monday.com session token and scoped to the corresponding account; database access is restricted by row-level security. Logs never contain voter emails.

Data deletion

When you uninstall Upvotebell from monday.com, your configuration, ideas, votes, comments, subscriptions, and voter emails become inaccessible immediately (your public portal returns a 404), and all related data is hard-deleted within 10 days (in practice, within 7 days). Portal visitors and account admins can also email support@devloggic.com to request immediate deletion.

Contact

Questions? Devloggic SAS
Email: support@devloggic.com