Card Vault+ is a Trello Power-Up that saves card snapshots so teams can recover deleted cards and restore older card content. This policy explains what Trello data we access, what we store, why we store it, and how you can control your data.
When you enable Card Vault+ on a Trello board, the Power-Up can save snapshots of card content (manually or automatically), show version history, and restore selected fields or recreate deleted cards from saved snapshots. Card Vault+ is card-focused recovery—not a full Trello workspace backup.
With your authorization, Card Vault+ accesses Trello through the official Trello API to:
Card snapshots may contain personal data if your Trello cards include names, emails, or other identifying information in descriptions, comments, or member fields.
We do not sell your Trello card content.
Card snapshots and recovery data are stored in our backend database (PostgreSQL) hosted with our infrastructure provider. Data is not stored in browser localStorage, cookies, or Trello pluginData as the source of truth for recovery.
Small UI preferences in the Power-Up may use browser storage; those preferences are not used as recovery data.
Snapshot retention depends on your board settings (for example 30 days, 90 days, 1 year, or forever). Expired automatic snapshots are deleted according to your retention policy. Manual snapshots may be kept longer when “keep manual snapshots forever” is enabled. Audit and restore logs may be kept longer for security and support.
Revoking Trello access stops new snapshots and restores that require Trello API access. We process Trello GDPR compliance notifications (account deletion, token revocation, and profile updates) through Trello’s Compliance Polling API when background jobs are enabled in production.
Restore recreates a new Trello card or updates an existing card from saved snapshot data. It does not guarantee recovery of attachment files, exact card position, full comment history, or all Trello metadata. Cards that were never snapshotted while protection was enabled cannot be recovered.
We encrypt Trello tokens at rest, use HTTPS in production, scope API access by user and board, and avoid logging sensitive card content in production logs.
We use infrastructure providers to host the API, database, and background jobs. Those providers process data only as needed to run Card Vault+. We may disclose information when required by law or to protect the security and rights of users and the service.
Privacy questions or data deletion requests: support@nikaj.dev