Last updated: 14 August 2026 · Evidence Check AI for monday.com
We store our verdict, not your evidence. The file stays in your monday account. We keep what we concluded about it plus a SHA-256 hash of the bytes, so it can be shown that the verdict was about exactly that file, and never the bytes themselves.
| Stored | Contents |
|---|---|
| Installation | Your monday account id, the moment of installation, the retention period in force, and the monday access token — encrypted. |
| Verdict log | Board, item and column id; the asset id of the attachment; a SHA-256 hash of the evaluated bytes; a SHA-256 hash of the requirement text; a short excerpt of that requirement so the log stays readable; the verdict, confidence and the model rationale; the model id and prompt version; token counts, latency and the moment of assessment. |
| Overrides | Who overruled a verdict, the previous and the new verdict, the mandatory reason, and when it happened. |
To reach a verdict, the attachment and the requirement text are sent to Anthropic (the Claude API), which acts as our processor for that request and does not train on it. That is the only third party involved. Everything else — the verdict log, the overrides, the installation record — stays in our own PostgreSQL database in the EU.
A verdict does not stay forever. The default retention period is 24 months, after which the verdict and its override history are deleted automatically. We can set it to any value between 3 and 84 months, either on request or through the app's API. There is no settings screen for it yet, so today it is a deliberate step and not something that changes by accident. The same period applies to the usage record we keep for billing, which holds the board, item and column the call was made for — it is deleted on the same clock, not kept longer.
When you uninstall Evidence Check AI, everything we hold for your account is deleted at that moment: every verdict, every override and the installation record itself. Not a status flag, a real delete, in one transaction.
The monday access token that lets us fetch an attachment is stored encrypted with AES-256-GCM, and it is destroyed by that same delete. After an uninstall there is no credential to your monday account left on our side.
Access, correction, export and erasure: mail info@getcompliant.online. An export of your own verdict log is available at any moment from the board view, as a CSV file — you do not need us for that one.