Last updated: August 18, 2026
Greenlight Approvals ("the app") is a monday.com marketplace app that runs approval workflows on your boards, a product of PT Integrasi Cerdas Indonesia, operating as Orelis.ai. This policy explains what data the app handles, where it goes, and what we do with it. The short version: your data stays in your monday.com account; we collect almost nothing.
Approval requests, decisions, approver names, and timestamps are written to your monday boards (columns and item updates). Transient coordination state for in-flight approval chains is stored in monday.com's own app storage, scoped to your account. We do not operate a separate approvals database.
Approver index. So that an approver can later see all of their pending approvals in one place, we keep a small index linking a one-way, salted fingerprint of each approver's email address to the monday.com account IDs where they have approvals waiting. That index contains no email addresses, names, item details, or approval contents, and the fingerprint cannot be turned back into an address without a secret key that we store separately.
Requesters can attach a single file (up to 10 MB) to an approval request. The file is uploaded straight to your own monday.com account storage — the same Files-column storage your boards already use — not to a separate Greenlight database. To let an approver open it, we proxy the download through a link that is cryptographically signed, tied to that one approver and that one file, and expires after 7 days. We do not keep our own copy of the file; its retention is governed by your monday account, the same as the board data described above.
Approval request and reminder emails are sent through our own mail server (hosted at Contabo GmbH, Germany). Approver email addresses and the content of those emails (item name, decision links) transit this server for delivery only. Decision links are cryptographically signed, single-use, and expire after 7 days.
When the app's AI features are active, Greenlight generates a short plain-English approval brief on each request (with anomaly flags) and can draft routing rules from a plain-English description. The text is generated by Moonshot AI's Kimi model (api.moonshot.ai), which acts as a sub-processor for these features only. To do that, the app sends Moonshot:
This data is sent transiently, only to generate the text, and only while the AI features are active. We store only the generated brief or draft — and the decision itself is always made by a human, never by the AI.
The Greenlight Approvals application server is hosted on Railway (Railway Corp., USA). Requests to the app — including approval decisions and portal sessions — are processed there. Approval data itself (chains, rules, templates) is stored in monday.com's own app storage, inside your monday account's infrastructure, with monday access tokens encrypted at rest. Our mail server is hosted at Contabo GmbH (Germany), as described above. When the AI features are active, Moonshot AI processes the limited request data described in the section above to generate briefs and rule drafts. We use no analytics or advertising sub-processors.
The customer portal (app.greenlight-approvals.com) sets two cookies when you sign in:
Neither cookie tracks you across sites or feeds any analytics or advertising system, and we do not set third-party cookies.
Audit entries on your boards remain under your control and can be deleted like any board content. Transient chain state is deleted automatically when chains complete or when you uninstall the app. OAuth access tokens are stored in monday's secure storage and can be revoked at any time by uninstalling the app.
All traffic is encrypted in transit (TLS). The app uses OAuth 2.1 with PKCE, short-lived signed decision tokens, and monday's account-scoped storage isolation.
Questions about this policy or your data: support@greenlight-approvals.com.