Privacy policy
Applies to Jotform Sync Plus. Last updated 4 September 2026.
Who we are
Jotform Sync Plus is operated by Anatolii Skuba, an individual developer based in Ukraine, under the product name Steadyhook. Website: steadyhook.app. Privacy and legal contact: anatolii.skuba@outlook.com. Product support: support@steadyhook.app.
What the app stores
| Data | Why | Where |
|---|---|---|
| monday.com OAuth access token | To create and update items on the boards you configure. Submissions arrive when nobody is signed in, so the token must be held server-side. | monday code secure storage, encrypted at rest |
| Your Jotform API key | To list your forms, register the submission webhook, and import past submissions on request. | monday code secure storage, encrypted at rest |
| Your configuration | Which form feeds which board, the field mapping, the condition, and which answers become subitems. | monday code secure storage |
| Operational sync metadata | Jotform submission ID, linked monday item/subitem IDs, a one-way content fingerprint, timestamps, sync status and monthly usage. This lets retries and edits update the same work item without retaining answers. | Account-segregated monday app storage |
| Operational logs | To tell a failure apart from silence when something does not sync. Logs record account, board and created-item identifiers, timing, actions and non-PII error codes. | monday code logging, retained 30 days |
What the app does not store
Form submissions are not written to the app database. A submission is temporarily buffered in monday code Queue for delivery and retry, written to your monday board, and discarded. Uploaded files remain in Jotform storage; the app does not copy file contents. Submission answers are not written to logs or sent to the AI mapping feature.
Who else sees the data
Two parties, both of which you already use: monday.com, which hosts the app and receives the items it creates, and Jotform, which sends the submissions. No analytics, advertising, or third-party trackers are used. No data is sold or shared with anyone else.
The AI suggestion
When you press Suggest mapping with AI, the app sends your form's field names and your board's column names and types to monday.com's own Models API, and receives a proposed mapping back. Nothing is applied until you review it and press Save.
No submission answers are sent. Not a sample, not a preview, not one row. The feature works entirely from the names of things. Because the request goes through monday.com's AI gateway, it runs on your account's monday AI credits and no third-party AI provider is contacted by us directly.
Every domain the app contacts
| Domain | Side | Why |
|---|---|---|
| api.monday.com | backend | Reading board columns and groups; creating items and subitems. |
| auth.monday.com | backend | Exchanging the OAuth authorisation code for an access token. |
| api.monday.com (platform-ai-gateway) | backend | The AI mapping suggestion. Field and column names only — see above. |
| api.jotform.com eu-api.jotform.com hipaa-api.jotform.com |
backend | Listing your forms and questions, registering the submission webhook, and importing past submissions when you ask for it. Which host is used depends on the data region you pick; an EU or HIPAA account is never contacted through the standard host. |
That is the complete list. The interface loads no scripts, fonts, or styles from anywhere else — the monday SDK is served from this domain rather than from a public CDN, so no third party sits in the path of your session token.
Deletion
Uninstalling the app triggers immediate deletion of your OAuth token, Jotform API key, configuration, sync links, status and usage counters, and removes the registered Jotform webhooks. If an upstream API is unavailable during uninstall, write to support@steadyhook.app for a manual check.
Your rights
You can ask what is stored about you, ask for it to be corrected or deleted, and object to processing. Write to the address above.