Skip to the page
Toneinux

Turn a spreadsheet into a board everyone reads

Security and data

Security and data, stated plainly

Where the data sits, what is kept, who can see a board, how a seat is removed, and what happens when you leave. No certificate is claimed on this page, because none is held.

Where the data sits

The tool runs on servers in a data centre inside the European Union, and the region is written into your agreement so that it is a term rather than a matter of trust. Your sheet does not move. The connector reads it where it lives, in your shared workspace or on your shared drive, and carries back only the values inside the named ranges you chose. Nothing outside those ranges is read, and nothing that is read is used for any purpose other than drawing your board.

A pale green school notebook beside open pages of squared paper
Your sheet stays where it is kept. The board reads it there.

Kept

What is stored, and what is not

Stored

  • The values of each named range at each read, with the time of the read. These are the snapshots.
  • The layout of each board: which panels, bound to which ranges, placed where.
  • The list of seats in your workspace, each with a name, a work email address and a role.
  • The connector's read credential, encrypted at rest and never shown again after it is entered.

Not stored

  • The rest of your sheet, and any file the connector was not pointed at.
  • The formulas behind any value. The board sees results, never the working.
  • The sheet's own revision history, which stays with the sheet's host.
  • Personal customer records, because boards that would carry them are not taken on.

Traffic between your browser, the tool and the sheet's host travels over TLS, the ordinary encrypted transport every browser uses. That is a description of how the web works, not a certificate.

Access

Who can see a board

Only seats in your workspace. There are two roles. An editor can place, move and remove panels and bind ranges. A viewer can open a board, read it and step back through snapshots. An owner, usually the person who signed the agreement, can invite seats, change roles and remove seats, and there can be more than one owner so nothing depends on one person being in.

A board's link opens only for a seat that is signed in. Passed to anyone else it shows a sign-in page and nothing more. There is no public sharing, no embed code and no setting that opens a board to anyone holding the link.

Removal

How access is removed

  1. Remove a seat

    That person is signed out of every session within a minute. The boards, the snapshots and the ranges are gone from their view. Their past edits stay on the boards, attributed to a seat that no longer exists.

  2. Remove a connector

    Every panel that read from it is detached. The panels stay on the board marked stale, with their last good read, until an editor binds them to another range or deletes them.

  3. Revoke at the sheet

    Rotating or withdrawing the connector's credential at the sheet's own end has the same effect as removing the connector. That is by design: your sheet's permissions are the last word, and the tool cannot outrank them.

Leaving

When a team stops

Close the workspace and the boards, the snapshots and the seat list are deleted within thirty days; the connector's credential is revoked at once. Before closing, an owner can export every board's snapshots as plain comma-separated files, so the record of what the board showed leaves with you rather than with us. Your sheet is untouched throughout, because it was never ours to touch.

A trial workspace closes the same way, on the same schedule. Nothing from a trial is kept to be shown to anyone else.

Plainly

What we do not claim

Not on this page, or any other

  • We do not claim a certification, an audit or a compliance standard of any kind.
  • We do not publish an uptime figure.
  • We do not promise a saving of time or money.
  • We do not process personal customer records, and we will say no to a board that would carry them.

If your procurement needs any of those in writing, we are not the right vendor, and we would rather you knew that before the walkthrough than after it. If what you need is a plain account of where the data sits and who can see it, that is this page, and you can ask about any line of it on the call.