Privacy information / Development phase

Private creation requires deliberate data boundaries.

This page describes the product principles implemented for the current development and private-beta environment. A jurisdiction-specific privacy notice, controller identity, and contact channel must be published before public production processing.

Data used by the workspace

Account identity, profile information, organization participation, project records, uploaded evidence, security events, and audit records are processed only to operate and protect the creation workspace.

Visibility and access

Drafts are permission-bound. Organization and project access is evaluated server-side, and knowing an object identifier does not grant access. Public visibility must be an explicit product action.

Security and minimization

Passwords, session cookies, authorization values, private storage keys, and secret credentials are not returned as ordinary API content or written to application logs. Operational records use non-sensitive identifiers where possible.

Data rights and retention

Signed-in members manage consent and exercise export and erasure rights from the account privacy center at /account/privacy. Consent history is append-only, exports are encrypted and expire after 24 hours, and erasure follows a 7-day cooling-off period with a human review. Legal holds and processing remain platform operations. For any data-rights question, contact [email protected].