Privacy policy
Not yet published.
This deployment is pre-release. A counsel-reviewed privacy policy, naming the data controller and sub-processors, must be published here before the platform is offered to the public.
What the software does today
These are properties of the implementation, verifiable in the source, not commitments made on behalf of any operator:
- Accounts store an email address, a display name, and an Argon2id password hash. Plain passwords are never stored or logged.
- Sessions record an IP address and user agent so you can review and revoke your own devices. They are deleted 30 days after expiry.
- Privileged actions are recorded in an append-only audit log scoped to the organization they occurred in.
- Logs redact credentials by key name and by value shape before they reach any sink.
- Data export and account deletion are implemented as first-class background jobs.