PRIVACY
How we handle data, today.
This page describes our current data practices, not a counsel-approved privacy policy. Our full privacy policy is in preparation.
We do not sell or rent personal data. Details of collection purposes, retention, and rights will be in our full privacy policy. If you need something specific in the meantime, contact us.
- PERSONAL DATA WE ACCEPT
- The pilot minimizes employee personal data — opaque tokens plus limited work location and plan facts. Names, government identifiers, home addresses, birth dates, and personal email addresses are not accepted through the standard roster path.
- AUTHENTICATION
- Pilot users sign in with a passwordless magic link — no local password, no password reset. Enterprise SSO (SAML 2.0 / OIDC) is planned for Phase 1 and configured per customer.
- ENCRYPTION
- Public traffic is served over HTTPS. GCP encrypts stored service data at rest. Selected sensitive application fields (stored email addresses, support message content) also use application-level AES-256-GCM encryption; secrets live in GCP Secret Manager, not source.
- AUDIT LOGGING
- Security-relevant and customer-administration mutations write append-only, tenant-scoped audit events. Access to internal audit views is itself audited, and application logging is structured to exclude plaintext personal data.
- WHERE IT RUNS
- The primary production configuration is GCP `us-central1`. This is a configuration fact today, not a contractual data-residency commitment; any residency, sub-processor, or DPA terms come from an executed customer agreement.