Privacy and your information
Updated September 13, 2026
Current development status
Public registration is closed. Private testing must use fictional information. Secure sharing, recovery and mobile integration are still being completed. This page describes the current development version; we will update it before opening the service.
Information used to operate accounts
The account service stores account names, email addresses, password hashes, verification status, sessions, authentication settings, hub memberships, invitations, permissions and activity or consent records. These operational details are not encrypted with your personal recovery key. We use them to authenticate you, deliver account messages and enforce hub access.
Personal and hub records
The experimental vault and shared-record pages encrypt supported record content on your device before sending it to the service. They store encrypted content and identifiers, version numbers and timestamps. The client does not upload readable recovery or record keys. Encrypted record keys may be stored for selected recipients. A lost key cannot be recovered by resetting your sign-in password.
This protection has not received an independent security review. It does not protect a compromised device or guarantee that an operator capable of changing the website could never access future entries. Do not enter sensitive personnel information during testing.
Sharing with a hub
Authorized hub users who have the record key can read its contents. A record offer lets its recipient explicitly keep the hub information or replace it with their saved personal information. Open shared-record editors can refresh saved changes from the same hub while preserving unsaved drafts for review. Automatic updates between different hubs and key revocation are not implemented yet. Removing access cannot erase information another person has already downloaded or copied.
Sharing recovery
The experimental sharing screen creates an identity on your device. The service stores its public key, fingerprint and a private key encrypted with a separate sharing recovery key. Selected recipients receive encrypted record keys, bound to the sender, recipient, hub, record and saved version. Members must compare identity fingerprints through a trusted conversation. Password resets cannot restore the sharing recovery key. Identity replacement, key rotation and automatic recovery of every record are not implemented.
Record key backups
You can save an encrypted backup of up to 40 record keys for your account and hub. It is encrypted on your device with a separate backup recovery key. The service stores only the encrypted backup, account and hub identifiers, version and timestamp. Restoring requires that same account, current hub record access and the backup recovery key. Replacing the backup replaces its entire key collection. Account or hub deletion removes the active backup; infrastructure backups may persist under the retention limits described below. Password resets cannot recover the backup recovery key. Keep your original private key file separately.
Local prototype data
The local prototype keeps its records in that browser or app's local storage. It does not automatically import them into your online account. The private transfer tool lets you review and copy selected personnel fields from local saved data or an export into new encrypted hub records. Selected tasks, calendar events and assessment history can also be transferred. Historical scores are preserved without recalculation. New assessment transfers require the corresponding personnel record; the service stores the relationship between their record IDs so deleting the personnel record also deletes those assessments. This relationship does not identify an account until the personnel record is associated with one. Older unlinked imports are not automatically associated. Imported person and section identifiers do not grant access or assign cloud members; access rules are not transferred. The original export and local storage are not deleted. Clearing app storage, uninstalling the app or losing the device can remove local records. Keep backups before changing devices.
Service providers
Cloudflare provides hosting and database infrastructure. Resend processes the recipient address and message content for verification, password-reset and invitation emails. Infrastructure providers may process technical request information, such as IP addresses, to deliver and protect the service. Do not send personnel records or recovery keys by email.
Device unlock
The optional mobile biometric feature stores a sign-in session in biometric-protected device storage. It does not store your password or send Face ID or fingerprint templates to us. Session expiry, biometric changes or device loss may require signing in again. Record recovery keys are separate.
Retention and deletion
The experimental record store retains up to ten previous encrypted versions. Encrypted backups you download remain in your possession and require the appropriate key. Deleting an active shared record removes its active history; downloaded copies and infrastructure backups may still exist. Confirmed member removal deletes that member's linked record in that hub. Unlinking retains the hub's record and ends the active membership link. A linked member can explicitly copy their saved hub record into an existing personal vault before unlinking; later hub changes are not automatically copied. Other hubs and existing personal vaults are not deleted by these membership actions. The development version provides account deletion requests with a seven-day cancellation period and self-service completion after fresh sign-in. Transfer hub ownership first; contact support if you cannot. Completing deletion removes your account, personal vault and associated identifiable hub records and history, including associations retained after unlinking. We retain limited record-to-account associations for this purpose. Previously unlinked or unassociated records may require a separate privacy request. Infrastructure backup expiration and deletion after a restore remain under verification before public release. This policy does not promise deletion of copies other people already downloaded.
Contact
Email goldentriangleapp@gmail.com for privacy questions. Include only the information needed to explain your request. Never include a password, verification code, recovery key or personnel record.