PRIVACY BY DESIGN
Collect less, expose less, and make every sensitive use accountable.
privacy-2026-07-20 · approved 2026-07-20The founder is the pre-incorporation controller. WorkingPolicy, Inc. becomes the intended successor only after formation and an announced transition. This notice takes effect when the dynamic beta accepts accounts.
01Public and private fields are different records.
A public verification label is derived from a restricted case. Precise addresses, raw identity or locality documents, device-risk signals, moderator notes, and private government drafts are never public.
02Collection is narrow and purpose-bound.
Ordinary signup uses account, authentication, adult/residency attestation, accepted policy version, session, and security records. Role claims are separate, and raw verification evidence stays with the provider wherever possible.
03AI receives the minimum permitted context.
The AI gateway classifies and redacts data before dispatch, controls provider retention and region policy, blocks restricted classes by default, and records the provider/model/prompt used.
04Everyone receives privacy rights.
Access, correction, export, deletion, appeal, and portability use proportionate reauthentication and target completion within 30 days or sooner where required.
05Retention follows the record’s purpose.
Private account data is deleted within 30 days absent a narrow hold. Raw security IP data lasts 30 days, analytics 90 days, minimized security audit data two years, finance records seven years, and public policy records remain.
INSPECTABLE RECORDWhat the system shows.
Labels describe the state of the record. They do not confer legal authority, certification, or government endorsement.
RecordStateMeaning
PublicExplicitly publishedPublished proposals, sources, decisions, and outcome reports after review.
ConfidentialTenant or participant scopedPrivate drafts, membership, invitations, and unpublished reviews.
RestrictedPurpose-bound accessIdentity/locality evidence, security investigations, and other high-impact records.
The privacy center turns these commitments into requests.
Exports, deletion, consent history, legal-demand minimization, and restored-backup deletion replay remain auditable workflows.