WorkingPolicy
Start a proposal
PRIVACY BY DESIGN

Collect less, expose less, and make every sensitive use accountable.

privacy-2026-07-20 · approved 2026-07-20

The founder is the pre-incorporation controller. WorkingPolicy, Inc. becomes the intended successor only after formation and an announced transition. This notice takes effect when the dynamic beta accepts accounts.

01

Public and private fields are different records.

A public verification label is derived from a restricted case. Precise addresses, raw identity or locality documents, device-risk signals, moderator notes, and private government drafts are never public.

02

Collection is narrow and purpose-bound.

Ordinary signup uses account, authentication, adult/residency attestation, accepted policy version, session, and security records. Role claims are separate, and raw verification evidence stays with the provider wherever possible.

03

AI receives the minimum permitted context.

The AI gateway classifies and redacts data before dispatch, controls provider retention and region policy, blocks restricted classes by default, and records the provider/model/prompt used.

04

Everyone receives privacy rights.

Access, correction, export, deletion, appeal, and portability use proportionate reauthentication and target completion within 30 days or sooner where required.

05

Retention follows the record’s purpose.

Private account data is deleted within 30 days absent a narrow hold. Raw security IP data lasts 30 days, analytics 90 days, minimized security audit data two years, finance records seven years, and public policy records remain.

INSPECTABLE RECORD

What the system shows.

Labels describe the state of the record. They do not confer legal authority, certification, or government endorsement.

RecordStateMeaning
PublicExplicitly published

Published proposals, sources, decisions, and outcome reports after review.

ConfidentialTenant or participant scoped

Private drafts, membership, invitations, and unpublished reviews.

RestrictedPurpose-bound access

Identity/locality evidence, security investigations, and other high-impact records.

The privacy center turns these commitments into requests.

Exports, deletion, consent history, legal-demand minimization, and restored-backup deletion replay remain auditable workflows.

Read retention rulesRead the AI notice