Privacy policy
Private evidence deserves a smaller footprint.
MVP policy · Effective 7 August 2026
The beta and contact forms can store submitted fields in a protected intake database. Local TEST mode never sends email. Hosted confirmation email remains fail-closed until every launch check and separate external-send approval pass. This MVP does not charge a card, verify an identity, pay an answerer or upload evidence.
Data in this MVP
Demo profiles, watches, questions, membership state, answer feedback and product events remain in local browser storage. The closed-beta and contact forms are different: they send the fields shown to a restricted intake database.
Closed-beta applications
We collect a name or working alias, email, named programme, timing and research answers. Answerer applications also include a role, year, evidence description and conflict disclosure. We use this only to select and operate the beta. Do not submit identity documents or private evidence in these forms.
Test and live records
Local submissions and hosted submissions made while intake mode is set to test are labelled TEST, excluded from recruitment claims and never send email. A live record requires every launch prerequisite plus an explicit owner switch. Live confirmation delivery is recorded separately from the application itself.
Abuse prevention and confirmation email
Submission limits use a daily salted hash of the connecting network address. The raw address is not stored in the intake table, and rate counters are deleted after their short operational window. When every live-launch gate is approved, the configured email provider receives the applicant email, name and reference ID only to send the confirmation.
Retention and deletion
Unselected beta applications are scheduled for deletion within 90 days after beta selection closes. Selected participant records are retained during the beta and for up to 90 days afterward, unless a longer period is required by law or to resolve a dispute. Use the contact form and quote the reference ID to request correction or deletion.
Production account data
A live service would need account details, practical profile fields, saved opportunities, questions, answers, moderation history and billing status. Card data should stay with the payment provider.
Contributor evidence
Verification evidence may contain sensitive personal information. Production must minimise collection, restrict reviewer access, define retention and let contributors request correction or deletion where lawful.
Public content
Questions and accepted answers are intended to be public after moderation. Users must remove private application content before submitting.
Your choices
Production must provide access, correction, export and deletion controls appropriate to the user’s jurisdiction.
Questions: contact the Residency Answers team.