← Back

Prototype privacy design

Your address is an admission credential, not content.

This is not a final Privacy Notice or Terms. It distinguishes controls implemented in this prototype from workflows that must be completed and legally reviewed before public member collection.

What we collect

When the dedicated identity and database services are enabled, the design calls for your verified work or academic email, identity-provider subject, affiliation, profile fields you choose, and narrowly necessary security and membership events. The public prototype uses fictional records only.

An unsaved profile draft stays in this browser tab's session storage so a refresh does not erase your work. It is removed after you save or discard it, and it is not analytics.

Who can see the email

Member-facing payloads omit email. The implemented admin design shows masked addresses by default and permits one full-address reveal only after server authorization, a stated purpose, recent authentication, and an audit event. Bulk raw-email export is not implemented.

What we will not do

We do not scrape or generate individual work emails. We do not place emails in URLs, analytics, notification text, or AI prompts. We do not sell visibility, Intro credits, or access to member contact details.

Your controls

The database separates versioned required legal acceptance from optional consent receipts. The implemented local and development control plane supports scoped correction, export, consent-withdrawal, and deletion requests; opaque receipts; visible timing and retention exceptions; and cancellation while a request is still eligible. Provider-bound identity checks, final fulfillment operations, retention-policy approval, and legal copy still gate production member collection.

Open private data controls