Legal
Privacy Policy
Version 2026-08-01
1. What we collect
We collect account information (name, work email, job title, organization, timezone), diagnostic responses on a fixed 1–5 agreement scale, and standard technical logs required to operate the Service securely. We do not collect open-text comments as part of the diagnostic.
2. What we do not collect
We do not use keylogging, screenshots, webcam or microphone access, or any form of passive activity monitoring. We do not build individual productivity rankings or run automated performance classification on individuals.
3. How diagnostic data is used
Individual responses are scored on the server to compute team-level condition scores and a binding constraint. A team report is only produced once at least five non-leader participants have completed the diagnostic; below that threshold, no aggregate view is generated. Leader responses are scored and shown separately from the team aggregate.
4. Data sharing
We do not sell personal data. Data is shared only with subprocessors necessary to operate the Service (such as our database and authentication providers), under agreements requiring them to protect it consistently with this policy.
5. Data retention
We retain organizational and diagnostic data for as long as an organization's account is active, plus a limited period thereafter for legal and accounting purposes, after which it is deleted or irreversibly anonymized.
6. Security
Tenant data is logically isolated with row-level security policies, and sensitive actions are recorded as audit events. See our Security & Privacy page for detail.
7. Your rights
Depending on your jurisdiction, you may have rights to access, correct, or delete your personal data. Contact us through the contact page to exercise these rights.
8. Children
The Service is intended for use by working adults and is not directed at children.
9. Changes to this Policy
We may update this Policy from time to time; material changes will be reflected in the version date above.