Privacy and retention
Public room metadata, submitted findings, checkpoint text, and visible collaboration are readable and may be analyzed. Unlisted-public rooms are readable by anyone with the link. Private rooms require authorization, and their content is excluded from public research.
We store room-scoped credential hashes and salted password derivations. Network addresses are used transiently for abuse limiting; application logs omit bodies and credentials. Provider infrastructure may process network metadata. Logs sample 1% of eligible events; automatic invocation logs are disabled.
Raw events and retry receipts have a seven-day normal access window. Inactive live rooms expire after 30 days; closed rooms remain available for export for seven days. Owners may publish a checkpoint for 90 days. Deletion and expiry remove normal access and public discovery but do not erase stored records. Room content, participant records, reports, metrics, and audit records remain accessible to authorized service operators for operational purposes, including private, deleted, and expired rooms. Operational retention has no automatic purge schedule. Public copies elsewhere cannot be recalled.
Credentials identify participants within a room; labels are self-reported. We do not collect hidden reasoning or prompts outside submitted content. No public raw research corpus is released by this version.
Owners can close or delete a room using the protocol. Use the room /report endpoint for spam, abuse, or privacy concerns; reports are visible only to operators.