Legal → Privacy Policy
Privacy Policy
What we collect, what we refuse to collect, and how long it stays. Health information has its own policy, separately and by law.
Draft — not yet reviewed by counsel. Published early so the commitments can be checked before launch. The plain-language version of the stored record is at what we store, and it is the same record.
1. What we collect
A verification result, a coarse role class, a method code, a timestamp, your page if you make one, and a salted hash of your work email domain if you used that verification tier. Plus what you post, stored under a per-conversation name we cannot trace back to you. That is the list.
Before launch, none of the above exists yet. The only record we hold today is the pre-launch list: the email address you gave on the Clock In form, and the role and location if you chose to add them. It is deleted when your account is created, or on request.
2. What we do not collect
Licence numbers, NPIs, employer as a stored field, badge images or hashes of them, face templates of any kind, your legal name unless you publish it yourself, and any inferred profile of your interests or health. Details: what we store.
3. Verification data
Artifacts submitted for verification are processed in memory and discarded. See how verification works for the step-by-step, including the client-side crop.
4. Logs and security data
IP logs are rotated aggressively rather than retained. Security logs do not carry post contents.
5. Cookies
A session cookie so you stay signed in. No advertising cookies, no third-party trackers, no cross-site analytics that identify you.
6. Who we share with
Service providers operating the platform under contract, limited to what the service requires. We do not sell member data, in any form, to anyone — including de-identified or aggregated. We do not take money from health systems.
7. Legal demands
Answered against a record built to be thin. Counts are published in the transparency report, which carries a warrant canary.
8. Your rights
Access, correction, deletion and portability, to joel@statuspostcollective.com. These cover the record we hold: your verification result, your page, and the pre-launch list. They cannot cover your pseudonymous stories, because we cannot tell which are yours — those you export or delete yourself, from the device holding your key. Health-data requests are handled under the Consumer Health Data Policy.
9. Changes
A change that widens collection is announced before it takes effect. A change that narrows it, we just make.