Privacy
Version 2026-08-26
This is written from the database rather than from a template, so it says what is actually stored rather than what a policy usually says. If something here is wrong, it is a bug and it is worth telling us about.
What is held, and why
| What | Why |
|---|---|
| Your email address and a password hash | So you can sign in, and so the account can be recovered if outbound email is ever configured. |
| The address of each device you asked us to notify, and which things you asked to be told about | So a notification can reach a phone that is not open. The address is minted by your own browser or by Apple, never by us, and it is only stored because you pressed a switch and your device granted permission. Both are yours. It is deleted outright when you turn notifications off on that device, when the push service says the address is dead, and when you delete your account. No message text, no name and no Outsider number is ever put in a notification, because a lock screen is a public surface. |
| A daily tally of how many times each page was served | So we can tell whether anybody is using this and where they stop. It is split only by whether the visitor was signed in, and that is read from the presence of a cookie and never from its contents. There is no identifier of any kind in it: no account, no address, no device, no location, and no visitor id. It is a table of totals, so no row in it can be narrowed to a person, including you. |
| Your email address, if you put it on the founding list | So we can tell you when the founding drop opens, which is the only thing it is used for. It is kept separately from accounts: somebody on the list has no account, no Outsider number and no password here. Joining the list and joining Base Camp are different things and neither one creates the other. |
| Which link you first arrived on, if it carried a campaign tag | So we can tell which piece of work brought people here, and stop paying for the ones that did not. It is three words a marketer typed into their own advertising URL, held for thirty days in a cookie on your device and then written once against your account. It is not an identifier, it does not follow you off this site, and there is no advertising pixel or third party script anywhere in this app. |
| Your Outsider number, the date you joined, and your climb stage | The number is your identity here. It is never reissued, including after you delete the account. |
| The name you choose to show, your city, your bio, and what you are climbing toward | Only shown to other Climbers when you switch the roster on, which is off until you do. |
| Your answers to the twenty intake questions, and the reading built from them | To produce your archetype. It is never sold, never shared, and never sent to any third party. |
| Your journal entries | Private to you. Nothing else in this app reads them and no model is run over them. |
| The private focus you choose, any words you add, the next step shown, whether you opened it, and the answer you give afterwards | To give you one explainable next step and preserve your private history across devices. It is visible only to you, is not used to match you with people or Spaces, and is deleted with your account. |
| Which learning Resources you saved or marked complete, and when | To keep your Learn shelf and progress consistent across devices. Opening an original source does not mark it complete. |
| What you submit to shared surfaces: feed posts, perspectives, replies, answers to the daily question, service listings | To show standing items to other Climbers and to let a human review held or reported content. If you delete your account, service text is removed from both the listing and any conversation subject copied from it. |
| Your messages, in one-to-one threads and in rooms, plus names of ad hoc rooms you open | To deliver them. They are stored in the database like everything else and are not end to end encrypted. If you delete your account, your shared message text is removed and an ad hoc room name you created becomes Closed room. |
| Which official Spaces you joined, were invited to, or left | To open the Space discussion room, enforce its member limit, and stop access when you leave. Joining a Space does not connect you privately to everyone inside it. |
| Who you are connected to, and who asked whom | To decide who may reach you. Never shown as a count and never walked to find who else you might know. |
| Your Handshakes with another Climber, including their terms, state, delivery and dispute notes, and receipt | So both parties can complete an agreement and keep proof of its ending. If either party deletes their account, the other keeps only a minimum receipt with the two permanent Outsider numbers, the final status and the retention date. Names, prices, terms, due dates, delivery notes, revision notes, dispute text and older receipt wording are removed. If an introducer or canceller deletes their account, their identity field is removed without erasing evidence owned by the two surviving parties. If a third-party dispute actor deletes their account, the original account is replaced by a number-only tombstone and the surviving parties keep the dispute evidence. |
| Events you said you were going to | For the count on the event. Your name appears on your card only for events where you ticked that box. |
| Pieces you claimed, and when | So a physical garment can be tied to an account. |
| An opaque checkout receipt, the Shopify variant and quantity chosen, and the minimum order status and amounts returned by Shopify | So checkout can stay on Shopify while support can match a verified order to the person who opened it and, when applicable, the Climber who invited them. The receipt is a random identifier. An abandoned handoff expires after thirty days, and expired handoffs with no order are removed in bounded batches as checkout traffic resumes. Shopify receives no account ID, email, Outsider number or referral code from this app. We do not retain Shopify customer names, email addresses, phone numbers, shipping or billing addresses, payment data, raw line items, or the raw webhook. Deleting an account removes its direct links from checkout and order records while leaving the non-customer order evidence needed for support and accounting. |
| A record that an action happened, with limited operational detail | So there is an audit trail of writes. On account deletion, earlier entries lose their account attribution, subject and detail. One final deletion entry carries only the permanent Outsider number. |
| Reports you file and reports about you, including creation, update and resolution times | So a concern can be answered and the decision can be audited. Whoever reported something is never shown to the person reported. On account deletion, direct account links and personal notes are removed where they point to the deleted person. The report reason, state, outcome, creation time, update time and resolution time remain as moderation evidence. An open report that can no longer be acted on is closed at the deletion time. |
| Session tokens, stored only as a SHA-256 hash | So you stay signed in. The token itself is never stored, so a database copy cannot be used to sign in as you. |
| Rate-limit records containing keyed one-way fingerprints for public email and IP checks, account IDs for signed-in actions, and room plus invited-account pairs for re-invite protection | To slow guessing, account abuse and repeated room invitations. Public door rows never store the raw email address or IP address, and a server-held secret prevents those fingerprints from being reversed or joined across different door flows. Signed-in counters are linked to the account and are removed when that account is deleted. A room re-invite pair is counted for seven days so a prior answer cannot be probed through repeated invitations. Expired counter rows are removed when that rate bucket is used again, so a dormant room re-invite row can remain longer than seven days. |
Who else sees any of it
| Who | What, and when |
|---|---|
| The company hosting this app and its database | Everything above, because it is stored on their infrastructure. Always. There is no version of this that does not have a host. |
| CARTO and OpenStreetMap | Your IP address, because that is how any request for a map tile works. Only on the map page, and only while it is open. |
| Shopify | The Shopify variant and quantity you chose plus one random checkout receipt. We send no Climber account ID, email address, Outsider number or referral code. Information you enter after Shopify checkout opens goes directly to Shopify under its own store checkout. Only when you ask this app to open a hosted Shopify checkout. |
| The original site for a learning Resource, such as YouTube, a publisher or a course provider | Your IP address and whatever that site normally receives from a browser request. We send no Climber identity or Learn progress with the link. Only after you explicitly open the original. Learn does not preload its video, thumbnail, player or page. |
| The meeting provider chosen for a live event | Your IP address and the audio, video, device or name you choose to give that provider. The Web Network sends no Learn data, messages or profile fields with the link. Only after you RSVP, the call window opens, and you explicitly press Join call. The Web Network records that the link opened, not that you attended. |
| The push service your device uses, which is Mozilla, Google or Apple | The address your own browser gave us, and a notification encrypted to keys only your device holds. They can see that something was sent to your device. They cannot read what is in it. Only while notifications are switched on, and only for the devices you switched them on for. |
| An email provider | Your email address, to send a confirmation or a password reset. Only when outbound email is configured. Where it is not, no email is sent at all and the app says so. |
What this app does not do
- No third-party analytics, no tracking pixel, no session recording, no advertising identifier and no visitor id. Page views are counted as daily totals on our own server, and nothing in a total can be traced back to a person. Nothing this app depends on reports your behaviour to anybody. The one dependency that ever leaves this server is web-push, and it only ever contacts the push service your own device chose, only while you have notifications switched on, and only when something you asked to be told about has happened.
- Fonts are served from this app rather than from Google, so loading a page tells Google nothing.
- Nothing you write is sold, and nothing you write is used to train a model.
- No location is ever read from your device. The city on your profile is one you typed.
- No data is bought about you from anybody.
Taking it all with you
Everything you wrote leaves as one file, in markdown or JSON, from your profile. You do not have to ask and you do not have to wait. That includes the journal, your perspectives and feed posts, the read, the pieces you own, which Learn Resources you saved or completed, and your Space membership history.
Deleting it
There is a delete control on your profile. It is not a deactivation and there is no drawer somewhere holding your account in case you change your mind. It removes your email, password, name, city, bio, journal, feed posts, intake answers, the reading built from them, and saved or completed learning state. Perspectives, answers, listings and messages are emptied and retired, including messages inside rooms other people are still in. Your room and Space memberships are closed.
A small pseudonymous record survives without your name, email or profile. Your Outsider number stays taken because it is never reissued. Earlier activity entries made by your account, and entries whose explicit identity fields point to it, lose their account attribution, subject and detail. Unrelated numbers in an operational entry are not treated as identity. One final deletion entry carries only that Outsider number.
If you were part of a Handshake, the other party keeps a minimum receipt. It shows the two permanent Outsider numbers, the final status and the retention date. Names, prices, terms, due dates, delivery notes, revision notes, dispute text and older receipt wording are removed. This keeps proof that the agreement existed without retaining what either person wrote. If you were only the introducer or canceller, your identity field is removed without erasing evidence owned by the two surviving parties. If you were a third-party dispute actor, the original account is replaced by the number-only record and the surviving parties keep their dispute evidence.
Moderation reports remain as evidence without direct links to the deleted account. Their reason, state, outcome, creation time, update time and resolution time remain. Personal notes tied to the deleted reporter, author or subject are removed. If deletion closes an open report that can no longer be acted on, its resolution time records when deletion closed it.
Anything you already exported, and any copy of a resource somebody else downloaded, cannot be recalled. That is true of every system and it is stated here rather than left out.
What is not private
Messages are stored in the database like everything else and are not end to end encrypted. Somebody with database access could read them. That is said plainly because the alternative is letting a dark interface imply a guarantee the software does not make.
Live calls are opened through an outside meeting provider. The Web Network controls the Space, schedule, RSVP and access check. The provider carries the audio and video after you press Join call.
Your journal is private to you. Nothing else in this app reads it and no model is run over it.
Children
This is not built for children and it is rated for thirteen and over. If you are under thirteen, do not make an account here.
Asking about any of this
Write to info@thewebnetwork.app. A question about your own data gets answered.