Policies

Privacy notice

The complete privacy notice for the hub, versioned and dated. If anything here is unclear, that is a defect — tell us in support.

Version 2026.7 · effective 09/07/2026

Who is responsible

Perspectives Plus Research LLC operates the Perspectives+ hub and decides how hub data is handled. This notice covers the hub. Where a separate P+ app is available it says what it collects in its own notice.

What we store

Your account email and profile (display name, optional pronouns and affiliation, accessibility notes), your saved apps and their order, your hub activity, the suggestions and submissions you create with their attachments, your support tickets and attachments, your notification preferences, your guidance level, and records of the exact policy versions you accepted.

What we do not store

We do not record what you do inside another P+ app unless a verified integration exists and you can see it labelled as connected. We do not collect payment data in this hub, we do not sell data, and we do not run advertising trackers or third-party analytics scripts.

Why we use it

To give you an account and a launcher, to run review of what you send, to answer your support messages, to keep the service secure and auditable, and to meet legal obligations. We do not use your content to make decisions about you by automated means.

Attachments and storage

Files you attach to a suggestion, submission, or ticket are stored in private buckets. They are never publicly reachable. Access happens through short-lived signed links, and only you and the authorised staff for that record can request one. File type and size are checked by the database, not only by the browser.

Staff access

Staff roles are least-privilege and enforced by database policy, not by hiding buttons. Reviewers see only the submissions assigned to them and never your account, billing, or support records. Every privileged action writes an immutable audit event recording who acted and what changed.

Cookies and local storage

We store your sign-in session and a small number of interface preferences in your browser. There are no advertising or cross-site tracking cookies. Signing out clears the session from this device.

Hosting and bot protection

The hub is served through Cloudflare, which delivers pages and protects the service from automated abuse. As part of that protection Cloudflare may set an essential security cookie, commonly named __cf_bm, and may process connection details such as your IP address to tell people from bots. This is a security function, not advertising or cross-site tracking, and it cannot be switched off without turning off the protection itself. Cloudflare sets the lifetime of its own security cookie and we do not state a retention period we cannot verify.

Email

Transactional email for verification and password reset is part of signing in. Notification email stays switched off until you authorise it in your notification preferences, and you can switch it off again at any time.

Retention

Account and workflow records are kept while your account is open. Support threads and status history stay with the record so decisions remain explainable. Audit events are immutable and keep the action, the actor, and the time — not your content.

Your choices and requests

You can view and correct your profile, see your recorded consent history, request an export of your hub records, and request permanent account deletion from My P+ privacy. Deletion is confirmed explicitly and retains only the minimum needed for audit and legal obligations.

Security

Access is enforced at the database with row-level security, privileged operations run through audited server-side functions, and secrets stay server-side. No system is perfect; if you find a weakness, report it through support rather than testing it against other members' data.

Cross-app activity from connected P+ apps

The hub can receive counted activity events from a P+ app once that app has been given its own server credential and has sent a verified event. Until then the app is shown as not connected and no events exist for it. A connected app may send only allowlisted event types: account created, account activated, session started, feature used, content created, content updated, content shared, subscription started, subscription cancelled, refund issued, support opened, support resolved, moderation decision, and access decision.

What a connected app may send, and what it may not

Each event carries the sending app, the time it happened, an idempotency key, the event type, the schema version, an optional pseudonymous subject key that is scoped to that one app, an optional staff flag, and a small set of allowlisted counting properties such as surface, content kind, plan tier, decision, reason code, duration bucket, quantity, currency, and amount in cents. Events may not carry your email, your name, your raw account identifier from another system, notebook or submission text, search terms, file names or links, tokens or secrets, card or payment details, IP address, or browser user agent. Anything outside the allowlist is rejected at the door and counted only as a rejection reason.

Source-scoped pseudonyms

A subject key is a pseudonym chosen by the sending app and meaningful only inside that app. The hub does not reverse it, does not join it to your hub account, and does not combine pseudonyms from different apps into one person. Unique counts are therefore reported per app and cannot be added together as unique people across the ecosystem.

Why we collect cross-app activity, and who can see it

The purpose is honest operational reporting: growth, activation, active and returning use, retention, content participation, subscriptions and refunds where an app reports them, support resolution, and moderation or access decisions. Only the Platform Owner and analytics-viewer staff can read the aggregated reports, and only the Platform Owner can create, rotate, or revoke an app credential. Raw events cannot be read or changed from any browser account.

Retention and deletion of cross-app events

Accepted events are append-only and cannot be edited. Rejection records keep only the sending app, the time, and the reason — never the payload. Because events carry no direct identifiers, deleting your hub account does not delete counted events in a sending app; ask that app to remove its own records. If you want a specific app's pseudonymous key removed, raise it in support and we will pass the request to that app.

Anonymous measurement of this hub

To keep the hub working we record a small amount of anonymous operational measurement. It uses a rotating anonymous session label held only in your browser tab, in session storage, so it is cleared when the tab closes and is never linked to your name or email. We record the page path without any query text, search terms, identifiers or file addresses; a coarse referrer category such as direct, internal, external, search, social or campaign, never the referring address; campaign labels (source, medium and campaign) when a link you followed carries them; a broad device category of mobile, tablet or desktop; which hub app-launch and community-open buttons you press, which records only that the hub sent you onwards; a single technical error category chosen from a short fixed list, with no error text; and page speed measurements together with online and offline status.

What anonymous measurement never collects

It never collects names, email addresses, message or notebook content, search text, full web addresses, query strings, referring addresses, attachment or file addresses, tokens or secrets, payment or card details, advertising identifiers, device fingerprints, or any cross-site tracking. Detail values outside the fixed technical lists are discarded by the database rather than stored. We do not sell or share this measurement and we do not use it for advertising.

Who can see anonymous measurement

Raw measurement records cannot be read, changed, or exported by any browser account. Only the Platform Owner and analytics-viewer staff can read the aggregated reports built from them.

Retention and deletion of anonymous measurement

Anonymous hub measurement carries no account identifier, so it is not linked to your account and an account-deletion request cannot select it. Instead, measurement rows older than 90 days and short-term rate records older than one day are removed by ingestion cleanup and by a service-only maintenance routine, so removal happens on the next cleanup after a record passes that age rather than at a fixed moment. Records that are linked to your account — your profile, submissions, ideas, support conversations, files and consent history — are handled through the privacy requests on your account page.

Changes to this notice

When this notice changes materially we publish a new version with its own version number and effective date, keep every earlier version as history, and ask you to accept the current version the next time you use My P+.