Private-data policy · 26 July 2026

Private intelligence needs stricter rules.

This policy states the current controls and the limits. Shared client access is interim; individual accounts, roles and multi-factor authentication remain an open System Health requirement.

01CLIENT DATA

Who can see it

Authorised OTR operators and the client room’s authenticated users. Client information is not published in the public feed.

02CLIENT DATA

Where it is stored

Client outcomes and notes are stored in the site’s protected database. Private responses are marked no-store and noindex.

03CLIENT DATA

How long it is kept

For the client relationship plus 90 days, unless a signed agreement or legal duty sets another period.

04CLIENT DATA

AI and model training

Private client data may be processed only for the client’s requested OTR service. It does not enter the public release, a shared client-learning pool or foundation-model training.

05CLIENT DATA

Separation

One client’s private information cannot change another client’s feed. Client preference may change private relevance, never public facts or source quality.

06CLIENT DATA

Export, correction and deletion

Clients may request an export, correction or deletion. OTR records the request and confirms completion, subject to lawful retention duties.

07CLIENT DATA

Security incidents

OTR will contain the issue, preserve an audit record, assess affected data and notify affected clients without unreasonable delay.

Control

Ask for your data.

Email onthericeuniverse@gmail.com with the client room and request type. Identity will be checked before action.

Read the simple processing agreementInspect open security work