Skip to content
PRIVACY

What we keep, who processes it, and when raw text is cleared.

Forum 360 is an annual anonymous 360 for confidential peer groups — the EO/YPO kind of forum, not a public message board. This page is the short version. The mechanical proof is on the security page.

What this product is

A private forum (a small, confidential peer group) runs one 360 a year. Every member reviews every member. Comments are reworded by AI to reduce phrasing and identifying details, then combined across reviewers into a personal report for each member and a shared forum-health report for the group.

Why we use this information

Account and roster details connect the right person to the right forum. Drafts and ratings let members complete their reviews and let the restricted processing service build reports. Completion status powers reminders and the organizer’s progress view. Billing records manage annual credits, renewals, and refunds. Limited analytics help us understand public-page use and whether product actions succeed; they are not a record of what anyone wrote.

What we collect

The organizer’s account, the roster they paste (names, emails, optional phone numbers for reminders), magic-link sign-in, completion checkmarks, and the answers members type while a cycle is open. Billing name, address, and payment details are collected by Stripe, not stored as card numbers on our side.

Raw answers don’t survive successful processing

While a cycle is open, a member can read and edit their own drafts through authenticated app routes. Database grants prevent signed-in browser sessions from selecting raw-answer columns directly. Narrow server-side draft readers return only the signed-in author’s own text; organizers and other members do not get a raw-answer reader.

The privileged report worker sends submitted raw text through Vercel AI Gateway to Anthropic for rewording. After Anthropic returns a successful result through the gateway, Forum 360 stores the paraphrase and clears that row’s raw text in the same database update. If processing or that update fails, the raw text remains protected and is excluded from report generation in that run. Transient failures can be retried. A permanent size failure is quarantined instead of retried indefinitely; the author can correct it before release. The quarantined source is not cleared until successful processing or an authorized deletion. Unsubmitted drafts are not cleared by that report-generation step.

AI rewording

Forum 360 sends every AI request through Vercel AI Gateway to Anthropic, the current inference host. Those requests include draft text used to suggest optional follow-up questions during the interview, submitted raw answers and answered follow-ups used to produce paraphrases, and the paraphrases, scores, and aggregate context used to draft reports. Report-writing does not need the original wording. Forum 360 does not use answers to train its own models and does not send feedback or report content to Stripe, Resend, Twilio, PostHog, or Vercel Analytics.

Who can see what

Members see their own released personal report and the shared forum-health report — never anyone else’s private report, and never displayed attribution. Organizer controls expose completion status and, after release, sanitized score history — never raw or per-giver feedback. An organizer who also participates receives the same private personal report and shared report as every other member. If fewer than 3 members review someone, we show an insufficient-feedback notice rather than a personal feedback report.

Billing

Payments run through Stripe on Folly’s account, tagged so Forum 360 stays isolated from other products. Stripe gets billing identity and forum metadata. It does not get answers, reports, or roster feedback.

Service providers

Supabase provides authentication, the database, and private report-file storage. Vercel hosts and runs the application, and AI request content passes through Vercel AI Gateway. Anthropic is the current inference host and processes the feedback described above. Resend receives the names, email addresses, forum status, and personal app links needed for transactional email. Twilio receives a phone number and reminder content only when SMS reminders are enabled for that member. Stripe processes billing identity and forum billing metadata.

PostHog is configured without autocapture, session recording, or form capture; Forum 360 sends limited public-page and named product-event analytics with scrubbed properties. Browser analytics does not identify an account. Persistence is disabled, and Forum 360 explicitly expires the project-scoped PostHog cookie and browser-storage entries used by the earlier configuration before PostHog starts. Vercel Analytics also receives basic site-usage data. Member avatars are generated locally from initials and do not trigger an email-based avatar lookup.

Interview reliability measurements use only section types, outcome categories, and coarse duration ranges for the current visit. They exclude answer text, error messages, URLs, and member, forum, or cycle identifiers. Each measurement has a new random event identity rather than a persistent member identity. These counts do not reconstruct a person’s complete interview across visits. Vercel pageview analytics is limited to public pages with query strings removed. Analytics providers can still receive ordinary network metadata needed to accept a request; their operational retention is separate from browser persistence.

What we don’t do

We don’t sell data. We don’t run ads. We don’t put your forum on a public board. The providers above process only the data needed for their part of the service. Data is encrypted in transit and at rest. You can ask us to delete a forum or account at support@forum360.app. Released reports stay until you ask us to remove that forum’s history — canceling billing does not wipe them.

Questions

To ask about access, correction, deletion, or the handling of your personal information, email the support address below. Do not include feedback text or private reports in the initial message. Tell us which request you want to make; we can arrange an identity-verified follow-up without exposing another member’s information.

The longer, forensic version is How we protect you. Email support@forum360.app for anything this page doesn’t cover.

← Back to Forum 360 · Privacy · Terms · How we protect you · support@forum360.app