Trust & Privacy
Our System Sanctuary, LLC ("Our System Sanctuary," "we," "us," "our") was built because this community deserves a place that actually takes privacy seriously. This page tells you exactly what we collect, who can see it, and what we will and will not do with it. We wrote it to be read, not to be skimmed past. If something here is ever unclear, email us.
Our System Sanctuary is operated by Our System Sanctuary, LLC, a Florida limited liability company. The legal terms governing your use of the platform live on our Terms & Disclaimer page. This page is the companion to those terms. It is the human explanation of how we handle your data.
Who this is for
Our System Sanctuary is open to people who are 13 and older, and the experience is tailored to age. Adults (anyone 18 and older) have the full platform. Younger members, 13 to 17, have a more private, system-focused version designed for them, and the privacy details that apply to a younger member are written plainly in the version of this page shown inside their own account. Those accounts start with the most private settings already on, and the most sensitive tracking, such as health conditions, turned off entirely.
People under 13 cannot create an account, and we do not knowingly collect their information. If we ever discover an account belongs to someone under 13, we will close it and delete the data.
What we store
Everything you create here belongs to you: your journal entries, your members, your front log, internal weather, identity history, supporter connections, settings, and any media you attach. That is the personal content you make; the account, security, and optional details we keep are named one by one just below, so this section is the full picture of what we hold.
For your account itself, we store your email address and a one-way hash of your password. A hash means we never store the actual password. Not us, and not anyone who might ever access our database. This is how every responsible platform handles passwords, and we are not an exception.
We also store the birth month and year you give us when you join, or ask to join, along with a timestamp of when you gave it. We never ask for or keep the day. This is the smallest amount of information that lets us confirm your age, which the law requires us to do, and it is kept as a quiet record that the requirement was met. Your age decides which version of the platform you get: adults (18 and older) have the full platform, and people who are 13 to 17 have the more private version made for them. If someone tells us they are under 13, we do not create an account or keep what they entered.
We do not collect your IP address for analytics, advertising, device fingerprinting, location tracking, or browsing history, and we never sell it. There are two places an IP is touched, both for security, and we want to name them plainly. First, our public sign-up and waitlist forms briefly use your IP and email for rate-limiting, and store only a one-way hash of them, never the raw values, described below. Second, our authentication provider, Supabase, records the IP address and device of each sign-in as part of running the login system itself. We do not display that IP to you or use it for anything: the Devices & Sessions screen in Settings shows you only the device (its browser and operating system) and when it was last active, which is enough to recognize a sign-in you do not, and sign it out. By default we never show your location. You can optionally turn on an approximate location for your own devices on that screen; if you do, we work out a rough city or region from each sign-in's network location through our host (no outside location service), store only that short text for your own eyes, share it with no one, and delete it the moment you turn it off. It is off unless you choose it, we record your acknowledgment when you turn it on, and it is not offered to younger members. No other user can ever see any of this.
How we protect your data
Everything stored in our database is encrypted at rest by our infrastructure provider, Supabase, using AES-256, the same standard financial institutions use. Every connection between you and the app travels over HTTPS/TLS.
On top of that encryption, every table in our database has row-level security enabled. This is a second layer of protection, applied throughout the entire platform, that gates every row to your account ID at the database level. It means no other user can reach your data, even if they tried, and it stays on for every table we have, with no exceptions.
We do not use end-to-end encryption right now. We thought carefully about this. The trade-off, where losing your password would mean losing everything forever, is not safe for a community where dissociative amnesia is part of real life. We chose recovery over zero-knowledge for this version. If the community wants us to revisit that, we will.
Paper pages (photos of your handwriting)
Some pages you keep on paper. Paper Pages lets you photograph one you have filled in by hand and keep it here alongside everything else. A handwritten page is often the most personal thing a person keeps in a private space, so it gets the most careful handling we can give it.
Your paper pages are private to your account. They are not shown to supporters or connections, they are never posted anywhere, and they live in a private storage area that no public link can reach. The image travels encrypted over HTTPS/TLS and, like everything else here, is encrypted at rest by Supabase. It is shown back to you only through a link that is generated fresh each time you open a page and expires within about a minute.
The promise that matters most, and one we built into the app so it cannot quietly change, is this: your paper pages are never read by any AI, and never run through text recognition, handwriting recognition, or any analysis of what the page shows. The app keeps your photo exactly as you took it. It does not look at what you wrote. The only automated step is a malware scan of the file itself before it can be opened, which checks for harmful code, not your handwriting.
Your paper pages are included when you export your data, and they are removed, both the record and the image file, when you delete your account. Two honest limits: this is the same infrastructure encryption described above, not zero-knowledge, so the narrow access rules in "When we access your data" apply here too; and because you can open your own pages, the app cannot stop you from taking a screenshot or saving a copy yourself.
Who can see your data
Other members of the community can only see what you choose to share. Your display name appears alongside anything you post in community spaces. Your members, journals, front log, and everything else in your account are never visible to anyone else. The only way another person sees something is if you post it publicly or share it with a supporter you have explicitly invited.
Supporters you invite see only what you grant them. By default they see nothing. You decide what each supporter can access, down to individual categories, in Settings.
As for us, we have the technical ability to query the database, the same as any web application developer. The section below is specific about when and why we would ever use that ability.
As for anyone else, there are no advertisers, no data brokers, no analytics companies. The narrow exceptions are the AI and infrastructure services described below, each in their own section.
When we access your data
We do not read your journals or your personal information. Not out of curiosity, not for marketing, not to improve our product, not for AI training, not for any reason we have not listed here.
The only times we would look at your account data:
- You asked us to. If you reach out for help with a bug or a recovery situation and we agree together on what we need to look at.
- We are legally required to. A valid court order or subpoena. We will tell you if we are legally allowed to.
- A security incident. If we need to verify that nothing was tampered with during a breach, we look at metadata like timestamps and row counts, never your content.
We will tell you if any of these happen. If you would prefer we never access your account under any circumstances, email us and we will mark your account with a never-access flag. That flag is a real record, not a mental note: it is stored on your account with a timestamp, every change to it is logged, our admin tools show it anywhere your account can be looked up, and you can see it yourself in Settings under Export. Honoring it may mean we cannot help you recover access if something goes wrong, and that trade-off is yours to make.
What we will never do
- We will not sell your data. Not now, not ever, not to advertisers, data brokers, researchers, or anyone else.
- We will not share your information for advertising, profiling, or behavioral targeting.
- We will not use your data to train AI models. The AI Insights features run only on demand, only on data you have consented to share, one member at a time.
- We will not use third-party analytics trackers. No Google Analytics, no Meta Pixel, no session recording tools.
- We will never require you to use your real name or provide any real-world identifier.
Keeping bots out
Our public sign-up and waitlist forms use Cloudflare Turnstile to stop automated abuse. Cloudflare represents that Turnstile works without tracking cookies and without profiling people. You can read their privacy practices at cloudflare.com/privacypolicy.
Those forms are also rate-limited. To make that work, the form briefly looks at your IP address and email to detect when the same source is submitting over and over. Only a one-way hash of those values is stored, never the raw values, and only long enough to catch abuse patterns. This happens only on logged-out public forms, never once you are signed in, and never for analytics.
AI Insights and your data
The AI Insights features (BlackoutBridge, Daily System Digest, What Did I Miss, and Our Recent Days) are optional. None of them run without your consent, and every member of your system chooses individually whether to take part. A feature includes only the members who have turned it on, so a summary can be partial, which is by design. Any member can also opt out of AI entirely: when they do, they are never included in any feature, even in a shared or co-fronted entry where someone else was the main fronter. One honest limit to know: because shared notes can mention other people, a member who is included can still name someone else in passing. We never send a row that belongs to a member who has opted out, but we cannot promise a member's name will never appear inside another member's note.
When you run one of these features, a specific, limited set of your data is sent to Google Cloud's AI service to generate the summary or message. Here is exactly what that includes:
- Who was fronting, when, and any mood or context notes from those front log entries
- Journal entry titles and dates, never the body of any entry
- Entries you have marked private are flagged as such, and only the title is passed along
- For BlackoutBridge specifically: the full text of internal messages to the returning member, up to the 20 most recent
The body of any journal entry is never sent. Anything belonging to a member who has not consented is never sent.
What Google does with that data:
Google contractually guarantees your data is never used to train its AI models. That protection has no exceptions based on what the content is. Google holds inputs for up to 24 hours for performance purposes, then deletes them.
There is one narrow exception to that 24-hour deletion. If Google's automated systems flag something as a possible violation of its usage rules, that content may be held for up to 90 days while Google reviews it, and even then it is never used for training. Those rules are about things like illegal activity, content that helps someone harm other people, hate, and harassment. They are not about someone honestly describing their own experience, their distress, or what they are living through. There is no secret list of trigger words. The check looks at whether content appears to break those rules, not at any single phrase. You can read exactly what they cover in Google's Generative AI Prohibited Use Policy. This kind of review is rare, and it has nothing to do with you personally.
We do not store the AI's output on our servers. The summary is generated, returned to you, and not saved.
These retention windows reflect Google's policies at the time this page was last updated. They may change. Current details are always at policies.google.com/privacy.
The first time you use any AI Insights feature, and again any time the disclosure or provider changes, you will be asked to confirm what gets shared. Nothing is sent until you do. Every acceptance is recorded with the exact text you saw, the version, the provider, and the timestamp. You can ask us to show you your consent history at any time.
For Our Recent Days exports, only the date range and export date are stored on our servers. The summary itself is never saved. Regenerating an export always produces a fresh result from your current data.
Learn Hub search
When you search in the Learn Hub, only the words you type go to Google Cloud's AI service (Vertex AI), the same service behind our AI Insights features. Nothing from your system, your journals, or your account is included. Google does not use this data to train its models, and holds inputs for up to 24 hours for performance purposes, then deletes them. Details at policies.google.com/privacy.
Community posts and moderation
The things you share in the open community, your posts, comments, polls, and room names, pass through an automated safety check before anyone else can see them. That check sends the text to Google's Vertex AI, the same service behind our AI Insights, which reads it and returns a verdict. Google does not train on it, and deletes it within 24 hours unless their automated systems flag it for review.
Almost everything passes and appears immediately. If the check flags something, it stays visible only to you while a person reviews it; you see it marked, you can appeal from right there, and anything cleared in review appears on its own. Every removal decision is made by a person, not the machine. If the check itself is ever down, content publishes normally and is flagged for a human look afterward, so an outage never freezes the community.
Private group chats are not run through this check. What you say in a group chat stays between the people in it.
The same is true of direct messages and supporter messages: the wording of your private messages is never run through any automated text check. No person and no AI reads them.
Files and attachments are handled separately from message text. Anything you upload may be automatically scanned or reviewed for security and safety, and where we believe it is necessary or the law requires, we may remove, block, or report it. This is a check on the file itself, never a reading of your words. We do not use your attachments for advertising or AI training. No automated check catches everything, so we cannot guarantee a file is safe, and we ask you to open and download files with normal care.
Posts about active suicidal thoughts or crisis feelings are never flagged. This community needs to be able to speak openly about those experiences, and we built the system with that as a non-negotiable. We tested it specifically to make sure a post reaching out in a dark moment is left for the community to hold, not hidden.
There are also two community-driven protections: if enough established members report the same post within 24 hours, or if a member reports something that the filter has also flagged, the post is temporarily hidden while we take a look. This is a hold, not a strike. Reports from accounts younger than 7 days do not count toward that threshold. An account cannot report its own post, and switching members does not let the same account report twice.
Every moderation decision is reviewable and appealable in-app. A strike only counts when we confirm a removal, not when something is flagged or reported.
Files, images, and links you share
When you add an image, a file, or a link somewhere it can reach other people, the community feed, a room, a direct or group message, or an attachment a supporter can see, we may run automated safety checks on it. These are behind-the-scenes checks on the file itself, not a person reading your content.
Depending on what you share, those checks may include: files scanned for viruses and malware; images screened for clearly explicit content so it never appears in front of someone unexpectedly; links checked against known lists of dangerous websites; and images checked, using one-way digital fingerprints, against known databases of illegal child sexual abuse material. The fingerprint check works without the image being readable or kept by the safety service. These checks may change or pause over time, and no automated check is perfect, so please treat them as a safety net rather than a guarantee.
What is deliberately never checked this way: your journals, your scanned paper pages, and letters and messages between members of your own system. Those spaces belong to you alone, and scanning them would mean the check running the moment you open your own private writing, which is not a thing we are willing to build. If that policy ever changes, this page will say so before it does.
One check is not optional for anyone: if illegal child sexual abuse material is detected or reported in a shared space, the law requires us to preserve it and report it to the National Center for Missing & Exploited Children, and we will. If something you shared is blocked and you think that was a mistake, reach out through the Feedback page and a real person will look.
Health and medical information
We treat everything health-related in your account as sensitive personal data. That includes mood, internal weather, triggers, medications, conditions, diagnoses, and any AI-generated summaries you choose to share with a clinician.
We do not sell, share, license, rent, or aggregate any of this with anyone, including advertisers, data brokers, researchers, insurers, and AI companies.
The only times health-adjacent data leaves our servers are the narrow opt-in cases already described: when you choose to run an AI Insights feature on data you have consented to share, or when you type a search into the Learn Hub.
Our System Sanctuary is not a HIPAA-covered entity and is not a substitute for clinical care. If you share an export with a therapist or other provider, that is a handoff between you and them. We have no relationship with your provider and never receive anything back.
The Health Conditions feature stores diagnosis labels, dates, severity ratings, triggers, symptoms, physician names, medications, and free-text notes. This data is encrypted at rest, gated to your account by row-level security, and treated the same as everything else when it comes to export and deletion. Entries you mark private to a specific member are readable only while that member is fronting, and this is enforced at the database level.
One important thing to know: because this data lives behind your login, it is not accessible to a first responder who picks up your phone, or to anyone without your credentials. If you want health information available in an emergency without authentication, iPhone Medical ID, Android Emergency Info, or a MedicAlert bracelet are the right tools for that. This platform is not designed for that purpose.
What we read, and what we do not
The rule is one sentence: we machine-read words only where a stranger can encounter them, and we scan every image everywhere.
Words in the shared feed and in public rooms are checked by an automated system before they become visible. That check is automatic and takes seconds, not a queue somebody works through: a post that passes is visible immediately, and only a post the check flags is held back, in which case its author is told straight away and can ask us to look again. Words in private places are not read by us at all: not direct messages, not group conversations, not private rooms, not letters. The one exception is a supporter conversation between an adult and a 13 to 17 year old, which is screened in both directions and which both people have to accept before either can write.
Images are different, and we want to be honest about why. Every image is scanned wherever it is sent, including in private messages between adults, for malware, for known child sexual abuse material, and for sexually explicit content. The reason is specific to this community rather than general caution: in a system, the member who opens a message is not always the member the relationship is with. Two adults can agree between themselves to send explicit images, and neither of them can agree on behalf of whoever happens to be fronting when it arrives. If an image is refused, nothing is reported anywhere and nobody is accused; it simply cannot be sent here.
Your rights under the FTC Health Breach Notification Rule
Because we store health-related information you enter, we are subject to the FTC's Health Breach Notification Rule. If a breach ever affects your health data, meaning someone accessed, acquired, or disclosed it without authorization, we will notify you within 60 days of discovering it. Breaches affecting 500 or more users also require us to notify the FTC. Any notification will tell you what was affected, who may have accessed it, and what you can do.
The other services that touch your data
- Supabase stores your data and handles authentication. supabase.com/privacy.
- Vercel hosts the application. vercel.com/legal/privacy-policy.
- Resend delivers transactional emails like account confirmations and password resets. Your email address is processed for delivery only. resend.com/legal/privacy-policy.
- PluralKit syncs member and front data when you choose to connect your PluralKit account, through their API using an access token you provide. That token is stored in encrypted secret storage. We do not share anything with PluralKit beyond what the sync you initiate requires. pluralkit.me/privacy.
- Cloudflare handles bot prevention on our public forms as described above. cloudflare.com/privacypolicy.
- Sentry monitors the application for errors. It is configured to receive no personally identifiable information. Error reports contain only technical diagnostic data like error type, stack trace, and browser environment. sentry.io/privacy.
- Backblaze stores our nightly disaster-recovery backups. Every copy is encrypted before it leaves our systems, with a key Backblaze never has, so what they hold is unreadable to them or to anyone who reached their servers. Copies are kept for 90 days and then roll off automatically. backblaze.com/company/policy/privacy.
When you delete your account
Deleting your account starts a 10-day grace period. You can cancel the deletion any time during that window. After it closes, your personal data is removed from our active database.
Backups take a little longer. Our database provider, Supabase, keeps encrypted backups for up to 7 days, and our own encrypted disaster-recovery copies are kept for up to 90 days before rolling off automatically. Backups are only ever used to bring the whole platform back after a disaster, never to look up or restore an individual account. Once the 90-day window has passed, your data is unrecoverable by anyone, including us.
Posts and messages you made in community spaces become a [deleted] placeholder after your account closes, so threads do not break. If you want those removed too, let us know before you delete your account.
One small exception, kept for legal reasons: we retain a minimal record that you agreed to our Terms and attested your age, meaning the version you accepted and the date, for up to 7 years after deletion. Nothing else: no journals, no members, no health information, no posts. We keep only this proof of agreement so we can comply with the law and defend a claim if one is ever made about an account. It is never used for anything else.
If this place ever had to close
This community has watched more than one home disappear with little warning. So this deserves to be said plainly, even though the plan is for it never to matter.
Our System Sanctuary is not for sale, and there is no plan to walk away from it. But if something ever made it impossible for the person running it to continue, here is the commitment:
- You would get real notice, measured in months, not days, in the app and by email.
- Your one-click export (in Settings) would stay available the entire time, so every system could take a complete copy of everything: entries, members, messages, and the actual image files.
- Stewardship would only ever pass to someone willing and able to carry both the running costs and the legal responsibility, and only someone the community could trust. Any successor would be bound by the promises on this page before any handover, and you would be told before it happened, with time to export or delete your account first.
- If no trustworthy successor existed, Our System Sanctuary would close gently: notice, a long export window, and then deletion. Never a sale of your data, and never a quiet disappearance.
If you are 13 to 17: your data
A younger account carries exactly three extra facts, and nothing else: a flag that the account belongs to someone 13 to 17 (worked out from the birth month and year you attested at signup), the U.S. state you told us you live in, and, in the four states that legally require it, a single record that a guardian consented to the community feed. That is the whole list.
We want to be clear that this is not our idea. Four U.S. states have passed laws requiring a parent or guardian to consent before someone under 18 can use a social platform, and we are required to follow them for people who live there. We do not think a guardian should control whether a system can find other systems, and if those laws changed tomorrow this requirement would go with them. What we can control is how little the requirement costs you, so we ask for one recorded fact and nothing more.
The state you live in exists only so we know which state laws apply to your community access. It never appears on your profile or anywhere anyone can see it. The guardian consent record is one fact with a date; it does not create an account for anyone, and it gives no one, including the guardian, any way to see your members, your journals, your messages, or anything else you write. There is no parent portal here and there never will be.
If your state requires that okay, you choose whether and when to ask for it: from your dashboard you can have us email a guardian a short signed form, and we send it exactly once per ask, only because you asked, with no reminders ever. The form shows them only the name you go by here. A guardian can withdraw their okay at any time by emailing us, and if you can’t safely involve a guardian, everything outside the shared community stays fully yours.
Everything else works exactly as it does for adults: your private space is yours alone, your data is never sold or used for advertising, no AI trains on your words, and deleting your account deletes all of it, the three extra facts included. When you turn 18, the account opens up on its own and the minor flag simply stops being true; we do not keep a history of it.
One conversation is checked, and only one. If a younger member messages a supporter who is an adult, that thread is screened before messages arrive, in both directions: the text through the same Google service the rest of the site uses, and photographs for nudity and other explicit content. Both people are shown exactly what is checked and have to accept it before either can write, and that acceptance is recorded. Distress is never what stops a message: talking about trauma, abuse, self-harm, or suicidal feelings always reaches the supporter untouched, because that is what the conversation exists for. The check looks for an adult behaving toward a young person in ways an adult should not, and nothing else. It is not reported to a guardian, and no other private conversation on this platform, at any age, is screened.
Supporters
A supporter account is its own separate, limited account. It sees only what you have chosen to share, nothing more. It has no system of its own, no dashboard, and no access to community spaces.
You control what each supporter sees, per category, in Settings. You can also choose to notify a supporter when a specific member starts fronting. That sends the member's name and their optional note to the supporter in-app and, if they have push notifications on, to their device. It is opt-in for both of you, never includes journal or private content, and stops the moment you turn it off or remove them.
Using the Emergency Override on a sealed entry logs that action in your activity feed. Every access is auditable.
Your rights
You can ask us to let you see the data we hold about you, correct anything inaccurate, export everything, delete your account, or withdraw AI consent for any member at any time. Email privacy@oursystemsanctuary.com and we will respond within 30 days.
Security
The core technical protections, encryption at rest and in transit and row-level security on every table, are described in “How we protect your data” above. Two more pieces of the posture are worth naming plainly. First, the platform carries an automated enforcement test suite that re-checks the database’s privacy and permission rules on every code change before it can ship, so a change that would weaken those rules fails loudly instead of slipping through. Second, there are no third-party analytics or tracking scripts anywhere on the platform, which keeps the surface an attacker could reach deliberately small.
If you find a security issue, email admin@oursystemsanctuary.com and it goes to the front of the line. You will hear back within a few days, usually much faster.
If this page changes
We will notify you in-app before any change that affects what we can see or do with your data. For anything material, we will ask you to acknowledge the update before you continue using the platform.