Every conversation belongs to a membership at one club. No query shape reaches another club's rows, and no club can learn which other clubs a member belongs to. Enforced by tests that fail the build.
No self-service signup anywhere. Members hold no password — a six-digit code, ten minutes, one use, bound to the browser that asked. Removing a staff assignment revokes their sessions at once.
Grounded in your knowledge only; everything it reads is fenced from its instructions. It writes nothing into any club system today. No model is trained on your data. It hands off to your staff rather than guessing.
No passwords, no payment details, no member email or phone sent to the model. Append-only audit on every staff and operator action. Conversations age out 12 months after a membership ends.
3 named operators, read-only, audited. A dedicated instance — your own database and keys — is available where that guarantee is required.
Review: a full adversarial review of the application on
4 September 2026 produced 34 findings —
3 high, 16 medium, 15 low. All
3 highs closed within three days, with 14
of 16 mediums and 12 of 15 lows.
Report available under NDA.
Subprocessors:
DigitalOcean, Anthropic, MailerSend, Google, and GitHub. No analytics, no
tracking, no advertising, no data brokers.
Backup keys: the queue replica and the nightly copy of your documents are
encrypted on our host, under keys we hold, before anything leaves it. The managed database
and the object storage holding uploads are encrypted at rest by DigitalOcean under its keys
— the same arrangement for handbooks as for transcripts.
Retention:
conversations 12 months, roster record, profile, preferences, push subscriptions 30 days, a member who asks to be deleted 7 days, inbound newsletter, raw 1 day, uploads archives offsite 30 days, document links 6 days, and audit events 7 years.
Breach notice: to the club within
72 hours of confirmation, as a term of service.