What we collect, and what we do not
Everything we collect
| What | When | Why | How long |
|---|---|---|---|
| Your email address | Only if you enter it — newsletter, waitlist, notify list, or asking for a tool result | To send you the thing you asked for | Until you ask us to delete it, or you unsubscribe |
| Your name and message | When you use the contact or booking form | So a person can reply to you properly | Two years, then deleted, unless we are still working together |
| Tool answers | While you use a tool | To produce your result | Not stored at all, unless you ask us to email you a copy |
| Aggregate page counts | Only if privacy-preserving analytics are switched on | To know which pages are worth improving | Aggregate only. No cookie, no profile, no cross-site tracking |
There is no advertising pixel on this site, no cross-site tracker, no behavioural profile, and no data sold, rented, traded or shared with anyone for their own purposes.
What reaches a model, and what does not
Never calls a model
- Crop Planner
- Time and Capacity Calculator
- Rooted AI Workflow Builder
- Heirloom Shield Scanner
- Heirloom Shield Self-Assessment
- Community Resource Navigator
These run entirely on fixed rules. Nothing you type is sent anywhere.
Sends text to a model provider
- AI Opportunity Map
- Land Access Navigator
- Community Organizing Tool
- Sovereign System Builder
Only the answers you typed, and only for the written-guidance section. The request is made by our server, never your browser, and carries no name, no email and no identifier. We do not keep it after your result is returned.
We screen before we send
Before anything leaves our server we check it for things that should never be in an AI tool — Social Security numbers, card numbers, account and routing numbers, credentials. If we find one, we stop, send nothing, and tell you. That check runs whether or not you were paying attention, because everyone pastes something they should not eventually.
What you have allowed, and what you have not
Loading your settings from this device…
Every measurement this site can take
What is counted
tool_started— tooltool_step_completed— tool, steptool_completed— tooltool_restarted— tooltool_draft_restored— toolresult_printed— toolresult_copied— toolresult_downloaded— toolhandoff_followed— tool, toworkflow_refused— toolask_praxis_asked—ask_praxis_routed— togovernance_center_viewed—policy_started—policy_draft_generated—policy_sent_for_review—policy_approved—policy_version_published—policy_acknowledged—tool_review_requested—tool_approved—training_assigned—exception_requested—governance_review_completed—incident_reported—academy_path_started—practice_started—evidence_submitted—evidence_revision_requested—competency_verified—project_started—project_completed—passport_viewed—passport_exported—pathway_completed—lab_need_submitted—lab_feasibility_completed—lab_governance_reviewed—lab_project_approved—lab_builder_interest—lab_team_formed—lab_project_started—lab_milestone_completed—lab_community_test_started—lab_handoff_completed—lab_project_completed—lab_project_credential_issued—venture_candidate_created—validation_experiment_started—validation_experiment_completed—repeat_demand_recorded—ownership_review_started—venture_readiness_reviewed—spinout_decision_recorded—
Every one of these is a fact about the software: that a tool was opened, advanced, finished, or exported. None of them is a fact about you.
What is never counted
- Any answer given to any question, in any form
- The result itself — the risk level, the ladder level, the estimate, the headline
- Anything typed into a free-text field
- An email address, or anything derived from one
- Which sensitive categories somebody selected
- Anything that would let two visits be recognised as the same person
The second one is the one worth arguing about. Knowing how many scans come back red would genuinely help us build better tools — and it would also mean recording that a particular visitor was handling something they had to be careful with. We would rather not know.
What you should never submit
- Social Security or tax identifiers
- Card, bank or account numbers
- Passwords, keys or credentials
- Health information
- Immigration or citizenship status
- Someone else's personal details
- Case notes or incident reports
- Anything told to you in confidence
- Unpublished cultural or community knowledge
- Anything you would not want read aloud
The honest part
Where we are not sovereign
We teach data sovereignty, so we should be straight about our own position: this website runs on commercial cloud infrastructure. The hosting, the database and any model provider are all third-party companies operating under their own terms, in their own jurisdictions, subject to legal process we do not control.
That is not sovereign architecture and we will not describe it as such. What we have done is reduce the surface: collect little, retain briefly, keep the tools deterministic where we can, screen before sending, and make deletion genuinely easy. Those are meaningful and they are not the same as independence.
Community-owned compute and self-hosted models are a real long-term direction. They are not what this site currently is, and telling you otherwise would fail the first test we ask everyone else to pass.
Your rights, in practice
- Ask what we hold about you — we will tell you within thirty days
- Ask for a copy in a format you can actually use
- Ask us to delete it — we will, and confirm when it is done
- Unsubscribe from anything in one click, with no retention flow
Write to privacy@heirloompraxis.com. No form, no account, no justification required.
