1. Draft status and responsible operator
This draft explains the observed product design and proposed safeguards. It is not a finalized privacy notice. The controller's identity, public contact details, processor/hosting locations, transfer arrangements and category-specific retention periods must be confirmed before activation.
2. Information handled by the service
Account information includes names, email addresses, phone numbers where supplied, password hashes, email-verification records and account status. Profile and relationship information includes public IDs, profile images, organization and department memberships, approval history and privacy choices.
Content includes publications, audiences, messages, message metadata, reactions, reports, support correspondence and applicable uploads. Security information may include IP addresses, device/browser information, session records, access logs and failed sign-in events.
Rating records currently include the evaluator and target identifiers, submitted score, scale, timestamps, application status, relevant eligibility information and calculation results. This internal information is not shown in the ordinary public rating display.
When legal acceptance is activated, evidence will include the account, document versions and content hashes, acceptance time, selected confirmations and a limited client label. The legal-acceptance record itself will not add an IP address; separate security systems may still handle IP addresses.
3. Why information is used
Information supports account access, verification, membership relationships, rating eligibility and limits, score calculations, content delivery, communications, support, abuse prevention and security. The final notice must identify the applicable legal basis for each purpose in the relevant jurisdictions.
Agreeing to Terms is not blanket consent to all data use. Optional processing that requires consent must be presented as a separate choice. Where consent is the legal basis, a withdrawal process and the consequences of withdrawal must be explained.
4. Visibility and rating confidentiality
Profile details and aggregate ratings may be visible to other participants according to the feature and settings. Organization representatives can access membership requests they manage. Publication audiences and messaging relationships determine normal access to shared content.
Other participants are not shown an itemized list of who rated a profile or what each person submitted. Delayed updates and general submission responses reduce the ability to connect a particular submission with a score change. They do not guarantee that inferences are impossible.
Internal rating records still exist. Authorized operational access, lawful disclosure or a security incident could expose information that is not public in the interface. CiThree does not promise that a database compromise could never reveal rating relationships or values. A proposal to remove or minimize this history is future work.
5. Messages, images and device storage
Text messages and message metadata are stored by the service. Chat images using device-to-device transfer are relayed through the service and retained in participating devices' local storage rather than maintained as durable server image files. Transfer and message metadata can remain on the server.
Other uploads, including publication images and support attachments, may be stored by the service. Do not assume every image follows the chat-image model. Clearing local storage or changing devices may remove access to device-stored images.
Recipients can retain copies independently. This notice does not claim that all messages are end-to-end encrypted or that deletion removes every recipient's copy.
6. Providers and disclosure
Hosting, network protection, email delivery and other providers may process information needed to operate CiThree. Organization representatives receive information needed for their membership responsibilities. Disclosures may also be necessary to address abuse, protect rights or comply with valid legal requirements.
The final notice must identify relevant provider categories and locations, international-transfer safeguards and any additional recipients. No claim of a particular data residency or certified security standard is made in this draft.
7. Storage, cookies and security
CiThree uses authentication cookies and browser/device storage for sessions, preferences and applicable offline functions. Device storage may also contain cached or transferred chat images. These functions should be distinguished from optional analytics or advertising tracking.
Security measures reduce risk but cannot guarantee absolute protection. Protect your device and account credentials. The final release must verify tracking technologies, provider access, backup protection and the handling of security incidents.
8. Retention and deletion
A finalized category-specific retention schedule has not yet been approved. The current system stores account, membership, rating, message and operational records; disabling or hiding information does not necessarily delete it. Backups may retain copies separately.
Before activation, publish necessary and proportionate retention periods or clear criteria for each category, including logs, pending and suppressed ratings, messages, uploads, consent evidence and backups. Do not promise automatic erasure that has not been implemented.
Preventing duplicate accounts or score resets does not by itself justify indefinite retention of every record. The proposed future rating-history minimization and identity-persistence designs require separate review and implementation.
9. Your requests and choices
Depending on applicable law, you may have rights to access, correct, delete, restrict or object to processing, withdraw consent or receive certain information in a portable form. Some requests have lawful exceptions, including protection of others' rights or necessary legal records.
A public email/contact route, identity-check procedure, response process and applicable complaint authority must be published before activation. Existing participants can currently send a request through Contact us. Lack of a self-service deletion or rating-reversal button does not remove applicable rights.
Information about a rating may also concern another person. Requests must be assessed with regard to both parties' rights; neither automatic disclosure of every evaluator nor automatic refusal of every request is promised.
10. Changes to this notice
Material changes to data handling will be described clearly before they apply where required, including changes to rating-history storage. A new notice version will be published and separate consent obtained where required. A future announcement must not be used to imply that unimplemented privacy protections already exist.