Private means private.
The room belongs to the organization. Not to us, and not to anybody selling to your members.
Only authorized members enter the room. Nobody finds their way in from outside.
Roles decide what each member can reach, and individual items can be marked staff-only.
The room belongs to the organization. There is no advertising in it.
Privacy is part of the product. Member information is never sold.
How access works
The administrator controls who is in the room and what each role can reach.
They invite people, set roles, write the room rules and can remove access instantly.
Items marked staff-only do not appear for members. Staff see everything their role allows.
Hand one person a single permission without making them an administrator.
Every acknowledgment is stamped against the exact version of the rules that person accepted.
A room can hold member posts for staff review before they appear at all.
Staff can delete anything, members can report feed posts, and it is on the record.
Three layers, and what each one actually does.
In transit
Every connection between a member’s device and the room runs over TLS. Somebody on hotel or airport wifi cannot read it off the network.
At rest, by Cloudflare
Stored data is encrypted at rest on Cloudflare’s infrastructure, files with AES-256 in GCM mode under Cloudflare-managed keys.
Message content, encrypted by us
On top of that, the words people write in a room — board posts, private messages, alerts, notes and task detail — are encrypted by this platform before they are written to the database, using AES-256-GCM with a key we hold separately. Somebody who obtained a copy of the stored data without that key would read ciphertext, not messages.
What that does not mean. It is not end-to-end encryption, and it does not put your room beyond our reach. Staff access for moderation, a misconduct report or a lawful request still works, and it is recorded in an append-only log. Files and photographs currently rely on Cloudflare’s encryption at rest rather than this additional layer.
What we will not do
We describe only what the product does today. If a capability is not listed here, we have not claimed it.
Questions about privacy?
Email [email protected], or read the privacy policy and terms.