Privacy Policy

How SGUILD handles account, workspace, and security data

Privacy baseline

SGUILD is built for trusted coordination. That requires collecting enough information to operate accounts, protect the platform, preserve organizational records, and investigate abuse without treating user data casually.

Effective date: July 11, 2026

Information we collect

  • Account information such as name, email address, authentication method, profile image, organization memberships, roles, and account settings.
  • Workspace records such as charters, member registry fields, ranks, levels, positions, divisions, standing, invitations, messages, decisions, and related operational content you or your organization submit.
  • Security and audit data such as request identifiers, timestamps, action names, outcomes, device/browser information, approximate network metadata, and hashed IP signals used for abuse detection and incident review.
  • Contact information and message content when you submit the contact form or otherwise communicate with The Solar Guild.
  • Business Problem Session information such as your business name and type, contact details, the operational problem you choose to describe, usual availability, contact-confirmation or withdrawal state, a clarified problem, the disposition, the participant-facing next step, and the version and timestamp of your contact permission.
  • Organization proposal information such as the organization name and type, representative and contact details, the problem or desired result, available resources and review capacity, and any later-agreed scope, privacy, compensation, and stopping terms.
  • Work & Career Conversation information such as your name, contact details, broad area, current work stage, goal category, the question and optional context you submit, usual availability, request status, and the version and timestamp of contact or research permission you grant.

How we use information

  • To provide authentication, account workspaces, team membership, charters, registry features, administrative tools, and platform support.
  • To secure the platform, investigate suspicious activity, enforce access boundaries, troubleshoot errors, and maintain auditability.
  • To communicate with users about account access, security, operational updates, support requests, and important platform changes.
  • To improve reliability, usability, and product value for workers, employers, administrators, and other legitimate participants.
  • To email first, arrange a requested Business Problem Session only after the requester confirms, and deliver a written outcome.
  • To securely receive and review an organization proposal, assess fit, provide requested follow-up, and carry out an Objective only under its agreed scope and terms.
  • To review and arrange a requested Work & Career Conversation, prepare for the question submitted, send a receipt, and provide the requested follow-up.
  • Only with separate optional permission, to add broad Work & Career Conversation categories to restricted cohort counts after direct identifiers and free text have been removed.

Security and forensic records

The Solar Guild keeps audit and security records so administrators can understand what happened if accounts are abused, data is changed unexpectedly, or automated activity appears. IP addresses may be hashed before storage where practical. Some infrastructure providers may still process network data needed to route traffic, prevent abuse, and provide logs.

When information is shared

  • With infrastructure providers that host, authenticate, store, email, monitor, or secure the platform, such as database, hosting, email, payment, analytics, and security services.
  • Within your organization workspace according to account roles and permissions.
  • When necessary to comply with law, protect rights and safety, investigate abuse, enforce terms, or respond to valid legal process.
  • With your direction, consent, or configuration, such as when you invite members or connect third-party authentication providers.
  • Problem Session details are not published with your name or business identity without separate permission.
  • Good-faith private organization engagement is not converted into a surprise public campaign, case study, or employee-monitoring system. That privacy promise does not purchase silence or favorable findings: separate public-interest work requires separately supportable information, scope, evidence, response rights, and a publication decision, and does not repurpose private intake material. Disclosure may still be required by law.
  • Work & Career Conversation details are not shared with employers, candidate-matching services, or public audiences. Career support creates no candidate profile, employer-facing record, employer contact, matching service, or employer introduction.
  • Career research permission is optional and never controls access to the conversation. No person-level research responses or categories are retained long-term; restricted pseudonymous consent, lifecycle, and audit evidence may remain only for the periods stated below.

Retention

  • Workspace content is generally retained until deleted by authorized users, administrators, or account lifecycle rules.
  • Problem Session requests are retained while they are being reviewed or discussed and may then be deleted or de-identified when they are no longer needed for follow-up, integrity, or dispute handling.
  • Organization proposals and Objective records are retained only as needed for review, agreed work, security, follow-up, integrity, dispute handling, or the retention terms of an authorized workspace.
  • Work & Career Conversation contact details, free text, and other identity-bearing intake fields are scheduled for irreversible removal from the active request record at 180 days.
  • The remaining Work & Career Conversation consent and lifecycle record is scheduled for deletion at three years. It is treated as restricted pseudonymous evidence, not described as anonymous.
  • If optional career-research permission remains active at the 180-day boundary, only broad category counts may be retained long-term. The retained aggregate has no name, contact detail, free text, exact date, person-level row, request identifier, or identity crosswalk.
  • Long-term aggregate research remains restricted and is reviewed periodically for utility and re-identification risk. A cell must contain at least ten request submissions before it can be considered for public or partner-facing reporting; this threshold does not establish ten distinct people or guarantee anonymity, and every disclosure still requires review.
  • Operational request and abuse-detection events are scheduled for routine deletion after 180 days.
  • Administrative audit records are scheduled for routine deletion after two years because they support integrity, investigations, fraud prevention, and dispute handling.
  • Other specific records may be held longer when reasonably required for an active security investigation, legal obligation, or dispute. The automated three-year deletion for the Work & Career Conversation consent and lifecycle record has no hold override in the current system.
  • Backups and provider logs may persist for limited periods according to operational deletion cycles; they are not used as permanent raw-data archives.

Your choices

  • You can update profile information, authentication methods, passkeys, and account settings where the platform exposes those controls.
  • Organization owners can manage members, invitations, roles, and workspace records subject to product permissions.
  • You can submit privacy, access, correction, deletion, or support requests through the contact page. Some records may need to be retained for security, audit, legal, or operational reasons.
  • You may withdraw permission to call or request correction of a Problem Session record through the contact page. Withdrawing contact permission does not retroactively remove a call already completed.
  • You may withdraw optional career-research permission through the Work & Career Conversation permissions page before the request reaches the irreversible aggregation boundary. After aggregation, no person-level research responses or categories remain for us to identify or remove from the aggregate.
  • You may use the same permissions page to stop contact about a Work & Career Conversation. Career support creates no candidate profile, employer-facing record, employer contact, matching service, or employer introduction.

Data minimization

We aim to collect data because it serves a concrete operational, security, or product purpose, not because it is convenient to collect. As the platform matures, high-risk data types should be added only after purpose, retention, permissions, and security controls are explicit. Air-gapped or encrypted storage does not make identifying data anonymous, so raw intake is not preserved indefinitely merely because storage is inexpensive.

Research and re-identification

The Solar Guild does not attempt to re-identify aggregate research data. Research access is limited, person-level source rows are not carried into the long-term aggregate, and any public or partner-facing reporting requires a minimum ten-submission cell and a separate disclosure review. The threshold is not a count of verified distinct people and does not itself establish anonymity. These safeguards reduce risk; they are not a claim that every data transformation eliminates every possible privacy risk.

Contact

Privacy questions and data requests can be sent through the contact page.