Legal
Privacy policy
Plain language on purpose. Every sentence describes the software as built on the date above.
About this document
A template for review by counsel before publication. It describes the software as built on the date above, and it will change when the software does.
What we collect
Your account: your name, your work email address, and a hash of your password — never the password itself.
Your workspace: what you and your teammates record in it — sheets, strings, facts, pages, files, messages, proposals and decisions — and who recorded each, and when.
Sign-in: the path you used (a password, or your organisation's directory) is written to the record. Your IP address is read only to slow down repeated sign-in attempts and is not stored.
Where it lives
In one database file on the deployment's own volume. For a Canadian institution that volume is in Canada unless you choose otherwise.
Your browser talks only to the deployment's own address. Cursors, typing and call signalling are relayed while you are connected and are not part of the record.
What leaves the deployment
Nothing, by default. Your administrator can configure three things: your organisation's directory, for single sign-on; a language-model provider, which receives a question only when a person presses "ask an expert" — and then only the question and the part of the record that person could already read; and an anchoring service, which receives one hash of the record and nothing else.
An in-product call contacts a public STUN server to find a route between the participants. The call itself runs between them, not through us.
No sale, no training
We do not sell your data. We do not use it to train any model, and no provider we send a question to may either.
There is no advertising and there are no trackers.
Cookies
One cookie: your session. It is httpOnly, ends after 30 days without a visit, and only a hash of it is stored on the server. Single sign-on uses a second cookie for ten minutes while you are sent to your directory and back. Nothing else.
Retention and deletion
The record is kept for as long as your workspace exists. A deleted sheet is marked, not removed, so the deletion can be undone — and the undo is recorded too.
When your organisation's agreement ends, the workspace — the file, its companions and its backups — is deleted inside the window the agreement sets, and we confirm the date in writing.
You can export the record at any time: the gap report, the binder, the register as CSV, the dossiers, the evidence extract and the ledger itself.
Your rights
Ask your workspace owner to see, correct or export what is held about you; the product's own search and exports are how they answer. Under PIPEDA — and under Quebec's private-sector privacy law where it applies — you may also complain to the Privacy Commissioner of Canada or to the Commission d'accès à l'information du Québec.
Contact
Questions about this policy go to minerva@minerva-ca.com. The person in charge of the protection of personal information at Minerva Software Inc. answers at the same address.