NSYDR
Privacy Policy
This describes how NSYDR works during the invitation-only pilot. The product is still being built, so this page will change as the product does. Nothing here describes something NSYDR does not do today.
What NSYDR Holds
NSYDR holds what you write inside a Circle — your answers and notes, the conversation, care requests, the meetings, the shared story — and the record of what you agreed to and when.
It does not hold measurements of you. A record of something you did and a score for how you are doing are different things, and the second one is not collected anywhere in this product.
You Choose the Audience Before You Send
- Every response carries an audience, and you choose it before you send — never afterwards. The sentence saying who can read it and who cannot is on screen at the time, at every width, and is never hidden behind a disclosure.
- The audiences are: everyone who has joined the Circle, the Steward only, people you choose, or only you. People who were invited and have not joined are not “the Circle”.
- “People I choose” needs an explicit list. Nothing is inferred, and an empty list is refused rather than quietly resolved to something wider or narrower on your behalf.
- The default in your settings is only a starting point. It never decides for a particular response.
Who Can Reach What You Wrote
Access is decided by the database, not by a filter in the application. Row Level Security is the boundary: a Circle you are not in returns no rows at all, rather than a filtered view of one.
The same rule holds inside a Circle. An update NSYDR sends you is readable by you and nobody else, and a Steward reading their own updates sees what was sent to them — stewarding the Circle changes nothing about that.
What NSYDR Deliberately Does Not Measure
- No response rate, no rank, no streak, no engagement score, no elapsed time, no “still waiting”, and no count of who has not answered.
- No last-active time. The field that annotated a person with their activity was removed rather than reworded, and the database column is not read into the product at all.
- No per-person completion percentage, reliability figure, or ordered list of who answers most — for anyone, including a Steward.
- Charter acceptance carries no timing. Nothing records how long somebody took to accept, and the roster is sorted by name so its order says nothing about anyone.
- Invitations record the answer a person gave. Not whether they have an account, not whether they opened the link, not how many times, not from where.
- Conversations have no typing indicator, no presence and no read receipts.
- Your devices page exists so you can end a sign-in you no longer want. It carries no location, no history of what was read, and no notion of a suspicious device.
Photos
- Member photos are kept in a private bucket. Nothing in NSYDR gives a photo a permanent public address.
- A photo is shown through a signed link that is minted for that request and lasts about five minutes.
- What is stored is the JPEG the in-app crop produces — the re-encode strips the camera metadata — and it is capped at 2 MiB.
Location
- Location is off, and there is no always-on anything. Sharing is a session you start yourself, for people you name, and it expires. A share past its expiry is refused.
- No coordinates are stored at all. What a Circle carries is the fact that an unexpired, consented session exists — no coordinate, no place, no history.
- An emergency contact, a mobile number, an address and location are four separate, optional things. Each is off until you switch it on, and giving one never turns on another.
Email, Text and Notifications
- What arrives in the app is the record, and that one cannot be switched off. Email, text and push are yours to switch.
- Email is a plain message with the reason it was sent. No tracking pixel, no marketing.
- Text messages need a mobile number you have verified.
- What a notification shows on a lock screen follows your own redaction setting.
Signing In
Signing in is a link sent to the address you type. There are no passwords.
That address is not checked against the invitation, and it must not be: telling a visitor “that is not the right address” would tell whoever is holding the link something about the person it was sent to. A link goes to the address typed, and only the account that proves that address can claim an invitation that names it.
AI Assistance
- It is off by default, and it is yours to turn on.
- It is not available for Circles marked sensitive, whatever the switch says. In those places the feature is off.
- Your private content — reflections, notes, care requests, messages — is never used to train external models. Not now, and not as a change that could be made quietly later.
Counting, and Pilot Research
- Product analytics carry event names, counts, enums, booleans and pseudonymous ids. Nothing a person wrote may enter them: message, prayer, health, recovery and commitment text are excluded by the rule and by the code, which refuses an event whose properties look like narrative rather than a count.
- Pilot research participation is an optional consent. It covers counts and timings only, never your words, and turning it off changes nothing else about your membership.
Records Kept So They Can Be Accounted For
A few things are written as records rather than as content: that you affirmed you are an adult and which wording you were shown, the consents you gave or declined and the Charter version each belongs to, and reports.
- These are audit records. They are not editable and not deletable, and they cannot be quietly changed — that is the whole reason they exist.
- What they carry is restricted to counts, enums, booleans, version numbers and record identifiers. Narrative content does not go into them.
Export, Correction and Deletion — What Is True Today
Downloading everything you have written, correcting something that is wrong, and deleting your account are planned, and none of them works yet. Until they are built, ask by hand: write to support@nsydr.com, or use Feedback inside the product, and a person will handle it.
When deletion exists, this is what it will and will not be able to reach:
- Your own words, your profile and your private notes go.
- Some shared records stay — a decision the Circle made together, a meeting that happened, the fact that a Charter version was accepted. Those belong to more than one person, and they remain under the retention rules written into that Circle’s Charter, which every member can read.
- The audit records above are not edited or deleted. So NSYDR will not promise to erase everything, because it cannot.
Where It Runs
NSYDR uses third-party service providers to host, operate, secure and support the service. These providers may process information on our behalf only as necessary to provide their services.
Accounts, rows and member photos are held in a managed database, and the sign-in link is sent by a managed authentication service. The Row Level Security described above is enforced inside that database, which is why a Circle you are not in returns nothing rather than something filtered.
If NSYDR cannot reach that database in production it refuses to serve the page. It does not fall back to the sample content the walkthrough uses, because that would put a visitor inside somebody else’s Circle.
One Thing This Policy Cannot Soften
NSYDR is not emergency monitoring or dispatch. It does not watch for emergencies and cannot send help. Nothing on this page — no setting, no consent, no audience — changes that, and no privacy choice you make is read by anything looking for a crisis. The whole boundary is at Our Safety Boundary, and the Terms of Service state it too.
If You Have a Question About This
Write to support@nsydr.com. A person reads it. If you are already a member, Feedback inside the product goes to the same place: it is read by a person and written into a record that cannot be quietly changed.
If something in either document is wrong, or promises more than NSYDR actually does, that is worth telling us. Saying less is the intent.