Privacy
Beta Privacy Notice
Document details
Version: 1.0 (draft). Effective date: none — this draft is not yet in effect, and nothing in it is in force. Last updated: 12 August 2026. Responsible entity: [SPHEROMNI RESPONSIBLE ENTITY — TBD]. Governing law and jurisdiction: [PRIMARY JURISDICTION — TBD]. Contact: [PRIVACY CONTACT — TBD].
Change history:
- Version 1.0 — drafted at Milestone 21 for the controlled beta. Not in effect, and not reviewed by counsel.
1. What this document covers
This notice supplements the Privacy Notice and covers only the four things the controlled beta adds to what Spheromni processes:
- the record that you confirmed you are an adult;
- the record that an invite code was redeemed for your account;
- feedback you send, and any reply written to it;
- error reports, only if you turn error reporting on.
Everything else — what Spheromni holds about you generally, why, the legal basis for it, who else processes it, how long it is kept, and what rights you have — is in the Privacy Notice, which is not changed by this document and which remains the complete statement. The controller is [SPHEROMNI RESPONSIBLE ENTITY — TBD].
2. The adult confirmation
What is held. That you confirmed you are an adult, the version of the wording you were shown, and the date and time. Nothing else. No date of birth is collected or held, and no check is performed against any source — this is a statement you made, not a verification.
Why. Spheromni is offered to adults only. Recording the answer is what makes the rule enforceable at all and is the evidence that you were asked.
Where it lives. Two places, for two purposes: a marker on your account, which is what the product checks when you sign in, and a row in your consent history, which is what you can read for yourself in Settings, under Privacy.
How long. Until your account is deleted, at which point it goes with it. There is no way to withdraw the confirmation on its own, because there is no state of “no longer an adult”; deleting the account is the way to remove it.
3. The invite code
What is held. On your account: that you hold beta access, and when. On the code itself: which account redeemed it and when, the date it was minted, whether it was revoked, and an operational note written by staff. Staff are instructed not to put names, email addresses or anything else identifying into that note.
Why. Access is invite-only, each code works once, and the record is what makes both true.
How long. The account marker goes when your account does. The code record survives your account's deletion, with the link to you removed — the row is kept as an operational record of a code that was issued and used, and once detached it identifies nobody. This is a deliberate choice and is recorded as one in docs/legal/legal-review-issues.md for counsel to confirm or correct.
Nothing was sent to you. Spheromni does not have and does not use any means of contacting you: no email was sent with your code, and no email address of yours was used to issue it.
4. Feedback
What is held. The category you chose, what you wrote, when you wrote it, its status, and any reply staff write with the time they wrote it. It is linked to your account, and staff working the queue can see the email address of the account that sent it — which is the same arrangement, and for the same reason, as a privacy request.
What you should not put in it. Anything confidential, and anything about another person. What you write is read by staff and is not private in the way your files are. Beta Terms section 6 sets out the licence you grant over feedback.
Where the reply appears. On your account page, in the list under the feedback form, and nowhere else. You will not be notified — Spheromni sends no email and no notification of any kind, so an answer exists only where you can open it.
How long. Until your account is deleted, at which point feedback and any reply are deleted with it. There is no age-based deletion of feedback in this release — a closed item is not swept away after a period, it is simply closed. That is stated here rather than implied, because a retention schedule that omitted it would read as though one existed.
5. Error reports — off unless you turn them on
This is optional and it starts off. Nothing is collected, held or sent unless you turn on “Send error reports” on your account page. It is its own control with its own purpose: turning on performance telemetry does not turn this on, and turning this on does not turn that on.
What is held, in full. Three fields and no others:
- what kind of failure it was — one of three values describing where in the application it was caught;
- the error message, truncated;
- the path of the page you were on — the path only, never the query string and never the part after a
#, because both routinely carry identifiers and search terms.
Each report is linked to your account and carries the time it was stored. No stack trace, no browser or device identification, no screen recording, no session replay, no document or file content, and no free-form context of any kind is collected. The whole of what a report can say is “a failure of this kind happened on this page, and this was the message”.
Why. So that failures are visible at all. Nothing else in this build records that anything went wrong.
Who receives them. Spheromni, and nobody else. There is no error-reporting company, no analytics provider and no third party of any kind involved — the reports go to Spheromni's own database. The Subprocessor List is unchanged by the beta.
How long. 30 days, after which they are deleted by the same retention sweep that handles every other timed deletion. Note the honest limit stated in the Privacy Notice and repeated here: that sweep has no scheduler and runs when a member of staff runs it.
Turning it off deletes what was collected. Withdrawing this consent stops collection and deletes the reports already stored for your account — the same behaviour performance telemetry has. Deleting your account deletes them too.
Nothing watches them. There is no alerting, no grouping and no dashboard that tracks them over time. A count of the last day's reports is visible to staff, and that is all.
6. Your rights, exports and deletion
Your rights are unchanged and are set out in section 17 of the Privacy Notice. Two mechanics are worth stating for the four categories above.
The download of your data includes them. The export you can generate from Settings, under Privacy, contains your feedback and any replies, your error reports, your consent records including the adult confirmation, and the invite record where you were the person who redeemed the code — including the code itself, since it is spent and it is yours.
Deleting your account deletes them, immediately and irreversibly, with the one exception named in section 3: an issued code's own record survives with the link to you removed. There is no recovery window and no backup copy.
7. Legal basis, transfers, complaints
The legal-basis framework, international transfers and the supervisory authority are unresolved for the whole document set and depend on [PRIMARY JURISDICTION — TBD]; sections 6, 13 and 19 of the Privacy Notice carry those placeholders and this notice adds no new answer. The engineering position recorded for counsel is that the adult confirmation and the invite record are necessary to provide the service you asked for, feedback is processed on the basis of the relationship you entered by sending it, and error reports are processed on consent alone.
8. Contact
Questions about this notice go to [PRIVACY CONTACT — TBD]. Questions about your own data are better filed as a privacy request in Settings, where the answer is written into that same window — Spheromni sends no email, so an answer exists only where you can open it.