Plain summary
Unpolished Diamonds collects only the information needed to run mentorship, account access, Diamond Profiles, Polishing Paths, Action Stones, support, security, and sponsor-safe reporting.
We do not sell personal information. We do not share Google user data for advertising. Sponsor and organization reporting is designed to avoid unsafe exposure of private mentee data.
Data we collect
| Category | Examples | Purpose |
|---|
| Account data | Name, email address, role, signup state, verification state | Create accounts, authenticate users, route support, and protect access |
| Mentorship data | Goals, mentor preferences, session preparation, Action Stones, reflections, progress evidence | Build Diamond Profiles, guide mentorship, and show proof of growth |
| Program data | Program enrollment, cohort membership, attendance, task completion, certificates | Operate Polishing Paths and measure completion |
| Security data | Session records, audit events, access requests, support references | Protect accounts, investigate issues, and maintain reliable access |
| Contact data | Inquiry type, message content, email address | Respond to mentorship, sponsor, privacy, and support requests |
Google user data
The current codebase does not implement Google Calendar, Gmail, Drive, Workspace, Meta Login, Meta Pixel, or Facebook API access. If Google sign-in is enabled for account authentication, the app uses only basic sign-in scopes.
| Reviewer question | Unpolished Diamonds answer |
|---|
| Data accessed | Basic Google account profile information: name, email address, profile picture if available, and the unique Google account identifier. The app does not request Gmail, Calendar, Drive, or Workspace data. |
| Data usage | Google data is used for sign-in, account creation or matching, displaying identity inside the product, security checks, and audit logs related to authentication. |
| Data sharing | Google user data is not sold and is not shared for advertising. It may be processed by infrastructure providers that host the application, database, email delivery, logging, or security systems. |
| Storage and protection | Authentication data is handled through backend services, encrypted in transport with HTTPS, protected by access controls, and not exposed publicly. |
| Retention and deletion | Account and authentication records are kept while the account is active or as needed for security, legal, billing, or audit reasons. Users can request deletion at /data-deletion. |
| AI/ML training | Google user data is not used to train generalized AI or ML models. If AI coaching processes account context, it is for user-requested product functionality and is governed by backend controls. |
| Minimum scopes | The app requests only the minimum Google OAuth scopes needed for sign-in: openid, email, and profile, when Google sign-in is enabled. |
| User control | Users can revoke access from their Google Account permissions page, request account deletion, or contact the privacy team. |
How data is used
- Create and secure accounts.
- Generate and update a Diamond Profile from assessment and growth evidence.
- Support Mentor Circle matching, session preparation, and shared action plans.
- Operate Polishing Paths, cohort rooms, reminders, certificates, and progress records.
- Produce sponsor-safe reporting using aggregated or privacy-respecting progress proof.
- Respond to support, privacy, billing, organization, and technical inquiries.
- Detect misuse, enforce conduct rules, and protect young or vulnerable users.
Sharing and service providers
We do not sell personal data. We do not share Google user data for advertising. We share data only where needed to operate the service, comply with law, protect users, or respond to a user-requested workflow.
Service providers may include hosting, database, email, monitoring, security, and payment infrastructure. Sponsors and organizations receive cohort-level or consented reporting according to policy and scope.
Storage and protection
- HTTPS protects data in transit.
- Backend services handle authentication, sessions, audit logs, and AI gateway calls.
- Administrative access is restricted by role and business need.
- Private mentor notes and private reflections are not public data.
- Security logs and audit events help investigate suspicious access or support issues.
- No security method is perfect, but the platform uses reasonable technical and organizational safeguards.
Retention and deletion
We retain account, profile, mentorship, program, and security data while an account is active and for a reasonable period after closure where needed for legal, billing, security, safeguarding, or audit purposes.
Deletion requests can be submitted through the Data Deletion page or by contacting the privacy team. We confirm receipt, verify identity where needed, process deletion, and send confirmation when complete.
- Deletion instructions: /data-deletion
- Privacy contact: foundry-security@iswellmade.com
- Backup and log copies may expire on normal retention schedules.
Meta and social platform data
The public web app does not currently load Meta Pixel, Meta Login, WhatsApp APIs, or Facebook APIs. If a Meta integration is added later, this policy and the cookie policy must be updated before the integration is used.
The data deletion page is public and suitable for Meta app review because it explains how a user can request deletion and receive confirmation.
Privacy contact
For privacy, data access, correction, deletion, or security questions, contact foundry-security@iswellmade.com. For general support, contact foundry-support@iswellmade.com.