Public Value Open public beta privacy notice
This notice describes the personal and product data used for the live beta, how visibility is controlled, and the export, deletion, and safety boundaries available to participants.
Version 2026-08-10.2 · Effective August 10, 2026
Who is responsible
Public Value Open is currently an independently operated public-benefit software project. The formal controller legal name, service address, privacy email, and governing jurisdiction remain explicit external placeholders. Privacy and product requests can presently be submitted through the authenticated data-rights and feedback routes.
Account, identity, and participation data
The service processes account identifiers, verified email addresses, authentication and security events, chosen display names and handles, age and policy attestations, identity-assurance state when used, account roles, team relationships, invitation and registration state, blocks, restrictions, and the receipts needed to enforce those choices.
Activity data can include Duel terms and responses, Competition and Tournament configuration and participation, teams and brackets, Community Choice eligibility and ballots, Showcases, Open application drafts and submissions, scores and decisions, completion records, notifications, feedback, and correction, appeal, or withdrawal history.
Evidence, records, and applications
When enabled for an activity, the service processes uploaded evidence files, links, descriptions, content hashes, technical scan and custody state, access grants, holds, deletions, and the binding between evidence and a submission or decision. Do not upload personal or sensitive information that is not necessary for the stated activity.
Open applications may contain the track, responses, evidence references, declarations, revision history, submission state, and operator decision records shown in the application flow. A draft remains private to authorized people unless a separate visibility control says otherwise.
Proof, Competition, Tournament, Showcase, and social records remain private or limited by default unless the product shows a public visibility choice. Proof Passport publication is consent-scoped, record-specific, reversible through a successor publication choice, and does not expose raw evidence, ballots, access paths, or a universal score.
Safety, operations, and assistance data
Confidential reports, moderation cases, restrictions, recusal, appeals, deletion holds, and relevant audit evidence are processed only for authorized safety and operations work. A report narrative is not delivered to the reported participant merely because a case exists.
After explicit participant authorization, governed assistance sends redacted request text and the bounded instruction needed for that feature through Vercel AI Gateway to the pinned OpenAI model. Suggestions, human disposition, policy checks, and necessary diagnostic receipts may be retained for up to the period shown in the assistance record. Product data is not used by the project to train a general-purpose AI model, and assistance does not receive authority to publish, vote, score, or decide.
The service also processes bounded command receipts, outbox and delivery state, release and configuration evidence, error traces, security signals, and aggregate lifecycle measurements needed to operate, recover, and improve the product. It does not use session replay, raw-content analytics, personal popularity scores, or arbitrary browsing trails.
Why data is used
Data is used to authenticate people, provide requested activities, preserve agreed record lifecycles, enforce authorization and eligibility, deliver invitations and notifications, secure and recover the service, review safety and disputes, respond to support and data-rights requests, diagnose defects, measure whether core workflows function, and meet applicable legal obligations.
Product data is not sold. A materially different purpose requires notice and, where appropriate, fresh consent or policy acceptance.
Who processes data
Supabase provides authentication, hosted PostgreSQL, storage, and related database services. Vercel provides application build, hosting, delivery, runtime execution, and operational infrastructure. Their systems process the identifiers, product records, files, requests, and logs needed to provide and secure those services.
Resend provides transactional email delivery and processes recipient email addresses, reviewed message content, and delivery metadata. Cloudflare Turnstile processes network, browser, device, challenge, hostname, and timing signals for bot and abuse protection. Sentry receives bounded application error and performance diagnostics; session replay and account form values, email addresses, activity terms, evidence, applications, reports, ballots, and credentials are excluded by configuration and policy.
Vercel AI Gateway routes explicitly authorized governed-assistance requests. OpenAI provides the pinned language-model inference for those requests and processes the redacted request text, bounded instruction, generated response, token counts, and necessary technical metadata. Obvious credentials, email addresses, and private URLs are redacted before provider processing, but participants must still avoid submitting secrets or unnecessary personal data.
No payment processor is enabled for this release. An additional processor or materially expanded processor purpose requires an updated Processor List before use.
Visibility and disclosure
Access follows the audience and role displayed for the relevant activity: for example participant, team, organizer, reviewer, electorate, authorized operator, or public. Invitation tokens and evidence-access links are access credentials and should not be forwarded. Public pages may show only records and profile elements whose publication requirements are satisfied.
Data may be disclosed when required by law, to protect people or the service, or to listed processors under their service terms. The project does not create synthetic public participants or results and does not silently turn a private record public.
Retention, export, deletion, and anonymization
Authenticated users can generate a private PVO data export and request identity deletion. A deletion request pauses new affirmative actions and remains reversible until governed anonymization begins. A legal, safety, evidence, dispute, team-ownership, or operational-integrity hold may delay finalization and is recorded explicitly.
Finalization removes or tombstones direct identity links and requires separate confirmation of authentication-account anonymization. Some minimized audit, safety, aggregate, public-consent, or integrity records may remain when needed to preserve another person’s rights, a completed activity, security evidence, or a legal obligation, but they must no longer be used as active identity authority.
Private records, evidence, applications, reports, logs, backups, and command receipts are retained only while reasonably needed for operation, safety, dispute integrity, recovery, or legal obligations. Exact fixed retention periods remain an external legal and operations placeholder; the service does not promise immediate erasure from every backup.
Security, location, and choices
The service uses access controls, row-level security, encrypted network transport, immutable or append-only authority records, and command audit evidence, but no internet service can guarantee absolute security. The primary Supabase project is configured in Canada; listed processors may handle delivery and operational data in other locations.
You may decline to create an account, decline an invitation or activity, limit publication, block another participant, withdraw where the lifecycle permits, request a correction, export your record, request or cancel deletion before finalization, appeal where offered, or report a concern.