Privacy Policy
What we hold, and what we don't.
Last updated: July 2026
What we collect
- Account: email address and password hash, used for authentication only.
- Mission profile (browseable): mission statement, sector, organization type, stage, partnership types, what you offer, what you need, geographic reach, optional impact statement and availability text.
- Identity profile (private): full name, organization name, optional website, optional photo URL, optional years in operation, optional credentials.
- Match activity: the requests you send, receive, accept, decline, schedule, and confirm.
- Reports: if you report another user, we store the report and the reason text.
What we never collect
- Your calendar contents. The beta does not connect to Google Calendar.
- Your contacts, location, browsing history, or any third-party social graph.
- Tracking pixels or behavioral advertising data.
What other users see
Other users see your mission profile and your assigned alias (e.g. Partner Saffron-23). They do not see your identity profile until a match between you is confirmed and the meeting time has arrived.
This restriction is enforced at the database level. Browseable API endpoints query a structurally-anonymized view that cannot return identity columns.
Third parties
- Supabase — database and authentication. Your account email and profile are stored on Supabase's infrastructure.
- Anthropic (Claude) — when computing match scores, we send only the mission-side fields of both profiles to the AI. Identity fields are never sent.
- Resend — transactional email delivery (verification, match notifications, intro emails). Resend processes the recipient address and email body on your behalf.
- Vercel — application hosting.
None of these providers receive your data for advertising or for resale to other parties.
Your rights
- Access: request a copy of your data.
- Correction: edit your profile at any time from the Profile page.
- Deletion: request account deletion at any time. We will remove your identity and mission profile within 7 days. Anonymized match history may be retained for service integrity.
Security
Passwords are stored hashed; authentication uses standard HTTP-only cookies. The application enforces row-level security at the database so users can only read or modify their own data.
Changes
Material changes to this policy will be emailed to your registered address.
Contact
For any privacy request, email support@bellatech.io.