1. Introduction
Neighborhood Technology Solutions LLC ("we," "us," or "our") respects your privacy and is committed to protecting the personal information of our users in Illinois and beyond. This Privacy Policy explains how we collect, use, and safeguard the information you provide through our various applications.
2. Information We Collect
Across our products, we collect information you provide directly and limited operational information needed to deliver, secure, bill, and support the features you choose to use. Through our feedback form, this includes:
- •Name (First and Last)
- •Date of Birth
- •Phone Number
- •Feedback Content (The specific comments or issues you submit)
Information Collected by Town Square
Use of the Town Square App and its features is optional. You may browse public community content without creating an account; creating an account enables additional functionality such as posting, private messaging, neighborhood connections, and notifications.
- •Profile Information: Name, email address, date of birth, and optional profile photo provided during signup.
- •Neighborhood and Address: Neighborhood selection and address (if provided) to connect you with your local community. Location is not tracked automatically.
- •Community Posts and Media: Content you post in the community hub, including text, photos, and videos. Media is stored securely and associated with your user profile.
- •Private Messages: Direct messages between users are encrypted in transit and not proactively monitored. If a conversation is reported for abuse, moderators may access the relevant messages to investigate.
- •Notifications: Device notification tokens are collected to send you important app updates and community alerts. You can opt out of notifications at any time in your device settings.
- •Account Authentication: We use Firebase Authentication to securely manage your login credentials. We do not store your password.
- •Usage Data: We may collect limited technical information (such as device type and app version) to improve app performance and security. No third-party analytics or advertising trackers are used.
All information collected by the Town Square app is used solely to provide and improve community features, ensure user safety, and comply with legal requirements.
Information Collected by RoozCast
RoozCast is a voice-first personal productivity app that helps you capture daily check-ins, organize tasks, and optionally sync selected information with services you connect. RoozCast collects only the information needed to provide those features.
- •Account and profile information: RoozCast starts with a pseudonymous Firebase anonymous user ID, so a name or email address is not required to use native subscription features. If you later link Apple, Google, or another supported sign-in, we may receive your email address, display name, and provider identifier. We do not store your password.
- •Check-ins and personal content: RoozCast stores the typed or spoken check-ins you submit, including raw text, generated transcripts, AI-generated summaries, accomplishments, task suggestions, task status, categories, due dates, reminders, and related notes you choose to save.
- •Temporary audio files: If you record a voice check-in, RoozCast uploads the audio to Firebase Storage so it can be processed by the backend. Audio files are temporary and are deleted after processing where possible.
- •Schedules, reminders, and device tokens: We store your check-in schedule, notification preferences, timezone, and Expo push notification token so RoozCast can send reminders and notify you when check-ins or summaries are ready.
- •Optional integrations: If you connect Google Calendar or Google Tasks, Notion, or Fireflies, RoozCast stores the minimum integration metadata and OAuth/API credentials needed to sync data on your behalf. Integration secrets are stored separately from ordinary profile data and are not included in normal user data exports.
- •Subscriptions and purchase records: Apple App Store and Google Play process native subscription payments. RoozCast receives limited purchase, product, transaction, entitlement, and pseudonymous account-linking records needed to verify access, prevent fraud, restore purchases, and meet billing and legal obligations. We do not receive or store your full payment card or bank account number.
- •Third-party AI processing with your consent: Before RoozCast sends personal content to an external AI provider, it asks for explicit consent. Depending on the feature and available provider, selected check-ins, transcripts, prompts, task or planner context, and selected Google Calendar, Tasks, or Drive content may be sent to Google Gemini/Vertex AI, OpenAI, or Anthropic to provide transcription, summaries, search, briefings, and assistant features. You may decline or later revoke this consent in Settings; features that require external AI processing will then remain unavailable.
- •Shared-content safety: If you choose to share a planning space, RoozCast applies automated high-confidence filtering and provides controls to report objectionable content and block another user. A report may include the selected reason, optional details, a short content excerpt, hashed technical references, and moderation status. Safety reports are restricted to authorized review and retained for up to 180 days unless a longer legal or security hold is required.
- •Diagnostics and support information: We may collect crash reports, error logs, app version, and limited device information through tools such as Sentry to troubleshoot bugs and improve reliability. We avoid intentionally sending personal check-in content in crash reports.
RoozCast does not collect advertising identifiers, precise location data, or address-book contacts. Native stores handle payment credentials; RoozCast receives only the limited subscription and purchase records described above.
RoozCast privacy settings and visibility
RoozCast is designed for private daily reflection. Your check-ins, transcripts, summaries, tasks, and notes are private to your account by default and are not visible to other RoozCast users. RoozCast does not include a public feed or follower-based sharing for personal check-ins.
- •Limited internal access: We do not routinely read, monitor, or review your personal check-ins. Authorized personnel may access account data only when needed to provide support you request, investigate security or abuse reports, maintain the service, comply with legal obligations, or protect the rights and safety of users and the company.
- •Optional sharing through integrations: If you connect services such as Google Calendar, Google Tasks, Notion, or Fireflies, RoozCast syncs only the information needed for the features you choose to enable. Information sent to connected services is then handled under those services' privacy settings and policies.
- •User controls: You can manage notification preferences, disconnect optional integrations, revoke third-party AI consent, report shared content, block another sharing participant, export supported RoozCast data, and permanently delete either an anonymous or linked account from the app.
Independent Contractors
We offer an optional program for users to register as independent contractors. The following describes the data we collect and how it is used when you register to work through Town Square.
- •Eligibility: Individuals aged 16 and older may register as contractors. Users under 16 are not eligible. Contractors aged 16–17 must be linked to a parent or guardian account; the linked parent/guardian can view the contractor's accepted and active jobs.
- •Profile & equipment: Contractors provide profile information and select the equipment they use. Equipment selections are used to match appropriate jobs.
- •Identity verification: We verify contractor identity using Persona; we collect the identifying information necessary for that verification.
- •Background checks: Where required, we request background checks through Checkr and store results only as necessary to evaluate eligibility.
- •Banking & payouts: Contractors connect bank details via Stripe for payouts. Stripe handles payment processing and bank verification; we do not store full card or bank account numbers but may retain transaction identifiers and receipts.
- •Calendar integration: Contractors may connect Google Calendar so the app can match jobs to available times. Calendar access is optional and may be revoked at any time.
- •Availability & scheduling: Contractors control an availability toggle (on/off) and may set a buffer time between jobs. Jobs may be scheduled with as little as 30 minutes' notice and up to one day in advance, subject to contractor settings and job type.
- •Earnings & records: We retain earnings records, payout history, and job history to display to contractors and to support payments, disputes, and recordkeeping.
- •Retention & third parties: Contractor data retention follows Section 4 (Data Retention). We share contractor data with third‑party providers (Persona, Checkr, Stripe, Google) only as necessary to provide verification, background checks, payments, and calendar sync, in accordance with this policy.
Information Collected by CommonShelf
CommonShelf is an open shared inventory product. It is designed for collaborative location tracking and accountability in a shared environment, not for confidential or private recordkeeping.
- •Account and access information: CommonShelf may process Firebase anonymous authentication identifiers, an optional display name or other attribution text you choose to provide, and limited technical data such as browser, app version, and device information needed to operate, secure, and troubleshoot the service.
- •Location and inventory records: We process location names, categories, items, quantities, notes, stock and restock fields, deleted-item records, and related inventory history that users create or update in CommonShelf.
- •Notifications and communication: If you enable CommonShelf notifications, we process notification preferences, verified notification email addresses, push-device tokens, verification status, and delivery records needed to send alerts and digests.
- •Operational and administrative records: CommonShelf may process on-behalf attribution, support-workflow records, deletion-review records, name or attribution moderation decisions, and other service-integrity records needed to operate shared inventory responsibly.
- •Visibility model: Because CommonShelf is an open shared product, information you place in CommonShelf may be visible to other CommonShelf users who participate in the shared system and should not be treated as private or confidential.
We use CommonShelf data to run shared inventory tracking, notification delivery, support workflows, deletion review, naming-rule enforcement, and service integrity in an open shared environment where users should avoid storing confidential or private records.
Information Collected by SecureShelf
SecureShelf is a paid private inventory product designed for role-based location access, accountable updates, and export-friendly continuity.
- •Account and access information: We process account identifiers such as your user ID, email address, display name, sign-in provider, and related authentication metadata from email-link, Google, Apple, or other enabled sign-in methods. We do not store your password.
- •Location and inventory records: We process secure location names, categories, items, quantities, notes, stock tracking, restock-related fields, and transaction history associated with a secure location.
- •Notifications and communication: If enabled, SecureShelf processes verified notification email addresses, push-device registrations, notification preferences, and notification delivery history needed to support member notifications.
- •Operational and administrative records: SecureShelf processes member roles, invites, immutable audit events, deletion requests, export metadata, support-view records, customer IDs, subscription IDs, billing state, invoice or payment-status metadata, and related accountability records needed to operate paid secure locations. We do not store full payment card numbers.
- •Visibility model: SecureShelf is designed so supported secure-location content is available only to authorized members of that location and authorized administrators who access data for support, security, billing, or legal reasons.
We use SecureShelf data to operate private role-based inventory, audit and accountability records, notifications, billing, exports, and authorized support or administrative workflows for secure locations.
Information Collected by MyCircles: Concentric Circles
MyCircles is local-first by default. You can create and manage projects on your device without an account. If you create an account or choose features such as cloud projects, snapshot sharing, Live Share, AI Ask, billing, or map tools, we process the information needed to provide those features.
- •Account and sign-in information: If you create an account, we use Supabase Authentication and may process your email address, account ID, sign-in provider, and authentication metadata for email magic link, Google, or Apple sign-in. We do not store your password.
- •Profile information: You may provide a display name and optional avatar or profile image. Profile images may be stored in account metadata or product storage so your account can be personalized across signed-in sessions.
- •Project content: MyCircles projects may include people, names, bios, notes, custom attributes, relationships, connection labels, rings, positions, colors, narratives, view settings, color labels, local activity history, imports, exports, snapshots, and related metadata you choose to create or save.
- •Cloud projects, snapshots, and Live Share: If you use cloud projects, snapshot sharing, or Live Share, we store the project data and share metadata needed to create links, restrict access to invited email addresses where configured, maintain share slugs and signatures, sync collaborators, and show presence or activity in real time.
- •AI Ask and semantic search: If you use AI Ask, we process your project query, bounded project context, person summaries, relationship context, embeddings, usage counts, hashed IP/request metadata for rate limiting and abuse prevention, and AI response metadata. AI processing may use Google Gemini/Vertex AI, OpenAI, or Anthropic through our Supabase Edge Functions; embeddings currently use Google Gemini.
- •Map and geocoding features: If you use map tools, address search, or address-to-coordinate features, we may send the address text or search input needed for autocomplete or geocoding to Google Maps Platform through our backend. Map displays may also load OpenStreetMap tile data. We use this only to provide the requested map feature.
- •Subscription and billing metadata: If you subscribe or request account changes, we may process plan, tier, product key, provider, status, purchase identifiers, subscription identifiers, customer identifiers, billing event metadata, and support notes from Apple App Store, Google Play, Stripe, or manual support workflows. We do not store full payment card numbers.
- •Account controls: Signed-in users can permanently delete an account in MyCircles or through the public MyCircles deletion page using fresh email, Apple, or Google proof already linked to the account. Guest profiles are local-only and use Reset local data instead of a server deletion request.
Information Collected by Unveiled: Commit to Heart
When you first use Unveiled, the app automatically creates a pseudonymous cloud identity so its local-first data can sync and recover without requiring your name or email. You may later link Apple, Google, or email sign-in to that same identity.
- •Account and identity data: We process a pseudonymous account identifier and, if you link an account, the email, display name, and provider identifiers supplied by the sign-in provider. While Apple is linked, encrypted provider credentials and a pseudonymous subject reference may be retained to support required revocation and server-notification handling. We do not store your password.
- •Memorization data: Projects, practice history, voice summaries, Daily Recall history, settings, and related synchronization metadata are stored to provide the features you choose and continuity across supported devices. Completed Daily Recall prompt text and answers are not retained in test history.
- •Purchase information: Apple App Store and Google Play process Unveiled's one-time full-access purchase. We receive limited product, transaction, receipt-verification, and entitlement metadata needed to grant and restore access, prevent conflicting claims, and support store requirements. We do not receive full payment card numbers.
- •Account controls: You can permanently delete an anonymous or linked account in the app or through the Unveiled account deletion page. After completion, Unveiled remains account-free until you choose Start Fresh or sign in. Starting fresh creates a different empty pseudonymous identity.
Information Collected by Monet or Manet
Use of Monet or Manet is optional. It is an account-free visual-identification game that keeps limited game state on your device and processes only the information needed for purchases, leaderboards, advertising, support, and service integrity.
- •Local game state: The app keeps game progress and preferences on your device. Shared Preferences is used for ordinary game state. Platform-protected secure storage is used for a verified Remove Ads entitlement, a per-install opaque identifier, and leaderboard deletion tokens.
- •Leaderboard submissions: If you choose to submit a score, we process the player name, selected mode, score, accuracy, best streak, submission time, and a locally held deletion token. Firebase Functions and Cloud Firestore provide the submission and public leaderboard service. New entries are retained for up to 24 months. You can delete an entry created by your installation in the app while its deletion token is available; lost-token and legacy-entry requests can be sent through product support.
- •Purchase and entitlement information: A store-managed one-time Remove Ads purchase is verified with the applicable store before it grants an entitlement. We retain an entitlement record and hashed store identifiers for up to 24 months after its last verified event. We do not collect payment card numbers.
- •Advertising: The free, ad-supported experience shows non-personalized advertisements delivered through AppLovin MAX. On Android, Meta Audience Network may also bid as an additional demand source. Ad requests are always non-personalized: ads are selected from the app and general context rather than from a profile of you, and the app instructs the advertising SDKs not to use device data for interest-based advertising. The app does not request advertising-tracking permission. On iOS the advertising identifier is not available to the advertising SDKs; on Android the operating-system advertising identifier may be read by the advertising SDKs to deliver and measure non-personalized advertisements. A horizontal banner appears on the mode-selection screen and a full-screen ad may appear between rounds; a verified Remove Ads purchase suppresses both. Apple's SKAdNetwork may provide aggregated, delayed install attribution that does not identify you. An in-app Privacy Choices notice lets you revisit this information, and remote advertising-availability controls let us disable advertising without a new app release. AppLovin's independent processing is governed by AppLovin's Privacy Policy, and Meta's by Meta's Privacy Policy.
- •Remote advertising controls: Firebase Remote Config uses a Firebase Installation ID and associated app-instance information to deliver advertising-availability settings. This identifier is separate from the installation identifier used by our leaderboard service. In remediated versions, the advertising configuration request follows resolution of ad-supported purchase entitlement and applicable consent eligibility. Disabled or unavailable configuration prevents advertising in those versions; it does not disable purchases, leaderboards, or app-integrity services, and does not control older versions that lack these safeguards.
- •Integrity and installation identifiers: Firebase App Check and platform attestation services help validate requests and prevent abuse. App Check is initialized at startup, independently of advertising consent. Firebase retains Installation IDs until a deletion request is made through its API; after that request, associated data may take up to 180 days to be removed from live and backup systems. Deleting a leaderboard entry does not itself request deletion of Firebase Installation IDs or independent service-provider records.
- •Security and operations: Firebase App Check and server-side validation help protect purchase and leaderboard requests. We keep redacted operational event logs for up to 30 days. The app does not include Firebase Analytics, Crashlytics, or another analytics or crash-reporting SDK.
- •Service providers: Firebase, AppLovin, and Meta Audience Network process the information described above to provide app integrity, leaderboard, purchase-verification, and non-personalized advertising services, and each is governed by its own privacy policy. Storefront payment processing is handled by the applicable store, whose terms and privacy practices apply to payment processing and refunds.
- •Age and support: The app is intended for users aged 13 and older. If you need help with a purchase, a leaderboard entry, or a privacy request, use the product-support link above.
Information Collected by Inkify
Information We Collect from Form Owners and Admins
During installation and configuration of the Inkify Add-on, we process limited admin and operational information required to manage licensing, provide support, and run the features a form owner chooses to enable. This may include:
- •Admin Email Address: Used to verify license status, manage subscriptions, send operational notices, and provide support.
- •License, Voucher, Subscription, Team Seat, and Billing Metadata: Used for activation, tier checks, Enterprise access, organization-owned transferable seats, signer-profile subscriptions, payment-collection readiness, billing support, fraud prevention, and abuse prevention.
- •Organization Seat Metadata: For Inkify Team Seats, the website and Inkify Hub may store the team or organization name, owner email, seat admin emails, assigned seat emails, seat tier and status, requested and approved domains, Stripe customer, checkout, subscription, and webhook identifiers, auth/session records, audit events, and finalized-submission usage counters by organization, user, and day.
- •Inkify Help Metadata: If you use Inkify Help on the setup guide, we may process your signed-in email, helper auth/session records, rate-limit hashes, aggregate daily usage counts, approved knowledge source references, and the question you submit for AI processing. If you opt in to Setup Coach, we may store hashed-email setup progress metadata such as setup step, safe counts, booleans, status categories, an opaque setup session, and sync state for up to 90 days after last activity. Inkify Help does not store chat transcripts by default.
- •Configuration Metadata: Settings such as form IDs and titles, published form URLs, hidden payload configuration, branding preferences, delivery settings, workflow mode, counts, timestamps, redacted operational status, and customer-selected storage/template labels where needed for display. Inkify Hub configuration metadata must not include customer Drive file IDs, storage references, template contents, signed PDFs, response Sheet rows, signatures, private keys, or customer file contents.
Information Processed for Form Respondents and Signees
Inkify helps form owners collect information from individuals who respond to connected Google Forms. Depending on the form and enabled features, this may include:
- •Form Answers and Signatures: Used by the form owner's Google Workspace add-on to generate signed records, populate templates, and create signed PDFs in the form owner's Google Drive.
- •Signer Identity and Evidence: Signer names and emails when collected by the form, consent version/hash, consent timestamp, IP address where available, user agent, transaction ID, signed-record hash, PDF hash, and audit metadata.
- •Signed-Copy Delivery Data: The email address a signer provides for a signed copy is included in the native Google Form submission so the form owner's add-on can send the signed copy from the form owner's Google context.
Customer-Owned, Zero-Knowledge Custody Boundary
Customer-Controlled Workspace: Generated signed PDFs, signatures, form answers, response rows, templates, Drive files, private signing keys, signed-copy email content, and customer-owned workflow records are processed in the form owner-authorized Google Workspace and add-on context. Zero-knowledge custody means naborlydone-controlled hub and short-link systems are designed not to retain customer-owned signing records, including submissions, signatures, signed PDFs, response Sheets, templates, private keys, signed-copy email content, member sheets, or private workflow state.
Inkify Hub Processing: The Inkify Hub may retain admin/license/support metadata, organization seat metadata, form configuration metadata, safe form registry records, redacted workflow projections, finalized-submission usage counts, timestamps, policy modes, and similar service metadata needed to render and coordinate the service. It may also store encrypted signer-owned profile values when a signer chooses to create a saved profile.
Payment Metadata: When enabled, form-owner license billing, organization Team Seat billing, signer saved-profile billing, Stripe Connect readiness, and redacted in-form payment attempts may be stored as operational payment metadata. Inkify payment metadata must not include customer form answers, signatures, PDFs, Drive files, signed-copy email content, or private workflow records.
Branded Short Links: Short links at forms.naborlydone.com store only non-PII routing metadata: slug, link kind, opaque form/event/workflow/invite handles, click count, and last-used timestamp. They must not store full destination URLs, owner or signer emails, prefill payloads, decoded signer tokens, answers, signatures, signed PDF links, member profiles, or signer rosters. No third-party advertising or marketing trackers are used for Inkify.
PDF Verification Tool: The Inkify verification page is designed to inspect signed PDFs locally in your browser. The PDF file, extracted text, embedded evidence block, verification result, and cryptographic checks are not uploaded to naborlydone unless you separately choose to share that information with us for support.
Brokered Connected Forms
When an eligible form administrator explicitly opts in, Brokered Connected Forms uses naborlydone for authorization metadata only. This metadata can include opaque account, Form, policy, request, connection, and command handles; keyed account and domain digests; encrypted administrator email addresses; safe lifecycle states and revisions; bounded counts; and timestamps. It does not receive lookup tokens, roster rows, completion statuses, form answers, signatures, PDFs, Google resource IDs or URLs, private keys, or customer email and PDF content.
The Connected Forms console uses identity-only Google sign-in to verify the administrator. It does not request Google Drive access tokens or refresh tokens. The Google identity credential is verified and discarded; the console uses a bounded, secure session cookie. Every Drive, Sheet, permission, trigger, projection, activation, revocation, and recovery change still runs in the applicable customer's Google account.
Connected Forms projections protect authorization metadata and formulas against dashboard-editor changes, but visible projected status is not a confidentiality boundary. A dashboard editor may be able to read, copy, or export visible status data after the source owner approves the connection and the disclosure. Revocation preserves historical customer-owned records unless the applicable owner separately chooses an approved cleanup action.
Signer-Owned Saved Profiles
Signers may choose to create an optional Inkify saved profile so matching fields can be prefilled on future Inkify forms. A profile is owned by the signer, not by the form owner. Creating a profile is not required to submit a form.
- •Profile Login: Inkify uses email-code login for signer profiles. Profile login codes are sent only for authentication and do not include form answers, signatures, PDFs, or signed-copy email content.
- •Profile Values: Saved profile details are encrypted in Inkify-controlled profile storage and used only for signer-approved prefill and profile management. Profile values are not sold, used for advertising, or shared with form owners as a member database.
- •Review Before Save: After submitting a form, signed-in users may be asked whether reviewed answers should be saved to their profile. Suggested updates start unselected and are saved only after the signer chooses them.
- •Delete Profile: When a signed-in user deletes their profile, Inkify hard-deletes the encrypted profile row plus related profile authentication, session, and consent rows from the profile database. Deleting a profile does not delete forms, PDFs, emails, or records already submitted to a form owner.
- •Profile Billing: Saved profiles are a separate signee-paid feature priced at $2/month or $20/year per profile, before any payment processor or checkout fees shown before purchase. Billing metadata is handled only as needed to operate the profile subscription and does not include form answers, signatures, PDFs, or customer-owned signing records.
License Usage and Subscriptions
Inkify owner licenses and Enterprise subscriptions are intended for the single authorized Google Account that activates or subscribes to the service unless the customer has officially purchased organization-owned transferable seats. Official organization seats may be assigned, revoked, and reassigned by authorized organization admins through the Inkify organization hub; those records are limited to operational license metadata and do not include customer-owned signing records.
Organization-owned Team Seats support exact-email assignment so a seat can be moved when an employee or contractor changes roles. Exact-email assignment works immediately after a seat is available. Domain controls may be requested by an organization owner, but requested domains are not treated as verified or approved until naborlydone staff approves them. Removing or changing a domain does not by itself delete existing customer-owned Google Workspace records.
Team Seat entitlement checks and finalized-submission usage increments are metadata-only. We may receive the assigned user's email, organization and seat identifiers, tier, status, and a metadata-only idempotency key for counting finalized Inkify-hosted submissions. We do not receive form answers, signatures, PDFs, response Sheet rows, Drive file contents, templates, private signing keys, member profiles, signer workflow state, or raw form content for Team Seat license validation or usage counting.
We may monitor operational license metadata for billing support, fraud prevention, abuse prevention, and enforcement of authorized seat boundaries. Credential sharing, informal pooling, resale, or using one paid account as a shared administrative account outside an official organization seat is not permitted.
Inkify Help AI Assistant
Inkify Help is an optional setup-guide assistant for recognized Free Trial/free-tier, personal paid, personal Enterprise, and organization seat users. It answers from approved product, setup, privacy, terms, and public-support-safe Inkify knowledge and may show illustrative sidebar or form guidance from an allowlisted map.
Inkify Help uses Google Gemini/Vertex AI for AI processing when enabled. We send the question you type and approved knowledge context to the AI provider so it can answer. We do not send or ingest customer-owned form answers, signatures, PDFs, response Sheet rows, Drive file contents, templates, private signing keys, member profiles, signer workflow state, or raw form content.
Inkify Help does not store chat transcripts by default. We store only metadata needed for sign-in, rate limiting, aggregate usage, model-error counting, optional Setup Coach progress, and security. Setup Coach and automatic setup sync are opt-in; synced setup data is limited to counts, booleans, and categories, expires after 90 days of inactivity, and can be cleared by the user. If Inkify Help drafts a support ticket, the draft is not submitted automatically; you must review it and choose to submit it through the support form.
Technical Trust: Authorized Scopes
To maintain a secure and functional integration, Inkify operates within your Google Workspace using specific, authorized permissions. Each "scope" serves a direct functional purpose:
- •drive.file: Creates, opens, copies, and stores files the Admin selects or the app creates, including signed PDFs, preview PDFs, managed templates, and compliance exports.
- •documents: Merges form answers into Admin-selected Google Docs templates and converts the resulting record to PDF.
- •spreadsheets: Reads and writes configured response, audit, member, event, voucher, and workflow sheets in the Admin's Google Workspace.
- •forms.currentonly: Inspects and configures only the active Google Form where the add-on is installed.
- •script.external_request: Calls the Master Hub, short-link service, IP evidence service, and configured add-on relay endpoints needed for visible product features.
- •script.send_mail: Sends signer invites, reminders, signed copies, and owner notices for workflows the Admin configures.
- •script.container.ui & script.scriptapp: Displays the add-on sidebar and installs/manages submission or maintenance triggers required for the configured workflow.
- •userinfo.email: Identifies the active Admin for license checks, owner-only controls, audit/export access, and support.
User Control and Access Revocation
You can revoke Inkify's access to your Google account at any time by visiting myaccount.google.com/permissions.
All information collected and processed by Inkify is used solely to provide and improve the application's features, ensure user safety, and comply with legal requirements.
Information Collected by ClearSlot
First effective for ClearSlot use: 11 August 2026. ClearSlot by NaborlyDone helps organizers collect availability and identify a meeting time. Participants remain account-free; a participant may respond with only a name or optionally provide an email address for essential schedule updates and request verification.
- Organizer and Organizer Team information: We process organizer email, profile and theme preference, owned and invited Organizer Team role and membership, selected-team preference, plan, usage, billing state, and versioned legal-notice acknowledgement needed to operate the organizer account and its teams.
- Organizer Teams and invitations: An owner may invite an organizer using an exact email address; Organizer Teams are not restricted to one email domain. We process the normalized invited email, team name, invitation status and expiry, membership lifecycle, owner-set capacity-retention order, organizer notification selections, and content-free team activity needed to deliver invitations, authorize shared schedule management, enforce capacity, and notify eligible organizers. Current eligible schedule editors may see the verified email addresses of current teammates for organizer-notification selection.
- Complimentary grants: Approved NaborlyDone operators may issue an immediate, time-limited or forever complimentary Plus or Club grant for a recipient's owned Organizer Team. We process the normalized recipient email, granted plan, exact expiration, optional bonus-seat quantity, delivery preference, account and owned-team binding, administrative reason, and operator action history needed to administer the grant. Complimentary grants do not modify Stripe subscriptions and do not follow the recipient into another Organizer Team.
- Additional Organizer Team seats: Club includes five total organizer seats, including the owner. A Club owner may purchase up to 20 additional monthly seats, for a maximum of 25 organizers. We process the selected quantity, Stripe subscription-item state, proration or payment-recovery result, scheduled reduction, billing reconciliation, and capacity-change status. ClearSlot does not receive or store full payment-card or bank-account numbers.
- Schedule and response information: We process schedule titles, instructions, date ranges, timezones, decision mode and state, participant names, reviewed availability, response status, and the final chosen time. Anyone with the public schedule link may be able to see the schedule information, participant names, response status, and aggregated availability intentionally shown on that page. Participant email and notification preferences are stored outside public participant records.
- Organizer-controlled participant insights: An organizer may separately enable a name-free, duration-aware group availability heatmap or a complete shared meeting suggestion. ClearSlot derives these views only from submitted responses and shows them only after at least three submitted responses exist and only to an Organizer-approved, event-scoped participant viewer. The display minimum reduces casual inference but is not a guarantee of anonymity; approved viewers who coordinate or already know the group may still infer information about an individual response.
- Optional named session rosters: If an organizer enables named rosters before the first successful response, ClearSlot shows a roster notice during submission. After the participant acknowledges that event-pinned notice, ClearSlot may show the participant's submitted name under an exact suggested or published session that their submitted availability fully covers. Roster viewing also requires current Organizer approval and a current submitted response. A roster describes an availability relationship and does not predict or confirm attendance. Rosters are derived at request time and are not stored as roster rows or name arrays, shared-suggestion snapshots, email content, analytics, logs, Realtime payloads, or support records.
- Participant access and email verification: Optional participant email supports tracking-free response receipts, recovery requests, and email-change confirmation through one-time secure access links. Browser device capabilities are random secrets stored only as digests and are bound to one schedule and participant. ClearSlot stores bounded verification state, content-free verification outcomes, device issue/last-use/expiry times, revocation and rotation state, and pending email-change state. Raw access tokens and browser capabilities are not stored in email snapshots, logs, exports, or operational metrics.
- AI and voice processing: ClearSlot may send a typed request or editable voice transcript and the minimum schedule context needed for the requested feature to OpenAI, Google Gemini, or Anthropic for transcription, schedule interpretation, bounded fallback, or a low-confidence second opinion. ClearSlot normally routes one request to one provider at a time. AI output is subject to user review. Content-free reliability records may include provider, model, task, category, latency, token counts, and confidence workflow, but not prompts, transcripts, calendar content, or model response bodies.
- No stored audio: Recorded audio is held in request memory only long enough to transcribe. ClearSlot does not store audio in its database, object storage, application logs, or local files. The editable transcript and reviewed availability may be saved through the normal schedule workflow.
- Google Calendar: Google connections request only the calendar-list and free/busy permissions needed to list selected calendars and read timing availability. ClearSlot does not request event titles, descriptions, locations, attendees, organizers, notes, or calendar-write access.
- iCloud Calendar: iCloud connections use the Apple ID and app-specific password supplied by the user to request calendar names and CalDAV free/busy timing. Credentials are encrypted with a versioned AES-256-GCM envelope. ClearSlot does not request or store calendar event content.
- Calendar drafts and deletion: Busy times are converted into an unsaved availability draft. Only availability the user reviews and submits becomes part of a response. Participant calendar connections are removed on disconnect, schedule closure, schedule expiry, or no later than two days after the schedule end date. Organizer connections are removed on disconnect or 30 days after the applicable paid period ends or Calendar entitlement is otherwise lost. A five-minute cleanup job handles expired and disconnected connections.
- Infrastructure, email, and billing: ClearSlot uses Supabase for authentication and product data, Cloudflare for hosting and server processing, Zoho ZeptoMail for tracking-free magic-link and essential schedule-status email, and Stripe for checkout, subscriptions, invoices, refunds, and billing state. We do not receive or store full payment-card or bank-account numbers.
- Paid purchase verification and incident records: ClearSlot records bounded internal scope and billing-operation identifiers, provider object identifiers, offer or operation kind, reconciliation state and deadline, paid-admission circuit state, proof-family state, amount and currency when needed for an approved remedy, and content-free operator audit timestamps. These records are used to verify that a successful payment produced the purchased entitlement, pause new paid actions when fulfillment cannot be verified, reconcile billing incidents, and prevent duplicate financial action. They do not contain payment-card or bank-account details, billing addresses, Checkout URLs, webhook payloads, invoice contents, or support-message bodies.
- Campaign attribution: When a new organizer follows a registered ClearSlot campaign link and completes email sign-in, ClearSlot may associate that campaign identifier with the organizer account and sign-in time. We use this association with existing scheduling and billing records to report aggregate campaign outcomes. Attribution does not collect participant names, availability, schedule text, audio, arbitrary tracking parameters, or browsing histories, and this measurement does not send product data to advertising platforms. Missing campaign information remains unattributed. The account-linked attribution record is deleted after 90 days or with verified organizer account deletion and is included in the organizer’s access export.
- Optional first-party sponsors: Sponsor placements are currently disabled. If enabled later on the Free plan, ClearSlot records campaign, placement, available Organizer Team and schedule references, and a daily pseudonymous session HMAC derived with a day-versioned secret from IP address and user-agent inputs for impression and click measurement. Raw IP addresses and user-agent strings are not written to sponsor measurement tables, and the secret and derived value are not reused across days. Sponsors do not receive participant names, email, availability, schedule text, transcripts, or calendar content. Paid plans do not receive sponsor placements under the current implementation.
ClearSlot Retention and Data Rights
- Short security records: Expired OAuth state and rate-limit rows are deleted after their short security window, no later than 48 hours after they stop serving that purpose.
- Operational records: Content-free AI attempt and assist telemetry, terminal notification delivery records, and row-level sponsor impression and click records are retained for 90 days, then deleted. Anonymous sponsor campaign totals may remain only after removing the daily session hash and Organizer Team and schedule references.
- Participant insight and access records: Terminal access verifications, revoked or expired device capabilities, completed or abandoned email changes, and terminal insight-computation leases are deleted after 48 hours. Content-free verification attempts and Participant Insights operational metrics are deleted after 90 days. Stale shared-suggestion snapshots are deleted after 24 hours. Current viewer decisions, roster-notice acknowledgements, and revision-current sanitized shared suggestions follow the participant or schedule lifecycle and the verified deletion rules below.
- Schedule records: Schedule, participant, contact, and reviewed availability data remain while the schedule and Organizer Team remain active or until a verified deletion request applies. Participants can overwrite a response while a schedule is open and can stop optional email updates.
- Organizer Team records: Active grants and memberships remain while effective. Ended or revoked grant records and grant-event identity fields remain for two years, then identifying fields are deleted while aggregate counts may remain. A removed organizer membership identity remains for one year, then is deleted. Accepted, canceled, replaced, or expired terminal invitations are deleted after 30 days.
- Billing verification and operator records: Circuit, proof-family, reconciliation-deadline, remedy, and operator-audit records are retained while needed for an active deadline, failed proof, billing incident, dispute, tax or accounting obligation, security review, or legal hold. Verified operator identity is redacted after two years under the operational-audit rule, while permitted content-free aggregate outcomes may remain. Cleanup does not remove an unresolved billing deadline or incident merely because a routine retention interval elapsed.
- Team messages and transfers: Terminal team transactional email and delivery records are retained for 90 days. Organizer response-digest buckets are deleted after enqueue or within 48 hours if abandoned. Pending ownership-transfer consent remains through its seven-day decision window; terminal transfer-consent identity is deleted after 30 days while a content-free outcome may remain with an applicable privacy request.
- Verified requests: An organizer request is authenticated through the organizer account. A verified participant request uses the existing edit capability or a one-time link sent only to the exact optional email already stored for that response. The support ticket receives only an opaque request ID, not the capability, schedule text, or private app content.
- Access exports: A reviewed export contains only the verified subject's releasable ClearSlot-controlled data, excludes credentials, security controls, sponsor hashes, and other people's private contact data, and is delivered through a one-time authenticated download. It is deleted after successful download or within 24 hours, whichever comes first.
- Deletion safeguards: A destructive request requires identity verification, an exact scope, operator review, and action-time approval. An encrypted operator-only rollback bundle containing only the reviewed cascade expires within seven days unless a documented failure or legal hold requires reviewed extension.
- Completion and provider exceptions: The bounded data-rights completion receipt is retained for three years by default as request and compliance evidence. Stripe, tax, fraud, accounting, security, backup, dispute, provider, and legal-hold records follow provider and legal necessity and may remain when ClearSlot cannot delete them independently.
Information Processed by Voice Writer
First effective for Voice Writer use: 12 August 2026. Voice Writer processes most information in its private local library. Neighborhood Technology Solutions LLC does not receive that local library. In-app on-device refinement remains on the iPhone. Information leaves the device only through an action the user chooses, such as Shortcut provider refinement, Copy, Share, or an explicit diagnostic export.
Local product operation
On iPhone, without installing an Apple Shortcut, a user can record, transcribe, recover a draft, use Review, edit and save text, Copy, and Share. The iPhone edition keeps the latest recording in protected app storage after the user resolves older recordings. History and Recently Deleted remain available only while older recordings or cleanup issues need attention. On Mac, Voice Writer keeps one latest result and a recoverable latest recording in owner-only Application Support storage after the user resolves older recordings. Supported transcription is provided by Apple Speech.
Voice Writer has no Voice Writer account, developer-operated backend, cloud sync, advertising, analytics, subscription, or proprietary model client. Notifications, Live Activities, and App Intents are content-free and do not expose transcript or audio content.
On-device and optional Shortcut model processing
On supported iPhones, Stop & Refine uses Apple Foundation Models on-device without a Shortcut. This in-app path processes only the complete finalized transcript with Apple's on-device system language model. It does not invoke Use Model, ChatGPT, or Private Cloud Compute. Availability depends on device eligibility, Apple Intelligence being enabled, language support, and model availability. The company does not receive the prompt or result through this path.
Shortcuts remain optional for ordinary local features and in-app on-device refinement. A compatible installed Shortcut is required for system-triggered refinement or automation, such as an Action Button workflow. Only a complete finalized transcript enters the Shortcut's Use Model action after an explanation and the user's explicit consent. Audio, incomplete recovery text, surrounding keyboard text, and diagnostics do not enter either model request.
In a compatible Shortcut, On-Device Apple Intelligence processes the request without requiring a network. Private Cloud Compute sends request-relevant data to Apple silicon servers; Apple represents that this data is used only for the request and is not stored or made accessible to Apple. ChatGPT is a separate extension model supplied by OpenAI. OpenAI states that, when ChatGPT is used through Apple's integration without a connected account, OpenAI does not receive the user's IP address and does not store requests. With a connected ChatGPT account, the user's account settings, history, training controls, retention, and deletion rules apply.
The production Voice Writer Shortcut currently selects ChatGPT, but the Shortcut is user-owned and editable. A user may edit it to select another compatible available model, including On-Device or Private Cloud Compute. Voice Writer cannot inspect or enforce the model selected by a user's Shortcut and does not hold Apple or OpenAI account credentials.
Learn more from Apple's System Language Model documentation, Apple's Use Model documentation, Apple Intelligence & Privacy, OpenAI's Apple integration data-handling notice, and the OpenAI Privacy Policy.
Keyboard and delivery
On iPhone, Full Access supports only the local App Group command, state, and insertion bridge between the app and keyboard. The keyboard does not own the microphone, collect surrounding text, or include a networking client. The host app owns recording and protected content. Copy and Share use destinations selected through the operating system.
On Mac, Accessibility access is optional. The separately enabled direct-paste and microphone-key options require this permission. For direct paste, Voice Writer selects the focused eligible text field when you stop recording with the assigned Shortcut or microphone key. You can change fields while recording. After Stop, keep that field and insertion point unchanged while refinement finishes. Voice Writer revalidates the destination, copies the result first, and issues no more than one Command-V only after destination and clipboard checks pass. If the Stop field is missing, changes, or is a password field or command console, Voice Writer copies the complete result once to the system clipboard and shows Copied. Complete Mac results are delivered without content or wording screening, including changed names, numbers, long text, and line breaks; you can correct the result yourself. If the clipboard cannot be written, the latest result remains available in the app for manual Copy. Voice Writer does not fall back to an earlier field and never presses Return or Send. On a supported built-in MacBook keyboard, the microphone-key option replaces Apple Dictation on that key while Voice Writer is running. Turning the option off or quitting restores the key. Both options are off by default, and no separate keyboard driver is installed.
Retention and deletion
- Recording deadline: Recordings and drafts are permanently deleted 30 days after recording, including saved drafts, Original / Raw transcripts, working text, edits, all refined or translated results, unresolved recovery work, and retained audio. Saving, editing, cleanup, translation, or moving a draft does not restart this deadline.
- iPhone latest-only storage: On iPhone, Voice Writer keeps the latest recording until a successfully started new recording replaces it, you permanently delete it, or its 30-day maximum expires. A failed start preserves the previous latest item. Existing libraries with older recordings offer review/export and explicit permanent deletion before latest-only cleanup begins. Export leaves originals in place until you delete them; exported copies follow the storage and deletion choices for the selected folder. Delayed edits and callbacks cannot restore permanently replaced content.
- Mac latest-only storage: On Mac, the latest recording remains available for recovery until a successfully started new recording replaces it, or until the 30-day deadline. A failed Start leaves the prior latest intact. Existing users can export older recordings to a chosen folder or permanently delete older recordings while keeping the newest before latest-only cleanup is enabled. Exported files are outside the protected library and follow the user's own storage and deletion choices.
- Legacy Recently Deleted: Where this remains available, the user-selected recovery period is one through seven days and does not extend the original 30-day recording deadline. You can permanently delete work earlier.
- Recording audio: Raw audio is removed after complete transcript and review persistence is validated, unless you enable Keep Audio Until Review Is Finished. That setting never extends audio retention beyond 30 days after recording.
- Cleanup: Voice Writer blocks access to expired recording content. If physical cleanup cannot complete, the app reports a cleanup issue and retries when it can run and access local storage. Settings are stored separately and are not subject to the recording deadline.
- Operational files: Content-free diagnostics are retained for seven days or until they reach 256 KiB, whichever comes first. Prior migration recovery copies are retained for seven days unless recovery remains unresolved, without extending the original 30-day recording deadline. Temporary protected sharing files are removed when no longer needed.
- Clipboard: The iPhone pasteboard expiry can be one minute, ten minutes, or one hour and is local-only where the operating system supports that option. The Mac pasteboard follows the user's system settings.
- Backups: Voice Writer requests backup exclusion for its private library, but cannot guarantee the behavior of independent backup tools or copies made outside the app.
- Deletion: In-app permanent deletion is authoritative for the local library. Because the company does not possess that library, support cannot remotely inspect, export, recover, or delete its drafts, transcripts, or audio. Uninstall behavior and device backups remain subject to the operating system and tools outside our control. The recording deadline applies to Voice Writer’s local library. Copies transferred to pasteboards, installed Shortcuts, model providers, or receiving apps and services follow their respective settings and policies. Deletion does not recall those external copies or system backups.
App Store disclosure
Optional ChatGPT refinement is conservatively disclosed as Other User Content used for App Functionality, linked to the user, and not used for tracking. This classification does not mean audio, incomplete recovery text, keyboard context, or diagnostics are transmitted.
3. How We Use Your Information
In compliance with Illinois law, we only use your data for the purposes disclosed at the time of collection:
- •To Respond to Feedback: We use your name and phone number to contact you regarding the specific feedback or support request you submitted.
- •To Provide RoozCast: We use RoozCast data to authenticate your account, verify subscription access, organize transcripts into summaries and tasks, maintain categories and schedules, send reminders, and support export or account deletion requests. Only after explicit consent, selected content may be processed by Google Gemini/Vertex AI, OpenAI, or Anthropic for the external-AI features you request.
- •To Sync Connected Services: When you connect Google Calendar or Google Tasks, Notion, or Fireflies, we use your authorization only to read, create, or sync the information needed for the features you choose to enable.
- •To Provide CommonShelf: We use CommonShelf data to maintain shared inventory locations, process inventory and history changes, support notification delivery and verification, and handle support or deletion-review workflows.
- •To Provide SecureShelf: We use SecureShelf data to authenticate members, enforce roles and billing state, process server-mediated inventory and membership changes, generate audit records, deliver notifications, provide export and continuity features, and support billing or administrative workflows.
- •To Provide MyCircles: We use MyCircles data to save local and cloud projects, authenticate signed-in accounts, generate share links and Live Share sessions, sync invited collaborators, process AI Ask queries, provide map/geocoding tools, manage subscriptions, enforce plan limits and abuse/rate limits, support exports/imports, and handle account deletion requests.
- •To Support Billing and Continuity: Where a product includes paid plans or export tooling, we use limited customer, subscription, audit, and export metadata to operate billing flows, prevent abuse, preserve accountability, and help users retrieve supported data.
- •To Provide Inkify: We use Inkify admin, license, organization seat, configuration, profile, and support metadata to render signing pages, verify access, operate optional saved profiles, send profile login codes, support PDF verification, and coordinate customer-owned Google Workspace processing.
- •To Provide ClearSlot: We use organizer, schedule, reviewed response, optional contact, AI-assist, Calendar free/busy, notification, billing, security, and privacy-request records to create schedules, collect availability, identify overlap, deliver essential updates, apply plan limits, and execute verified data-rights requests.
- •To Provide Voice Writer: The app processes local recording, transcription, recovery, review, editing, storage, delivery, and supported in-app Foundation Models refinement on the user's device. A complete finalized transcript leaves the local library only when the user explicitly chooses Shortcut provider refinement, Copy, Share, or diagnostic export.
- •Service Improvements: We analyze feedback data to improve our app's performance and user experience.
- •Consent-Based Communication: We will not use your phone number for marketing or automated messages unless you have provided separate, explicit consent.
4. Data Retention and Disposal (Illinois PIPA Compliance)
Under the Illinois Personal Information Protection Act (815 ILCS 530/), we are required to safely dispose of data that is no longer needed.
- •Retention: We retain your contact information only for as long as necessary to resolve your inquiry or for a maximum of 90 days following your last interaction with us.
- •RoozCast Retention: RoozCast check-ins, summaries, tasks, categories, schedules, and profile settings are retained until you delete them or delete your account. Temporary audio uploads are deleted after processing where possible. Crash and diagnostic records are retained only as long as needed for troubleshooting and service integrity. Shared-content safety reports are retained for up to 180 days unless a legal or security hold requires longer retention. Purchase, transaction, entitlement, tax, fraud-prevention, refund, dispute, and audit records may be retained after account deletion for the period required by law and provider, security, and accounting obligations.
- •Account Deletion: RoozCast includes an in-app deletion flow for both anonymous and linked accounts. It removes the authenticated user's ordinary product data, stored check-in audio files, third-party AI consent record, and Firebase Authentication account. It redacts the user's identity from retained shared-content safety reports. Limited billing, fraud-prevention, security, legal-hold, and audit records may remain as described above. This action is intended to be permanent and does not cancel a store subscription.
- •Unveiled Account Deletion: A verified deletion request fences new writes, removes ordinary Unveiled product data and the authentication account, and revokes attached Apple authorization where credentials are available. Choosing the in-app Apple unlink flow preserves the remaining account; revoking Sign in with Apple outside that completed unlink flow may require deletion of the still-attached account. We retain only bounded pseudonymous deletion receipts, security events, and independent tombstones needed to finish retries, prevent accidental restoration, meet legal holds, and prove completion. Support tickets are retained for up to 90 days after the last interaction unless a legal hold applies. An encrypted notification destination may be retained only until delivery or seven days after deletion.
- •Deletion limits: An offline device may keep a local copy until it reconnects and receives the deletion fence. Exported files, screenshots, device backups, and copies outside our control are not deleted by the service. Provider logs and encrypted backups age out under their documented schedules. Anonymous users who lose both the device session and recovery code may be unable to prove ownership through support.
- •CommonShelf Retention: CommonShelf location names, inventory data, history, notification preferences, delivery records, and deleted-item records are retained until they are edited, removed, or no longer needed to operate the service, support users, investigate abuse, or maintain service integrity.
- •SecureShelf Retention: SecureShelf secure-location content, membership records, audit events, deletion requests, billing metadata, support records, notification history, and export metadata are retained as needed to operate paid locations, support continuity and exports, prevent fraud or abuse, resolve disputes, and comply with legal obligations. Generated export files may expire from storage after their availability window closes even though related audit or billing records may remain longer.
- •MyCircles Retention and Deletion: A verified deletion request immediately fences cloud access. Owned projects and dependent cloud data, memberships, personal activity, files, profile data, and the authentication account are removed. Collaborator-required content in another owner's project may remain only after creator and modifier attribution is anonymized. The initiating installation is reset, and other signed-in devices reset before syncing again. Terminal operation records and sanitized application logs are retained for 30 days, verified support tickets for 90 days, provider revocation credentials for no more than 24 hours, and privacy-preserving offline-device markers for up to 400 days. ZeptoMail does not retain message content for MyCircles deletion notices; delivery metadata may remain for up to 60 days, and suppression records may remain as needed to prevent unsafe or repeated delivery. Legal holds and provider, tax, dispute, or accounting records may remain only for their approved purpose.
- •MyCircles Timing, Billing, and Backups: Healthy deletion targets completion within 75 minutes; identity-provider retries stop after 24 hours, and verified manual cases target resolution within 30 calendar days or sooner when required by law. Direct web subscriptions are scheduled to end after the paid period. Native subscriptions remain managed by their provider. Deletion does not automatically refund a charge. One eligible purchase restoration may transfer automatically to one verified replacement account; later transfers require review. Bounded backups are isolated and deletion tombstones are reconciled before restored user traffic reopens.
- •Inkify Profile Deletion: Inkify saved profiles are retained until the signer deletes the profile or the account is otherwise closed under the applicable product rules. Profile deletion hard-deletes the encrypted profile row and related profile authentication, session, and consent rows, but does not delete records already submitted to a form owner.
- •ClearSlot Retention: The exact ClearSlot periods and exceptions are stated in the ClearSlot section above. The cleanup process deletes short-lived security state, 90-day operational rows, 24-hour export artifacts, seven-day rollback bundles, expired Calendar credentials, and other bounded records without deleting active schedule data unless a verified deletion applies.
- •Voice Writer Retention: Voice Writer's latest-recording replacement, legacy Recently Deleted, unresolved-recovery, diagnostic, migration-recovery, temporary-sharing, clipboard, backup, and permanent-deletion boundaries are stated in the Voice Writer section above. Provider copies created by an optional model request follow the selected provider's controls and policies.
- •Secure Disposal: When your information is no longer required, we use industry-standard methods to delete electronic records, ensuring they are rendered unreadable and unrecoverable.
5. Third-Party Sharing
Data is a responsibility, not an asset.
We do not sell, rent, or lease our user lists to third parties. Because we are self-funded and owner-operated, your data is not—and will never be—treated as a financial asset to be sold, licensed, or leveraged to increase company valuation. We only share information with trusted service providers (who must comply with our strict privacy standards) to the extent necessary to provide our services.
Across all of our products, we do not sell personal data and we do not share personal data with third parties for their own marketing purposes.
CommonShelf uses third-party providers only to operate selected features: Firebase and Google Cloud for anonymous authentication, Realtime Database, functions, infrastructure, and push messaging; Zoho ZeptoMail for notification email delivery and verification; and browser or device notification services when you enable push notifications.
SecureShelf uses third-party providers only to operate selected features: Firebase and Google Cloud for authentication, Cloud Firestore, storage, functions, infrastructure, and push messaging; Stripe or another disclosed processor for checkout, subscriptions, invoices, and billing-portal flows; Zoho ZeptoMail for verification and notification email delivery; and browser or device notification services when you enable push notifications.
RoozCast uses third-party providers only to operate selected features: Firebase and Google Cloud for authentication, database, storage, functions, and infrastructure; Google Gemini/Vertex AI, OpenAI, and Anthropic for external AI processing after explicit user consent; Apple App Store and Google Play for native subscription billing; Google Calendar, Google Tasks, and Google Drive for optional user-authorized features; Notion for optional workspace sync; Fireflies for optional meeting context; Sentry for crash reporting; and Expo for push notifications. The website may also use Loops to process mailing-list email subscriptions.
MyCircles uses third-party providers only to operate selected features: Supabase for authentication, database, realtime collaboration, storage, Edge Functions, and durable account deletion; Cloudflare for the public deletion page, server-side proof exchange, status, support binding, and abuse controls, plus privacy-preserving restore tombstones only if an application-controlled restorable copy is introduced; Zoho ZeptoMail for tracking-free account-deletion completion and provider-action email; Google Sign-In and Apple Sign-In for optional account login and deletion-time proof; Google Gemini/Vertex AI, OpenAI, and Anthropic for AI Ask, semantic processing, and AI response generation where configured; Google Maps Platform for optional autocomplete and geocoding; OpenStreetMap for map tile display; Apple App Store, Google Play, Stripe, or another disclosed processor for subscription billing; and device/platform services for sharing, file import/export, camera/photo selection, QR scanning, and deep links. The dedicated deletion page and APIs do not use marketing analytics or advertising trackers.
Unveiled uses Supabase for authentication, database, Edge Functions, and account deletion; PowerSync for device synchronization; Cloudflare for the public deletion, proof, status, support, and independent tombstone services; Apple Sign-In, Google Sign-In, and supported email delivery for optional account linking and verification; and Apple App Store and Google Play for purchase processing and restoration. The dedicated deletion route does not use marketing analytics or advertising trackers.
Inkify uses third-party providers only to operate selected features: Google Workspace for form-owner processing, Cloudflare for Hub, routing, organization seat management, Inkify Help metadata, and encrypted profile storage, Zoho ZeptoMail for profile login-code and helper sign-in email delivery, Stripe or another disclosed payment processor for license, Team Seat, and saved-profile billing, and Google Gemini/Vertex AI for Inkify Help and limited signer-reviewed suggestions where enabled. Inkify does not use third-party advertising trackers for signer forms or saved profiles.
ClearSlot uses Supabase for authentication, database, and private encrypted request artifacts; Cloudflare for hosting and server processing; Zoho ZeptoMail for tracking-free authentication and essential status email; Stripe for hosted payment collection, subscriptions, invoices, refunds, and billing records; OpenAI, Google Gemini, and Anthropic for routed transcription and schedule assistance; Google Calendar for optional calendar-list and free/busy access; and Apple iCloud CalDAV for optional calendar names and free/busy timing. Provider processing and independently retained records also follow those providers' applicable terms and privacy practices.
Voice Writer uses Apple Speech for local transcription, Apple Foundation Models for supported in-app on-device refinement, and operating-system services for storage, pasteboard, Share, Shortcuts, and optional delivery. In-app Foundation Models refinement does not send the transcript to a third-party model provider. If the user runs a compatible Use Model Shortcut, the complete finalized transcript is processed by the model selected in that Shortcut—On-Device Apple Intelligence, Private Cloud Compute, ChatGPT/OpenAI, or another available model—under the applicable provider terms. This is a user-controlled Shortcut workflow, not a developer-operated model API integration.
6. Security Measures
We implement "reasonable security measures" as required by Illinois law to protect your data. This includes:
- •Encryption: Using SSL/TLS encryption for data transmitted through our forms.
- •Cloud Security: CommonShelf, SecureShelf, and RoozCast data use Firebase and Google Cloud services with encryption in transit and at rest. Product access boundaries may differ by product design, account model, and feature set.
- •Product-Specific Access Models: CommonShelf is intentionally open and shared, so it should not be used for confidential, regulated, or secret inventory records. SecureShelf is designed with authenticated accounts, role-based access, server-side authorization checks, audit logging for important actions, and private storage or access controls for supported secure-location workflows.
- •Integration Secret Handling: OAuth tokens, API keys, webhook secrets, and similar privileged credentials are stored separately from ordinary user content and redacted from standard export data where possible.
- •Access Control: Restricting access to personal data to only those employees or contractors who need it to fulfill their duties.
- •Voice Writer Local Security: The app uses protected app storage on iPhone, owner-only Application Support storage on Mac, content-free public surfaces, and fail-closed delivery. These safeguards reduce exposure but do not eliminate device, operating-system, provider, or user-controlled sharing risks.
7. Children's Privacy (COPPA)
Our services are not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If we discover such data has been collected, we will delete it immediately.
8. Data Breach Notification
In the event of a security breach involving your personal information, we will notify you in the most expedient time possible and without unreasonable delay, as required by Illinois PIPA (815 ILCS 530/10).
9. Your Rights and Contact Information
You have the right to request access to the information we have collected about you or to request its deletion. Please contact us at:
RoozCast users can also use the in-app Export My Data feature to receive a JSON copy of supported account data, and the in-app Delete Account feature to permanently remove either an anonymous or linked RoozCast account and ordinary stored data. Deletion does not cancel an Apple App Store or Google Play subscription; users manage cancellation through the applicable store.
CommonShelf users may contact us regarding shared-location data questions, notification subscriptions, or support-driven location deletion requests. Because CommonShelf is an open shared product, information other users have already viewed, copied, exported, or recorded may remain outside our control even after data is removed from our systems.
SecureShelf may provide export, billing, and support tools to authorized owners or administrators for supported secure-location data. Members may also contact us regarding access, export, or deletion questions, but some records may be retained for audit, billing, security, fraud-prevention, continuity, or legal reasons even after membership ends or content is removed from active views.
MyCircles users can use available in-app export tools to create supported project archives. Signed-in users can request permanent deletion in the app or at the public MyCircles account deletion page. The public flow accepts only fresh email proof or an Apple or Google identity already linked to the account. Support cannot substitute an unverified email, purchase record, arbitrary identifier, or private project content for proof. Exported files and copies a collaborator independently controls remain outside the deletion service.
Unveiled users can permanently delete anonymous or linked accounts in the app or at the public Unveiled account deletion page. The website supports linked-email proof and a recovery-code route for anonymous accounts. Support can explain proof options and refresh an already verified operation, but cannot accept an account ID or create a replacement deletion operation.
ClearSlot organizers and participants start access or deletion requests inside ClearSlot so the product can verify the exact subject and scope. The NaborlyDone support handoff carries only the resulting opaque request ID. Deleting an invited organizer account removes that person's memberships and personal Calendar connections without deleting the Organizer Team's schedules or billing. Owner deletion follows the reviewed transfer-or-delete process; deleting the whole billed Organizer Team may cancel associated ClearSlot billing immediately and does not automatically refund unused time except where required by law. Participant deletion removes only the verified response, contact, reviewed availability, and event-scoped Calendar connection; participants do not have a ClearSlot Auth account to delete.
Voice Writer users exercise access, export, and deletion choices inside the app. On iPhone these include Latest Recording, Review, Copy, Share, and permanent deletion; users with older recordings can also review or export them before choosing permanent deletion. History and Recently Deleted are available only while older recordings or cleanup issues need attention. On Mac these include the latest result, Copy, recovery, and a one-time older-recording export or deletion choice. Support can explain these controls but cannot access or act on the private local library. Requests concerning an optional model transfer must also use the selected provider's account and privacy controls where applicable.
Neighborhood Technology Solutions LLC
1847 W Morse Ave. Chicago, IL 60626
Email: support@naborlydone.com
Phone: (773) 942-0995
