Privacy design
Your address is an admission credential, not content.
This is a development draft, not a final Privacy Notice. It separates controls that exist in this product from work that must be completed and legally reviewed before public member collection.
What we collect
When identity and database services are enabled: your verified work or academic email, identity-provider subject, affiliation, the profile fields you choose, and narrowly necessary security and membership events. The production pilot restricts membership through verified affiliation and admission.
An unsaved profile draft stays in this browser tab's session storage so a refresh does not erase your work. It is removed after you save or discard it, and it is not analytics.
Photos and resumes
Optional profile pictures follow your current profile audience. Image metadata is removed before storage. Raw resume files stay private; only the work and education entries you attach appear on your profile. MR Black membership never widens your profile audience.
Posts and conversation context
Posts, their photos and videos, your asks and offers, and optional status follow your current profile audience. Status expires after the time you select; it does not track whether you are online. Post media is stored privately and checked again when opened. Removing a post stops access immediately; stored files are erased by scheduled cleanup.
Shared-Peer introductions require opt-in from the intermediary and recipient. Your intermediary can read your request and pass its reason to the recipient. Accepted Peers can exchange private text messages. Ending the relationship stops access to that conversation, and removing your own message erases its text here. These controls cannot remove copies someone has already saved.
Device access and contact cards
Notification permission is optional and separate from notification preferences. Delivery is not active yet. The iPhone app asks for Contacts access only when you choose Add to Contacts for an accepted Peer. You review their displayed name and professional details before saving; no email or phone number is included. The web app offers a contact card you choose to share or download. We do not read or upload your address book or use it to find or invite members. Copies saved outside Regard follow the receiving app's controls and are not removed when a Peer relationship ends.
Pages you publish
Club, organization and project pages are public when you publish them. Anyone with the link can read the name, description and links you add. Your private profile and account details are not attached. You can edit or delete a page in My pages; deletion stops the page being served here, but cannot remove copies made by other people.
Who can see the email
Member-facing payloads omit email. Administrators see masked addresses by default and may reveal one full address only after server authorization, a stated purpose, recent authentication, and an audit event. Bulk raw-email export is not implemented.
What we will not do
We do not scrape or generate individual work emails. We do not place emails in URLs, analytics, notification text, or AI prompts. We do not sell visibility, Intro credits, or access to member contact details.
Optional diagnostics
Diagnostics are optional and off by default. You can opt in under Settings where they are available. Only daily totals of main screens opening, recovery screens and retry actions are stored for 30 days. Error messages, stacks, page addresses, account identifiers and member content are excluded.
Your choice is a single on/off preference saved in this browser. Turning it off stops new collection; existing aggregate counts cannot be linked back to you and expire automatically. There is no advertising, session replay or tracking across sites.
Optional MR Black payments
When purchases are enabled, Stripe hosts payment and billing-management pages. Regard sends an opaque account identifier, edition and subscription plan to link your purchase. We do not send your private work or school email, profile, messages or contacts. Stripe collects the billing details you provide on its pages; Regard does not receive your full payment-card number. Private payment-provider identifiers and verified subscription events support access, restoration and billing records.
Billing records follow applicable retention requirements separately from optional diagnostics. Contact support about an account-deletion request while a subscription is active. You can manage an existing purchase even when affiliation access has expired.
Manage billingYour controls
Required legal acceptance is versioned and kept separately from optional consent. The control plane supports scoped correction, export, consent-withdrawal, and deletion requests with opaque receipts, visible timing, retention exceptions, and cancellation while a request is still eligible. Provider-bound identity checks, fulfillment operations, retention-policy approval, and legal copy still gate production member collection.
Open your data controls