Privacy and planning notice
Notice version: 2026-10-05.planning-v3. Effective October 5, 2026.
Your brief, your information and your choices
At a glance
- The free worksheet, calculator and demonstration run in your browser.
- Saving a brief stores its answers; submitting an inquiry is a separate action.
- An inquiry shares your brief and contact details with Malachi for human review.
- Anyone holding your private resume link can read the saved brief and published replies.
- Copies exist on the hosting system, in provider backups and on the owner's protected Mac. Some backup copies can remain after an active record is deleted.
- Contact privacy@stratavyn.ca about access, correction, consent withdrawal or deletion. The sections below explain verification, retention and backup limits.
This summary highlights the main choices. The complete notice follows.
Who operates Stratavyn and why information is used
Malachi Bonus operates Stratavyn. We use a brief you save and an inquiry you submit to understand your proposed workflow, check existing-tool options, identify required access and human approvals, and prepare a response at your private resume link.
A brief or inquiry is not an order or a commitment to build. It does not authorize crawling, paid AI, access to your accounts, a quote or payment.
What stays in your browser
The free worksheet, capacity calculator and synthetic demonstration run locally in your browser. Copy, download and print are local actions.
Moving worksheet answers to the configurator uses this tab's session storage. Refreshing an unsaved worksheet loses its entries. Opening the introductory workflow form alone does not create a saved server record.
Choosing an example, configuring functions or using guided suggestions can create a private saved draft. Explicitly saving your workflow brief is separate from submitting an inquiry.
The configurator stores your private resume access key in this browser's local storage to reopen the draft on this device. Your full private link also contains that key after the # symbol. Use a trusted browser and keep the link private. Clearing browser storage removes the remembered link, not the server record; keep your own private bookmark if you want to return.
The protected owner inbox uses an HTTP-only, same-site session cookie after login. There is no visitor account or advertising cookie in this flow.
What a saved draft contains
A saved build contains your starting goal, selected and required example functions, interface choice, activity dates and any source or evidence records already attached to it.
If you explicitly save a workflow brief, we also store your:
- Desired result and current process.
- Repeated friction, frequency and role-only example.
- Tools, attempted fixes and performer, approver and process-owner roles.
- Constraints, proposed access and optional deadline and investment guidance.
These are your statements, not verified facts or permission to access your systems. Use anonymized examples and roles. Do not enter credentials, confidential files or private customer records.
What an inquiry contains
When you explicitly submit an inquiry, we copy the saved brief into a frozen review request. We also store your name, work email, business, selected situation, answers about systems, documentation, data categories and approval roles, optional description, consent time and notice version, request status and response history.
Attached source or evidence records are copied into the review request. There is no document-upload feature in this flow, and the public flow does not scan your website.
We store a hash of the private resume token and limited security and event metadata. Submission-abuse controls include a keyed hash of the IP address. The inquiry rate-limit table does not store the raw IP address. Counters older than approximately 24 hours are cleaned on subsequent limit checks; inactivity or older backups can retain them longer.
Hosting, security logs and browser access
Hosting and proxy operational logs can contain connection addresses, requested paths, times, status codes and error categories. Application error records use redacted categories and request identifiers rather than submitted bodies. The inquiry rate-limit table's hashed-address rule is not a claim that all hosting logs exclude IP addresses.
Container logs rotate by size and file count, not a guaranteed number of days. Host service journals and provider logs can have different retention; no time-based expiry for those logs is promised here. Do not put private information or access keys in URL query fields. The private resume key is carried in the link fragment and sent to the app in an authorization header, not in the requested URL path.
Who can access it and where copies are stored
The active database and on-server database snapshots are on Stratavyn's OVHcloud VPS in Beauharnois, Canada. The owner inbox requires a private SSH tunnel, password and authenticator code.
Your private resume link acts as an access key. Anyone holding it can reopen the full build and read replies the owner explicitly publishes. Keep it private. Deliberately shareable example summaries exclude your free text, contact details, private replies and resume token.
Host and backup administrators can access protected database copies. Copies also exist in OVHcloud's whole-VPS backup service and on the owner's FileVault-protected Mac. We have not independently verified Canadian residency for every provider-held copy.
No advertising, paid AI or payment service receives these planning entries or inquiries through this flow.
Privacy-request email is forwarded by the domain's provider to the owner's controlled mailbox. Include only the details needed for your request.
How you receive a response
A human response appears at your private resume link only after the owner explicitly publishes it. No automatic inquiry or reply email is sent. Save or bookmark the link before leaving and return to check for a response.
Optional notifications are not part of this release. Any future notification feature would need separate opt-in and verified delivery configuration and would not include proposal details or the private access link.
How long active records are kept
The following periods determine when records become eligible for erasure; they are not guaranteed completion dates:
- Unsent build
- 30 days after its last saved change. Viewing the resume link does not extend this period.
- Closed, unquoted inquiry and its responses
- 30 days after closure.
- Open, unquoted inquiry and its responses
- 90 days after submission.
A daily job queues eligible records. A queued build remains readable until erasure, but cannot be edited or submitted. Quoted records or documented holds require separate review. No quote service is available through this launch.
Deletion and remaining backup copies
Before an active record is erased, a deletion instruction containing opaque record IDs, dates and reasons—not contacts or response bodies—must be transferred off-server and verified by restoring a separate copy.
If the owner's Mac is asleep, offline or unavailable, finalization waits until the owner arranges a verified transfer. We do not report deletion as complete while this step remains outstanding.
Future policy-tagged on-server public-database snapshots and Mac database backup sets become eligible for expiry 30 days after creation. They are removed on the next successful approved expiry run at that location. An offline Mac cannot run its expiry job. These are eligibility periods, not guaranteed deletion dates.
Existing pre-policy backups remain protected without automatic expiry, rewriting or deletion. Later disposal requires a separate owner decision.
The previously verified OVHcloud Premium configuration records daily backups at 17:57 UTC and seven rolling daily restore points, replacing the oldest once full. This is a historical verification, not a claim of a new inspection. Stratavyn's scripts do not control or delete those provider restore points.
As a result, backup copies may retain information after it has been removed from the active database.
What happens if a backup is restored
A restored service remains offline until the latest verified off-server deletion record is obtained, replayed on an isolated copy and checked. A missing or older deletion record, hold or contractual conflict requires manual resolution.
The opaque-ID deletion record does not automatically expire while older backups may still need it. A whole-VPS restore may also restore old credentials; exposed credentials must be rotated and sessions revoked before the owner inbox reopens.
Access, correction, withdrawal and deletion requests
Email privacy@stratavyn.ca to request access, correction, withdrawal of consent or deletion. No phone call is required. Do not send passwords, API keys or private customer records.
We verify control of the resume link or use another suitable verification channel before acting. After recording a verified withdrawal, the owner stops further review and response publication. Withdrawal is not a claim that existing published replies or backup copies have been deleted. We explain any legal or contractual restriction and any information that must remain subject to the retention and backup arrangements above.
For a verified deletion request, the owner can queue an unquoted record for deletion. The service target is seven days from verification unless a documented legal requirement prevents it. Completion still requires verified off-server acknowledgement. If completion is delayed, the owner must explain and resolve the delay rather than claim the record has been deleted.
Staging preview
The shareable staging preview accepts synthetic planning details only, into a separate database. It does not accept inquiries, provide an owner inbox or make provider calls.
Staging restart snapshots are separate. No automatic staging expiry date is promised. The production periods above do not establish a scheduled staging deletion job. Existing backups were not removed for this review.