What we store, what we reuse, and the line we don’t cross.
This page states what this product actually does with your data — nothing here is aspirational. For how a finding gets graded in the first place, see the method page; for the legal terms, see the privacy policy.
Your documents, your holdings, your results.
When you upload investment documents, we store the documents themselves, the holdings and identifiers we extract from them, and the analysis results — the per-commitment findings, the evidence behind them, and the report built from both.
Your own governance acts are stored too, and durably: your mission and IPS text, the commitments your committee has ratified, and any committee adjustment to a drafted finding. Those are your record, kept with attribution and a date — not analysis the product produced, but decisions you made.
Your documents and results never cross to another user on their own.
This is a product invariant, not a policy we could quietly relax: no analysis, no uploaded document, and no personal information reaches another customer as a side effect of how the product works. Nothing you upload is pooled, and no other customer’s analysis can read from yours.
You can deliberately share, and that is the one way anything crosses. An owner may share a completed analysis with a named person by email; that person can then open that analysis’s report. It is your act, on one analysis, to a recipient you name — but it is real, so this page says so rather than claiming an absolute the product does not hold.
Public market and filing data is reused — your data never is.
Separately from that boundary, this product treats public data differently on purpose. When it calls a public source — SEC EDGAR filings, grounded web research — it persists everything useful the call returns, not just the slice one analysis needed: full holdings, full research responses and their sources, every identifier resolution including a negative one. That record is reused across analyses, for any user, because it describes the public market rather than any one client.
That reuse never mixes in client data. The public record stays public data — your documents, holdings, and results are never folded into it, and nothing pulled from it for your analysis is attributed back to you in a way another user could see.
How much a third-party finding tells you about its source depends on where you read it.
Some of what a report says about a holding comes from someone else’s dataset — fund grades, signatory lists, financing records, impact-registry entries. Attributing those to the dataset behind them is what this product is trying to do everywhere, and it is why a dataset we haven’t loaded produces an omitted section rather than a filled-in guess. It is not yet something we can tell you holds on every page, so the rest of this section is what actually happens rather than what we intend.
The written report carries the most: the source named, its vintage, its URL. Others carry less. The CSV export has vintage columns for some datasets and none for others, and no source-URL column at all. The in-report badges carry the source and its value, but not a link. And a structured receipt can record an impact-registry certification against a holding carrying no source, no vintage and no URL beside it — that one names no dataset at all, which is why the paragraph above stops short of promising you it always would.
A single, uniform “source, vintage, and URL, everywhere it appears” guarantee is what this should become. It is not what the product does today, so this page does not claim it.
No person writes a finding into your report.
The engine produces the findings — a grade, a dollar figure, a severity, a narrative, a citation — from evidence, and that is the whole design: there is no hand-scoring screen in this product, and building one is ruled out rather than unbuilt. Where the evidence isn’t enough to support a judgment in either direction, the report says so as a named absence rather than defaulting to a number that implies certainty the evidence doesn’t support.
The honest edge, stated plainly rather than in a footnote: a transitional path still exists that accepts report content from an operator, and what it accepts is not cosmetic — it includes the graded rows themselves, along with coverage, collisions, discharge and receipts. A report assembled that way is readable through the ordinary report surfaces. That path is scheduled for deletion, not retained as an option, and no client report is meant to travel it — but while the code can still do it, we will not tell you that no person has ever authored any part of any report.
The one exception is your own governance acts, described above under “What we store” — your mission, your ratified commitments, your committee’s resolutions. Those are decisions you made, not analysis we produced, and the line between the two is the one this product holds everywhere: you state what you believe and decide what to do; the engine states what is true about the portfolio.
Not yet published.
This page does not state how long documents, results, or account data are kept, or when anything is swept or deleted, because no retention schedule exists in this product today to publish. Naming a period here would imply a policy we cannot guarantee.
For the legal terms that do exist today, see the privacy policy.