Privacy & data handling
Your team tells us about their work. Here’s exactly what happens to those answers.
No legalese. This page describes what the system actually does — what we collect, what gets stripped, who sees what, and how to reach a human.
What we collect
- Your workshop organizer gives us your name, work email, and role so we can invite you.
- The intake form asks about your work, not about you: your department and the systems you use, how often recurring tasks come up and how draining they are, rough hours per week, your AI experience and comfort, and a few free-text questions about what you’d want help with.
- To confirm it’s you, we email a one-time code to the address you were invited at.
- While you fill in the form, your in-progress draft autosaves — in your browser and to our server, so you can pick up where you left off on another device. Drafts are private to your invite link, are never shown to an AI model, and are replaced by your screened submission when you press Submit. Abandoned drafts are automatically purged.
What gets stripped before storage
Every submission is screened on our servers before anything is stored. Text matching a high-confidence sensitive pattern is replaced with a [REDACTED] placeholder:
- Payment card numbers (checksum-validated, so prose isn’t mangled).
- US Social Security numbers in standard format.
- API keys and access tokens, by known prefixes and long high-entropy runs.
- Anything labelled as a password, passcode, PIN, or secret.
This happens when you press Submit — before your submitted answers are stored or shown to any AI model — and it’s one-way: the original text of a submission is never kept. In-progress drafts are stored as typed (screening text mid-edit would mangle what you’re still writing) and are deleted on submit or purge.
The screen is deliberately conservative — it removes secrets, not your words. Your name and work email are part of the engagement on purpose. The form itself warns against including client names or policy numbers, and answers containing long number runs are marked for attention.
Who sees your answers
- Your individual answers are never published. They’re turned into aggregates — response rate, comfort mix, ranked pains — and those aggregates drive the report.
- Reports describe the room: counts, mixes, and recurring pains in the team’s own words. An approved report can be shared with your organization by link.
- For AI-assistant engagements, per-person priority profiles are also generated so the assistant fits each person’s actual work.
- Stored responses are accessible to the consultant team operating your engagement.
What the AI does
Primer uses Anthropic’s Claude to draft reports and workshop materials from the response set. The model only ever sees the screened, post-redaction answers.
The AI drafts; people approve. Deliverables start as drafts and are reviewed and approved by the consultant before your organization sees them.
The AI-assistant tier
Some engagements go beyond the workshop: a governed AI assistant connected to your team’s tools. For those:
- Gmail access is read-only by default. The default connection cannot send, archive, delete, label, or modify email. Write access is a separate, explicit opt-in.
- Actions are drafted by the AI and held for human approval, unless the engagement’s approval policy explicitly allows a category to run unattended.
- Assistant activity logs — runs, events, approval items — are automatically purged after a retention window, 90 days by default.
Retention & deletion
Intake responses are kept for the life of the engagement so reports can be regenerated and compared. Assistant activity is purged on the schedule above.
Want your responses corrected or deleted? Email twells@rocksteady.ai. We’re a small team — a human reads it.
Questions
Anything unclear, or anything you’d want us to handle differently: twells@rocksteady.ai.
This page describes the system as of June 2026.