Privacy
Plain answers about your data
Most privacy policies are written to protect the company from you. This one is written so you can actually check up on us. Everything below describes what the site really does today — when the site changes, this page changes with it.
Effective August 5, 2026
The short version
- We never sell your data. No ads, no brokers, no quiet “partners.”
- Your words are never used to train AI — not by us, and under our agreement with Anthropic, not by them either.
- To everyone on the network you are your handles. There is no real-name field anywhere on this site.
- You can download everything we hold about you, or delete your account and take your words with you — built into your member page, not a support ticket.
- Where we can’t promise something, we say so here instead of rounding up.
Who we are
Diversify All, Inc., doing business as All Good People Foundation — a 501(c)(3) public charity (EIN 83-2608475), registered with the California Registry of Charitable Trusts (No. CT0297107). Questions about anything on this page: info@allgoodpeople.net. A real person reads it.
What we collect, and why
Your phone number
Used to text you a verification code when you join, and again when you log in. Proving you’re one real person is the only thing we ever asked for it. Nothing else reaches that number unless you switch texts on yourself under “Choose how we reach you” on your own page — a separate decision, recorded with the exact words you saw, because holding your number is not permission to use it. Turn those off any time there, or reply STOP to any text. It is never shown to another member, never used for marketing you didn’t ask for, and never sold. It is the one real-world identifier we keep.
A handle you choose
Your name here. You can carry different handles in different rooms, so even your ideas can’t be stitched together into a profile of you by other members.
An email, only when you hand us one for a job
A donation receipt (that address lives with Stripe, our payment processor — our own database has no donor list), notifications you switched on (removable anytime, and unsubscribe works straight from the email, no login), or writing to us.
What you choose to bring
Posts, survey answers and the notes you attach to them, your watchlist, favorites, and the everyday details you tell your AI. When you import something — contacts, bank rows for a budget — we keep only the entries you individually tap. The file itself is never kept.
Payment records, barely
Stripe handles money start to finish; your card number never touches our servers. We keep a card fingerprint — a code Stripe issues, not your number — so a card can’t be used to create endless memberships.
Receipts of your choices
Every optional data use starts switched off. When you say yes or no, we record the exact wording you saw and when — so both of us can always check what was actually agreed. These receipts leave with you — delete your account and they go too.
What we deliberately don't collect
Your real name
There is no field for it. We couldn’t leak or sell what we never asked for.
Your AI conversations
They live in your browser and vanish when the tab closes — unless you tap Keep, in which case that conversation is stored for you alone.
IP addresses
Not stored in our database. They’re used only in passing memory to slow down abuse, then gone.
Anything a crisis brings you here with
Safe Harbor conversations are never written to our database and never analyzed, and the safety pages carry no analytics at all. The Safe Harbor vault is encrypted on your own device with keys we never have — if we were forced to hand it over, we could not read it.
Anonymous to people — verified to us
To other members, you are your handles. To us, you are a phone number and whatever you chose to bring. We won't pretend it's “anonymous to everyone, including us” — keeping this a network of real people requires that we hold your number. Precise promises beat pretty ones, so that is the promise: pseudonymous to the world, minimally known to us, sold to no one.
Your AI, plainly
Everything you bring here — survey answers and the notes you attach to them, favorites, your watchlist, the small facts of your life you mention — becomes one picture. Your AI draws on that picture for exactly one purpose: to be better for you. Not to target you, not to sell you to anyone, not to train anything.
Mechanically: when you talk with your AI, our servers send the conversation plus the relevant parts of your picture to Anthropic, the company whose models power it. Your handle goes; your real name doesn't exist here to send; and your reading list is deliberately never included — what you read stays between you and the page. Under our agreement with Anthropic, what you and your AI say to each other is not used to train their models. We can vouch for what leaves our servers and for what our contracts say; we can't personally stand inside another company's walls — so we name every provider on this page instead of making promises on their behalf.
Your Pulse answers are part of that picture — including the private note. When you tap an answer on the Pulse and add a note to it, that note is private in the way you'd expect: no other member sees it, and the public results are counts, never people. But it is not private from your own AI. Your answer and the words you wrote alongside it are saved to your picture, and they travel to Anthropic whenever you use something your AI does for you — a conversation with it, the read it writes about you, a fresh round of questions it makes for you. That is how it picks up something you actually said instead of asking you again. Every one of those is something you start; none of it runs on its own. Separately, answers to Pulse questions we imported from SurveyMonkey are mirrored back there for counting — the answer only, with no handle, no member id, and no note.
Your four letters — whether scored here or typed in because you already knew them — are part of that same picture: no other member ever sees them, they are never sent to any outside service, and they play no part in matching, notifications, or anything shown to anyone but you and your own AI.
The public AI on this site works the same way with less: it sees the text of the conversation and nothing about who you are.
Who touches your data
None of these are “data sharing partners.” Each is a tool doing one job, and each gets the minimum that job requires. Our servers talk to them; you never do.
Stripe
PaymentsCard details (which never touch our servers), a donation’s receipt email and the name you type, and your phone number inside membership checkout records.
Anthropic
Every AI featureThe text of AI conversations, and for your own AI, the picture you’ve built — including your Pulse answers and any private note you attached to one — under your handle, never a name, never your reading list.
Supabase
Our databaseWhere member data lives. Every table is locked with row-level security; the only road in is through our servers.
Vercel
HostingServes the site, and counts page visits (counts, not profiles). Switched off entirely on the safety pages.
Twilio
Sign-in codes, and texts you asked forYour phone number, to text you a login code — and, only if you switched texts on, the notifications you chose. Reply STOP to any of them and it stops at Twilio and here, in the same moment.
Resend
EmailThe address and contents of email we send you or you send us.
SurveyMonkey
Pulse analysisSurvey answers only — no handle, no member id, no email attached.
Printful
Merch fulfillmentThe shipping name and address you give Stripe when you order a physical item.
Amazon and Bookshop.org
Shop and book linksIf you click a shop or book link, that store sees its own search and pays us a small commission — Amazon through a 24-hour cookie it sets, Bookshop through a code in the link. Neither learns anything about your membership from us.
When a web lookup runs, the question text goes to the provider — the question, not you. We also ask Google’s YouTube search which video a song is. And if you choose to bring in your contacts, you sign in at Google yourself: we hold that permission only while the window is open, hand it back when you close it, and keep only the people you individually tap.
OpenAI
Optional web lookups, and mark artThe same lookups, the same rule — the question, not you. And if you draw yourself a mark, the words you type to describe it go to OpenAI to make the picture.
Who runs inside your browser
These are different, and the difference matters more than the heading suggests. We aren't handing them anything — their own player or picture loads onto the page you're already on. So they see you the way any site you visit sees you: your IP address, and whatever they already had on your device. We can't stand in the middle of that and we won't pretend we do, so we name it instead. All of it happens on the music, watch and game surfaces when you play or open something — not on a page you're only reading.
YouTube (Google)
How most music playsThe music player uses YouTube unless you pick something else, and YouTube’s own player runs on the page. Loading it tells YouTube your IP address and which video, and if you’re signed in to Google anywhere, that player is signed in too — including the cookies that come with it. Song thumbnails load from YouTube as well. The one place we could avoid all of that we did: a mixtape sent to someone who isn’t a member plays on YouTube’s no-cookie host and sends no referrer.
Apple
Music playback, if you pick itChoose Apple as your player and Apple’s MusicKit loads in your browser, where you sign in to your own Apple Music account. That sign-in is between you and Apple; it never comes to us. Album covers on the music, podcast and audiobook shelves are served from Apple too.
Spotify
Music playback, only if you connect itNothing about Spotify runs until you connect it. When you do, you sign in at Spotify, their player loads in your browser, and it talks to Spotify directly using a key kept in your browser’s own storage — that key never reaches our servers, so your Spotify account isn’t something we can see. What we keep is only what you save here.
JustWatch
Show and movie postersWhen you search for something to watch, the posters come straight from JustWatch, so they see your IP address. The search words go through us, not from you.
The Art Institute of Chicago, and flagcdn
Pictures in two of the gamesThe painting game and the country game show real images loaded from those sources into your browser, so they see your IP address. Neither is told anything else, and neither knows a game is being played.
Where we look things up for you
Search for a song, a show, a book, a station or a company and we ask whoever has the answer. The question travels; you don't. They see our server and the words you searched for — no handle, no member id, no account, nothing that says which of you asked.
- AppleMusic, podcasts, audiobooks and games you search for
- JustWatchWhich service a show or film is on
- WikipediaDetails behind a game or a title
- Yahoo Finance, the SEC, and Senate lobbying recordsThe prices, filings and disclosures behind your watchlist
- Radio-BrowserRadio stations
- GIPHYGifs, when you search for one to share
- The National Weather ServiceToday's forecast when you ask about the weather
- LibriVoxFree audiobooks
- LichessThe daily chess puzzle
- The Art Institute of Chicago, the World Bank, and flagcdnThe pictures and facts the brain games are built from
What you control
Download everything
One tap on your member page exports everything we hold about you — your words, answers, messages, receipts, all of it. “Everything” is the promise.
Delete yourself, two ways
Leave your words behind (re-signed as from a former member) or take them with you. Either way your identity, phone number, and vault are erased, and your handles retire forever — nobody can wear them after you.
Messages kept only by mutual choice
A direct conversation is saved only if both people choose to keep it.
Every optional use starts at no
Consent switches default off. Flip one, and the receipt records the exact words you agreed to. Flip it back anytime.
Cookies
A signed login cookie keeps you signed in for up to a year. A few small ones remember plain things — whether you've seen an intro, where you were in a form. If you arrive from an ad, one remembers only which ad, so we can tell that service its ad worked and nothing else about you.
None of ours follow you to other websites, none build a profile of you, and none of what they hold is sold. Our host counts page visits without profiling people — switched off entirely on the safety pages, along with everything else on this list. Ask us what any cookie does and we'll tell you plainly.
Two other companies can put their own cookies on your device, and both are named above rather than left for you to find. Amazon, if you click a shop link. And YouTube, whose player carries Google's cookies with it when you play a song — which is the honest reason that player has its own section on this page. Neither is ours, and neither is told anything about your membership by us.
Security, briefly
Every database table is locked with row-level security — the only path to data runs through our servers, which check who you are on every request. Cards are handled entirely by Stripe. The Safe Harbor vault is encrypted on your device with keys that never reach us.
Children
The network is not directed to children under 13, and membership verification is built for adults. If you believe a child has given us information, write us and we will delete it.
When this page changes
We're a U.S. nonprofit, and this page is written to exceed what the law asks of us — in words you don't need a law degree to read. When it changes, the date at the top changes with it; if a change actually matters, we'll say so plainly on the site rather than bury it. This is version one, written the week the network opened its doors. Hold us to it: info@allgoodpeople.net.
