Account activity & privacy
Free browsing and private codes
Browsing the public directory does not require an account. A private access code opens one workspace without an email or external sign-in. Treat your code like a password: anyone who has it can access that workspace. Use one code per person. The administrator issues and can revoke codes; only hashes of codes and session tokens are stored in the database.
Your workspace
After entering a code, you acknowledge the activity notice before creating a profile. We collect your first and last name and store them together as your display name. We also store your assigned member label, internal account ID, saved roles, stages, notes, and account dates. A secure sign-in cookie lasts up to seven days. No marketing signup is implied. Existing browser-local directory notes are not automatically imported.
Admin visibility
The administrator can see names, member labels, account dates, code usage, workspace visits, tracked roles, stage updates, and application-link openings. Private note contents are excluded from the admin dashboard but are stored on the server and are not end-to-end encrypted. Authorized infrastructure access may permit access for maintenance. Avoid passwords or sensitive personal information in notes.
We do not record keystrokes or activity on employer websites. Opening an application link does not mean it was submitted. The workspace does not submit applications.
Retention and deletion
Tracked roles and profiles remain until removed. Activity is displayed for up to 90 days, with older events removed on later workspace updates. Expired sign-in sessions and temporary rate-limit records are cleaned up on later sign-ins. Sign-in rate limiting uses a salted hash of the network address, not the raw address.
Use Account & privacy to export or delete your workspace. Deletion removes the active profile, roles, notes, events, access codes, and sessions for that workspace. A separately submitted waitlist signup and browser-local directory notes are not affected. Infrastructure backups may retain prior copies according to provider retention settings.
Hosting
Role Atlas runs on OpenAI Sites and Cloudflare infrastructure. Hosting providers process information under their own terms and policies. No external sign-in account is required.
Return to workspace