PurposeMapped

Privacy & Security Policy

Version 2.0  ·  May 2026

Your Privacy. Your Security. Complete Transparency.

Everything you share with PurposeMapped stays exactly where it belongs — in your private environment. Here is exactly how we make that true.

1. Your Data Belongs to You

2. What Data We Actually Collect

Transparency starts with clarity. Here is every piece of data PurposeMapped collects from you:

Account & Profile Data

Data TypeWhat We CollectWhy
Email Address Your email for account login and password recovery Authentication & account access
Account Name Display name for your account dashboard User identification within your environment
Subscription Status Plan type, renewal date Service delivery & billing

Payment Processing: Card information and payment history are processed and stored by Stripe (PCI-compliant payment processor). PurposeMapped receives only subscription status webhooks from Stripe; we do not store or access full card data.

Service Providers & Subprocessors

PurposeMapped uses a limited number of service providers and subprocessors to operate the Service. Depending on the features you use, these may include hosting and infrastructure providers (such as AWS), payment processors (such as Stripe), email and integration providers (such as Google), and AI model providers (such as Anthropic, OpenAI, and Google). These providers may process personal data on our behalf only for the purposes described in this policy and subject to applicable contractual and legal restrictions.

Profile & Configuration Data

Data TypeWhat We CollectWhy
Values Assessment Scores Your responses to the 8-question values quiz and calculated scores across 10 values Creates your psychological profile; personalizes companion behavior
Companion Choice Which companion type selected, companion name, selected portrait Determines companion personality, voice, interaction style
Onboarding Responses Answers to all setup questions Configures companion to match your needs and context
Interaction History Conversation history is retained within your user instance and companion bot to provide continuity. PurposeMapped does not maintain a separate central repository of your conversation history, except for limited transient processing, security logging, backups, and service-provider records as described in this policy. Allows companion continuity within your isolated environment

Technical & Usage Data

Data TypeWhat We CollectWhy
IP Address Your IP when you log in or interact with the Service Security (login verification, fraud prevention, abuse detection), service operations, and limited usage analytics
Device / Browser Info Device type, browser version, operating system Product stability, security, compatibility, and optimization
Usage Timestamps When you log in, when you interact with your companion Session management, security, audit trails, and feature usage analytics
System Events Non-identifying logs of instance health, errors, or system events (flagged for oversight when needed) System reliability, security monitoring

Cookies & Tracking Technologies: PurposeMapped uses session cookies and similar technologies to authenticate your session, maintain login state, and support core service functionality. We may also use limited analytics cookies or tokens to collect non-identifying information about how the Service is accessed and used. We do not use advertising cookies or third-party behavioral tracking technologies. You may disable cookies through your browser or device settings, but doing so may impair or prevent your ability to access or use the Service. A description of the cookies used by PurposeMapped and their applicable retention periods is available upon request at support@purposemapped.com.

Integrated Third-Party Data (Optional, User-Authorized Only)

IntegrationWhat We AccessUser Control
Gmail Email metadata and content that you specifically authorize through Google OAuth, including message subject lines, sender and recipient information, message bodies, labels, and draft content, solely to enable the Gmail features you request. You explicitly authorize access through Google OAuth. You can revoke access at any time through your Google account permissions.
Google Calendar Calendar metadata and content that you specifically authorize through Google OAuth, including calendar names, event titles, participants, times, descriptions, locations, and availability information, solely to enable the calendar features you request. You explicitly authorize access through Google OAuth. You can revoke access at any time through your Google account permissions.
Google Docs Document and file data that you specifically authorize through Google OAuth, including document content, titles, comments, file metadata, and related Drive metadata, solely to enable the document features you request. You explicitly authorize access through Google OAuth. You can revoke access at any time through your Google account permissions.
Element (Matrix) Messages you send to your companion through Element. Element integration is optional and user-managed. PurposeMapped does not create or administer your separate Element account, but messages sent through that channel are processed to provide the Service. You explicitly authorize bot access. You can revoke or disable that access through your Element or bot settings, or by contacting PMD support.

3. How We Use Google OAuth

PurposeMapped uses Google OAuth to request and manage your explicit permission to access Gmail, Google Calendar, and Google Docs/Drive features.

OAuth & Integration Capability

All integration permissions are user-defined and scope-limited. PurposeMapped uses Google data only to provide or improve user-facing features that you request within the Service — not for cross-user analytics, aggregate product development, advertising, or model training.

How Your Google Data Is Used

3a. Google Services & Compliance

When you authorize PurposeMapped to access Gmail, Google Calendar, Google Docs, or Google Drive, your use of those integrations is also subject to Google's applicable terms and privacy policies:

Google API Terms of Service  ·  Google Privacy Policy

PurposeMapped complies with applicable Google API Services requirements, including the following disclosure and use restrictions:

Notwithstanding anything else in this policy, if PurposeMapped receives information from Google Workspace APIs, PurposeMapped's use of that data will be limited to providing or improving user-facing features that are prominent in the user interface (meaning improvement of those specific features for the requesting user, and not for cross-user analytics, aggregate product development, advertising, or model training), and PurposeMapped will not transfer that data to third parties other than as necessary to provide and secure those features, comply with applicable law, or as directed by you.

4. How Your Conversations Reach AI Models

When you chat with your PurposeMapped companion, your messages are processed by artificial intelligence.

Which AI Models We Use

Model Changes: PurposeMapped may change which AI models are used, add new models, or discontinue models for reasons including performance optimization, cost management, security, legal compliance, or availability. We will update this policy or otherwise provide notice as required for material changes.

How Data Flows to AI Models

  1. You send a message to your companion (in-app, via Element, or browser extension).
  2. Your message is encrypted and transmitted to your private PurposeMapped instance.
  3. Your instance sends your message, relevant conversation context, and necessary service metadata to the AI model API endpoint.
  4. The API processes your message and returns a response.
  5. The response is stored in your private instance and displayed to you.

PurposeMapped does not maintain a separate long-term repository of raw messages sent to AI models beyond what is stored in your conversation history, security logs, backups, and limited operational records as described in this policy. Some raw request or response data may be processed transiently or logged in limited form for reliability, abuse prevention, troubleshooting, and security.

Training & Model Improvement

5. How We Protect Your Data

Encryption & Storage

Access Controls

6. Data Retention & Deletion

Data Retention Policy

Data TypeRetention PeriodReason
Active Account Data For duration of subscription Necessary to provide the Service
System Events & Logs 90 days Troubleshooting, security, optimization
Payment & Billing Records Up to seven (7) years from the date of creation, or such longer period as expressly required by applicable law Tax and legal compliance
Administrative Access Logs For the period reasonably necessary for security, audit, and accountability purposes Security audit trail and accountability
Data After Termination Up to 30 days, except where longer retention is required for backups, legal obligations, security records, or de-identified archival records Account recovery window, service wind-down, backup processing, and compliance with legal obligations; thereafter deleted or de-identified in accordance with this policy

How to Request Data Deletion

  1. Email Support: Send a deletion request to support@purposemapped.com with the phrase "I request complete data deletion."
  2. Specify Scope: You can request deletion of specific types of data or complete account deletion.
  3. Verification: We will verify your identity by confirming your email address.
  4. Timeframe: We will process your request within 30 days and confirm completion via email, subject to legal retention obligations and reasonable backup deletion timelines.
  5. Exceptions: Billing and other records required for tax, accounting, fraud prevention, or legal compliance will be retained for a maximum of seven (7) years from the date of creation, or such longer period as expressly required by applicable law. Upon expiration of the applicable retention period, such records will be permanently deleted or de-identified.

Account Termination & Data Cleanup

7. Your Rights & Control

Export Your Data: Request a copy of your conversations, profile data, and configuration through your dashboard where available or by contacting PMD support.

Revoke Integrations: Disconnect Gmail, Google Calendar, Google Docs, or Element at any time through your settings or by contacting PMD support. Google access can also be revoked through your Google account settings.

Delete Specific Data: Delete individual conversations or request deletion of specific categories of data without deleting your account, subject to technical availability and legal retention requirements.

Request Access Logs: Request information about administrative access attempts to your instance, subject to security and legal limitations.

Opt Out of Analytics: Where optional usage analytics are offered, you may opt out through your account settings or by contacting PMD support.

Account Deletion: Delete your entire account and data at any time. Deletion is processed in accordance with this policy, including the 30-day deletion window, backup cycles, and legal retention obligations.

Children's Privacy

The Service is intended solely for users who are 18 years of age or older, and is not directed to minors. PurposeMapped does not knowingly collect, use, or disclose personal information from any person under the age of 18. To the extent required by COPPA, PurposeMapped does not knowingly collect personal information from children under the age of 13. If you believe that any person under the age of 18 has provided personal information to PurposeMapped, please contact us immediately at support@purposemapped.com and we will take prompt steps to delete that information from our records.

8. Questions, Contact, & Miscellaneous

Privacy Questions

If you have questions about this Privacy & Security policy, contact us at:

support@purposemapped.com
Subject: "Privacy Question" or "Data Request"

We will acknowledge general privacy inquiries within 5 business days. Substantive responses to data subject rights requests will be provided within the timeframe required by applicable law (including, where GDPR applies, within one month of receipt, extendable by up to two additional months for complex or numerous requests).

Legal Compliance

Policy Updates

We may update this Privacy & Security policy from time to time. We will notify you of any material changes by email at least thirty (30) days before the changes take effect. For changes that materially alter the way we collect, use, or share your personal information, we will request your affirmative consent before applying those changes to your account. Continued use of the Service after the effective date of non-material changes constitutes acceptance of the updated policy.

Governing Law & Dispute Resolution

This Privacy & Security policy and any disputes arising out of or relating to it are governed by the laws of the State of Colorado, without regard to its conflict of laws principles. Any dispute arising under this policy that cannot be resolved informally shall be submitted to binding arbitration administered by the American Arbitration Association (AAA) under its then-current Consumer Arbitration Rules. Each party waives any right to participate in a class action lawsuit or class-wide arbitration to the fullest extent permitted by law. Nothing in this section requires arbitration of, or limits your right to pursue: (a) data subject rights requests under applicable data protection law; (b) complaints filed with a data protection authority; or (c) any claim that applicable law expressly requires be resolved outside of arbitration.

Last updated: May 2026

← Back to Sign Up