data and silence

Privacy and data rules

Rules for email, access links, purchase history, reading archive, deletion/export requests, and internal examples.

Personal data is not decor. It must not wander through internal pages, screenshots, prompts, or examples.

privacy owner

Minimum data

Collect only what is needed to find purchase, account, or access link.

Do not collect birth details, private stories, or full payment data for ordinary support.

editor

Internal examples

Use fictional examples only.

Do not paste real email, customer name, order ID, or private question into internal pages.

privacy owner

Deletion

Verify requester, record action, confirm completion in plain language.

Do not promise deletion from systems you do not actually control.

Privacy request path

Data requests go through their own corridor, not ordinary content backlog.

  • Identify request type: access, export, deletion, correction, consent.
  • Verify only necessary identity signals.
  • Record completion and what could not be changed.

checklist

  • No real customer data in docs.
  • No sensitive fields in analytics examples.
  • Deletion/export language matches actual capabilities.

handoff

  • Privacy owner hands owner a summary without unnecessary personal details.

red flags

  • Real customer data appears in screenshot, prompt, issue, docs, or public page.
  • Support asks for full card number.
  • Deletion promise is broader than actual system access.

related doors