Privacy notice
Collect only what the authorization workflow needs.
This notice describes the current Mandate portfolio MVP. It is intentionally explicit about the product’s simulated status and the limited data required to operate it.
Last updated August 14, 2026Data Mandate receives
- Account data such as your name, organization name, email address, password hash, and authentication records.
- Workspace data such as agents, mandates, simulated transactions, decisions, approvals, and audit events.
- Technical data such as IP-derived request information, timestamps, error details, and abuse-prevention counters.
- If you use Google sign-in, the identity information returned by Google for authentication.
How the data is used
Data is used to authenticate users, enforce tenant boundaries, evaluate simulated authorization requests, display explainable decisions, preserve audit evidence, prevent abuse, and operate the service.
Natural-language mandate interpretation
When you choose to structure a mandate from natural language, that instruction is sent to OpenAI for schema-constrained interpretation. The model does not receive authority to approve transactions, access payment credentials, or change an active mandate. You can use the structured form without relying on natural-language interpretation.
Data Mandate does not need
Do not submit card numbers, bank-account credentials, government IDs, production secrets, health information, or other sensitive personal data. The MVP does not process real payments and is not designed to receive those categories of information.
Service providers and retention
Railway provides application and PostgreSQL hosting, Google may provide authentication, and OpenAI processes mandate text only when that feature is invoked. Records are retained while needed to operate and secure the workspace or meet legitimate recordkeeping needs. Formal deletion and retention automation remains part of the production roadmap.
Questions and requests
Until a dedicated privacy channel is published, contact the project owner through the verified profile linked from the Mandate GitHub repository. Do not post personal data or credentials in a public issue.