Public information
Privacy Policy
This policy explains how MPG Auth QA dedicated collects, uses, stores, and shares information when listed members use this private application.
Effective date: August 24, 2026
Scope
This policy applies to MPG Auth QA dedicated's web application at dedicated.mpg-auth-qa.menspeergroup.app and its hosted authentication pages. It does not govern information members exchange outside the application.
Information we collect
Membership and profile information. We store a member identifier, email address, display name, role, timezone, active status, and the identifier that links the member to the authentication service.
Group content. Depending on how a member uses the application, we store meeting details; written reflections and ratings; review and comment activity; accountability commitments and steps; uploaded documents and their metadata; reminder-delivery records; and related timestamps.
Authentication information. The application currently supports emailed sign-in links and verification codes and uses a required session cookie. When the Clerk-based sign-in options are enabled, Clerk will provide sign-in, account security, and session management and will process credentials and required authentication cookies. MPG Auth QA dedicated's application database does not store Google passwords or member passwords.
Technical information. Cloudflare and, when its authentication service is used, Clerk may process information such as IP address, browser and device information, request metadata, cookies, and security or error events to deliver, protect, and troubleshoot the service. The application also stores a theme choice in local browser storage and a temporary visual-background choice in session storage; neither contains member-authored content.
Google user data
If a member chooses Google Sign-In, the application requests only openid, email, and profile. We use the verified Google email address and basic profile only to complete authentication and match the person to an active MPG Auth QA dedicated membership.
The application does not request access to Gmail, Drive, Calendar, contacts, or other Google API content. It does not use Google user data for advertising, credit decisions, or data brokerage, and it does not sell Google user data. The application code does not store a Google OAuth access token in its Cloudflare D1 database or R2 document storage; Clerk processes the OAuth exchange as our authentication provider.
How we use information
- authenticate listed members and enforce the active-member roster;
- provide meetings, reflections, reviews, comments, documents, commitments, and reminders;
- maintain account preferences and member-visible attribution;
- protect the service, prevent misuse, diagnose failures, and preserve availability; and
- comply with applicable legal obligations.
How information is shared
With other listed members. The application is designed for group collaboration. Submitted reflections, comments, review status, documents, meeting information, and accountability commitments may be visible to other active members as indicated by the feature being used. Draft reflections are not presented as submitted group content.
With service providers. Cloudflare processes hosting, networking, database, object-storage, email, and operational data. Clerk processes authentication, account, and session data when its sign-in options are used. Google processes information when a member elects Google Sign-In. These providers process information to supply their services and under their own terms and privacy commitments.
For legal or safety reasons. Information may be disclosed when reasonably necessary to comply with law, protect members, investigate abuse, or protect the rights and security of the service and its users.
We do not sell personal information or use member information for behavioral advertising.
Retention and deletion
We retain membership information while an account is active and as needed afterward to preserve the integrity of shared group records. Meeting records, submitted reflections, comments, reviews, documents, and commitments may remain as historical group content after a member is deactivated, particularly where deleting them would remove other members' context or break required record relationships. Authentication and operational records are retained according to the applicable Clerk and Cloudflare settings.
A member may ask to access, correct, deactivate, or delete personal information. We will evaluate deletion requests in light of shared group records, security, legal obligations, and technical requirements. Revoking Google access or choosing another sign-in method does not automatically delete the local membership record or group content.
Security
We use encrypted network connections, operator-created accounts, managed authentication, tenant-isolated storage, and an active local membership check on protected requests. No service can guarantee absolute security, and members should protect their sign-in credentials and avoid uploading information they do not have permission to share.
Children
The application is intended for listed adult members and is not directed to children under 13. Contact us if you believe a child has provided personal information.
Changes to this policy
We may update this policy as the application or its providers change. The effective date above will be updated, and material changes will be communicated through an appropriate member channel.
Contact
For privacy questions or requests, contact MPG Auth QA dedicated's administrator at mark@ankcorn.com.