Security and privacy
What Particulars stores, where it lives, who can see it, how connected systems are used, and how to remove it.
The short version: organization data stays inside the organization's boundary; connected sources are opt-in; AI output remains advisory until a person confirms it; personal coaching belongs to the person; export and deletion are straightforward.
Where data lives
Charters and organization metadata live in Postgres on Supabase.
The application is hosted on Vercel as a static frontend with serverless API functions.
Sign-in email is delivered through Resend. Payments use Stripe. Error reports go to Sentry.
AI features use the Anthropic Claude API, routed through the configured application infrastructure.
Current default regions are in the United States.
Authentication
Sign-in is passwordless through single-use email links. Particulars does not store passwords.
Sessions use signed first-party cookies. Signing out invalidates the active session.
Enterprise identity features such as SSO and SCIM are not yet offered.
Organization boundaries
Private charters, decisions, measures, connected-source output, and membership data are visible only inside the organization that owns them.
Membership in several organizations does not merge their private data. One organization cannot inspect another through a shared person.
Public charters are the exception by explicit choice: publishing a public link makes that charter readable outside the organization.
Personal boundary
Personal coaching is a user-held surface. It assembles only information the signed-in person is already entitled to see, and it does not expose that view back to an employer, client, or organization administrator.
Slack access
When an owner connects Slack, Particulars requests access only to the channels and workspace information needed for enabled features.
Particulars does not read direct messages, files, or channels that have not been connected.
Tokens are encrypted at rest and may be revoked by disconnecting the connector or uninstalling the Slack app.
What is sent to AI providers
When a user asks Particulars to draft, review, or analyze connected work, the relevant selected content is sent to Anthropic's Claude API.
Particulars does not use customer data to train its own general model.
Important AI-produced changes remain proposals until a person accepts them.
Deletion
A charter can be deleted from its settings.
An organization can be deleted by an owner.
A person can delete their account from profile settings.
Deletion cascades are immediate and irreversible; export first when the record may matter later. Full detail is in the Privacy Policy.
Security, data-processing agreements, subprocessors, residency, or enterprise review: contact clay@cpj.fyi.