Privacy Policy

Last updated: August 31, 2026

Draft — pending attorney review. This document describes the current repository code paths and intended deployment behavior. Live configuration and legal accuracy have not been independently verified, and an attorney has not approved this draft.

1. What this covers

This policy explains what information the RM-UCIE service collects through RM-UCIE (the “Service”) — both from people who use the product as an invited team member, and from visitors to the public website.

2. Information we collect

If you’re an invited user of the Service:

  • Your email address and credentials handled using the application's configured authentication and password-protection controls.
  • A time-based one-time-passcode secret, only if you choose to enroll multi-factor authentication.
  • The operational data you or your organization enter — constraints, projects, alerts, evidence, measurements, and related records — scoped to your organization. The service is designed to scope organization data separately; applicable deployment controls are reviewed during pilot scoping.
  • Standard session information (a single, secure, browser-only session cookie that keeps you signed in) and an audit trail of significant actions you take, for accountability and troubleshooting. When an authenticated session is issued, the security audit also records your account identifier, organization identifier, time, and the hosting network’s coarse edge-region code when available. It does not retain your IP address, GPS location, or a device fingerprint in that session-access event.

If you’re a website visitor:

  • If you submit the “RM-UCIE Intelligence Brief” email signup form, we store the email address you provide, the page it came from, and, when one can be derived from the request’s hosting/proxy headers, a public IP address (used only for abuse prevention on that form).
  • If you submit the contact or pilot-application form, we store the information you provide (name, email, organization, role, message, and, for a pilot application, industry, use case, and timeline) so we can respond to your inquiry. We also store a public IP address when one can be derived from the request’s hosting/proxy headers, for abuse prevention and security review. The initial public forms do not accept attachments.
  • We do not run third-party advertising trackers or analytics scripts on the public site.

3. How we use it

  • To operate the Service: authenticate you, enforce your organization’s access controls, and store the records your team creates.
  • To communicate with you: invite emails, and — if you signed up for it — occasional updates from the RM-UCIE Intelligence Brief list. You can ask to be removed at any time (see Contact below).
  • To keep the Service secure and working: rate-limiting abuse and diagnosing failures. Server-side error tracking (Sentry) is off unless a deployment operator configures it. When enabled, the application limits Sentry “extra” fields to allowlisted identifiers, counts, timings, and categorical values, and configures the SDK not to send default personally identifying information. A captured exception message or stack can still contain values produced by a dependency, so enabling Sentry remains a deployment-specific data-processing decision.
  • Optional external AI evidence-intake assistance is disabled by default. It becomes available only when a deployment operator sets the explicit enable flag, configures an API credential, and an authorized signed-in user makes an on-demand request. When used, the Service sends the imported CSV headers and a bounded portion of the raw CSV to a third-party AI provider, configured not to retain the submission. The software cannot determine whether a particular customer agreement or consent authorizes that transfer, so operators must keep the feature disabled until the applicable authorization, provider terms, and data-processing review are complete.

4. What we don’t do

  • We do not sell your information, or your organization’s data, to anyone.
  • RM-UCIE does not intentionally use your organization’s operational data to train an RM-UCIE model. If optional external AI assistance is approved and enabled, provider handling is governed by the applicable customer and provider terms, not by this draft alone.
  • We do not share one organization’s data with another organization on the Service.

5. Who else sees it

Within your organization, visibility follows the role-based access your administrator configures — not everyone with an account can see everything. Outside your organization, the Service may rely on deployment providers for hosting and, when configured, outbound email, server-side error tracking (Sentry), and on-demand evidence-intake assistance (OpenAI). Those providers may receive the limited information described above. Their handling must be covered by the applicable customer agreement, deployment configuration, and provider terms; this draft does not itself establish or verify those contractual protections.

6. How long we keep it

Operational and audit records are generally retained while your organization’s account is active. Public email-signup, contact, and pilot-application records — including any stored request IP address — currently have no automatic expiration in the application code and remain until an authorized administrative deletion or approved retention process occurs. Backups may be created for recovery; their encryption, location, and retention depend on the deployment configuration and must be verified for the applicable engagement. External providers may apply their own retention terms. Contact us to request data return or deletion and to confirm what can be deleted without compromising required security or audit records.

7. Your choices

You can ask us to access, correct, or delete personal information we hold about you — including unsubscribing from the Intelligence Brief list, or requesting removal of a website signup, contact inquiry, or pilot application — by emailing us. For invited-user accounts, your organization’s administrator is typically the fastest path to changes, since your account belongs to their workspace.

8. Changes to this policy

If this policy changes materially, we’ll update the date at the top of this page and, for invited users, notify your organization’s administrator.

9. Contact

Questions, or a request about your data: info@rmucie.com

See also our Terms of Service.