WORKING PRIVACY NOTICE
Your information should help you decide, not become the product.
This notice covers the current early-stage service. A lawyer still needs to review it before any commercial launch.
What is stored
Common Ground stores the account identifier and email supplied by Google sign-in, profiles, self-reported skills and contribution details, optional profile media, private matching coordinates when a person chooses to add them, community listings and evidence records, community event details and RSVPs, in-app alerts and their delivery preferences, private messages and conversation history, forming-circle records, stewardship history, and safety cases. A legacy saved-search record may remain for an account that used the retired feature; it is inactive and can still be exported or erased. Matching answers can reveal sensitive lifestyle preferences.
Who can see it
Profiles are visible to their owner and site administrators by default. People can separately opt into compatibility matching, the signed-in member directory, and the public directory. People who can view a profile can also read its questionnaire answers, shared-living experience, budget, labor limits, and choices marked Important. Answers do not have a separate visibility setting. Emails and precise addresses stay private. Accepting a message request opens an in-site conversation; it does not reveal either account's email.
Public information
Community listings and profiles whose owners turn on public visibility can be viewed without signing in. A public profile includes its name, broad location, description, self-reported contribution details, personal links, and any photos and short video its owner adds. Full questionnaire answers, shared-living experience, budget, labor limits, and choices marked Important are part of the profile and visible to everyone who can view it. Owners can edit or leave answers blank and control the visibility of the whole profile in Profile → Visibility. Media follows the profile's visibility setting; a private or member-only person profile does not make its media public. Uploaded photos are reprocessed to remove embedded metadata. Videos are stored as uploaded and may retain file metadata, so review them before sharing. Emails and precise addresses remain private; contact requires sign-in and mutual acceptance. Community listings may also show owner-added media, community arrangements, availability, evidence summaries, linked governance documents, and event dates with only an approximate place or “Online.” An exact event address, arrival instructions, or private meeting link is shown only to organizers and confirmed attendees, and is hidden again after withdrawal or cancellation. Upload only people who agreed to appear, and do not publish private member information or precise residential details that create safety risk.
Location choices
A saved matching location is optional. Using it privately for straight-line distance matching and showing a rounded public map marker are separate choices, and both can be turned off. Without private location consent, matching falls back to the broad city or region written in the profile.
Control, export, and erasure
Members can download a complete ZIP containing their structured Site records and available profile photos, covers, collages, short videos, hosted events, and event RSVPs. People can leave an RSVP or waitlist at any time, which removes access to attendee-only details. The account-wide Site-data erasure flow first shows an account-specific preview, then requires exact confirmation. It removes owned profiles, listings, events, RSVPs, media, legacy saved-search records, alerts, and other account data; withdraws contact; and closes circles the member facilitated rather than silently giving control to someone else. Media or events added by a co-steward to a community owned by someone else stay with that community, while the former contributor's identity is removed. A small pseudonymized safety-case history may be retained to preserve moderation accountability, and that exception is shown before erasure. This erases Common Ground Site data, not the person's Google account. Administrators can export a portable backup for migration and recovery. A formal retention schedule is still required before open beta.
FAQ help and contacting the team
The AI assistant sends your question and up to six recent chat messages (your questions and its replies, subject to a size limit) to Cloudflare Workers AI to generate conversational answers grounded in the published FAQ. Chat history is held in the current page session, not saved as a support ticket. Do not include sensitive personal information. It does not receive your private profile or member conversations. AI questions are not automatically submitted to administrators. When you explicitly send a support message, the site stores that message, your contact email, and the team’s reply in the private admin support inbox. Signed-out visitors use a secure, HttpOnly support cookie lasting up to 30 days to retrieve their own replies in the same browser. The email supplied by a guest is not verified. Signed-in support requests are associated with the account and included in its existing data controls. Contact the Common Ground team through Help & support about guest messages or deletion requests. We’ll reply as soon as we can.
Business model
Paid promotion must never change compatibility scores. The current product does not sell personal profiles or optimize for addictive engagement.