Constellation

Privacy, in plain language

Your data should never feel like a hidden room.

Every contribution has an audience. Every private space has a boundary. This page shows those boundaries, the operational access behind them, and the controls that remain yours.

Original passwords are never storedAudiences are named before sharingMembers can export their own records

Choose the audience before you share

Only you

Private reflections and anything marked Only me stay inside your account.

One Circle

Circle posts reach the current members of the exact Circle you choose.

The whole group

Group posts and Commons records are available to every active member.

Roles control entry and stewardship. They do not silently turn an Only you record into shared content.

Who can see what?

The practical access map.

“Administrator” below means an Owner or Admin using the controls built into Constellation. Moderators receive access to shared-space stewardship only.

Your password

No one can retrieve it

Constellation stores a one-way password hash. Members, moderators, administrators, and the owner cannot view your original password.

Profile and account

You, members, and administrators

Active members see the profile you share. Administrators can also see your email, membership status, platform role, Circle memberships, and account preferences needed to operate your account.

Private records

Only your account

Private reflections, private Shadow CV entries, private movement records, and private Exchange items are excluded from group views and administrator exports.

Circle records

Exact Circle members

A Circle post requires a named Circle. Constellation checks current membership whenever that record is viewed or searched.

Shared records

All active members

Group posts, Commons contributions, Council activity, rooms, and shared missions form the collective memory of the constellation.

Relationship agreements

The two named people

An agreement is returned only when you are one of its two participants. It is excluded from the administrator’s portable backup.

Inbox and recovery

You, with a narrow admin exception

Your notifications belong to your account. Administrators can see an account recovery request and issue an audited link that expires after one hour. They still cannot recover your old password.

The infrastructure boundary

The person who controls Constellation’s hosting and database credentials has technical access to stored database rows, including private content and password hashes. Those credentials are kept outside the member and administrator interfaces and should remain with the platform owner alone.

This is the deepest access boundary. Constellation states it here because private hosting still depends on a trusted infrastructure operator.

Your controls

  • Download a structured copy of the records associated with your account.
  • Change your email, password, notification rhythm, and active sessions.
  • Delete your account after password confirmation. Private reflections, Shadow CV entries, movement records, friction entries, offers, and personal notifications are removed.
  • Shared history that the group may still rely on is retained under the anonymized name Former member.

Operational retention

Temporary data has an ending.

Operational maintenance applies these limits while keeping active member-created records until their author edits, deletes, or closes the account.

30 days
Resolved recovery requests and old invitation secrets
90 days
Declined visitor requests and informational system events
180 days
Read notifications and warning or error system events
On account deletion
Direct identifiers are cleared and remaining shared history is anonymized