Skip to content

Privacy policy

Last updated: 7 September 2026

This free research diagnostic requires no account or email address. Your answers are saved in your browser so you can resume your work. When you request a PDF, they are sent to our server for processing in memory. The application does not save answers, institution names, individual findings or reports in a server database or application log.

What this tool does not do

The diagnostic does not require a user account, collect contact details, load analytics, serve advertising or share assessment data with advertisers. Scoring is deterministic: AI does not decide maturity ratings, identify gaps or change your answers.

Downloading a report does not clear your saved browser progress. You control that copy and any progress files or PDFs you download. Server-side processing does not create a saved assessment that the programme can retrieve later.

What data is processed and when

  • Assessment responses — Your answer selections, assessment scope and start time are transmitted when you request a PDF. The server computes the results and renders the report in memory. Raw answer selections are not sent to an AI provider.
  • Optional institution name — Used only to label your PDF. It is processed in server memory and is not sent to Anthropic, stored in a database or included in application logs.
  • Cloudflare Turnstile — Anti-bot verification loads on the results page. Cloudflare processes challenge information and request metadata; the report server also sends the challenge token and IP address to Cloudflare for verification. The server temporarily holds an IP-based counter in memory to limit report requests.
  • Research correspondence — If you choose to email feedback, your message and sender details are handled through email and may remain in the operator's mailbox. No assessment is attached automatically. Do not include confidential institutional or client information.
  • Browser localStorage — Assessment progress remains on your device until you clear it. Use “Clear all answers” in the assessment, or clear this site's data in your browser settings. This does not delete files you have downloaded.

Third-party processors

  • Cloudflare — Turnstile anti-bot verification.
  • Anthropic — Optional narrative synthesis, only when available and selected. The processing conditions are described below.
  • Supabase — Hosts the programme's regulatory and analysis content and aggregate daily report counts, token usage and cost. It does not store individual assessment results.
  • Resend — Sends operational alerts when configured. Alerts contain service status and aggregate usage figures, not assessment answers, institution names, scores or findings.
  • Vercel — Hosts the application and report function. Application logs contain operational event codes and technical status, not assessment content. Hosting and security providers may process network metadata under their own service terms and policies.

Claude API and AI processing

AI-assisted summaries are available as an optional choice before report generation. Authored research analysis is the default.

Optional AI summaries use Claude Fable 5.1 through Anthropic’s commercial API. This tool has no zero data retention arrangement. Anthropic normally deletes API inputs and outputs within 30 days. It may retain data for longer for policy enforcement or legal reasons. Content flagged for policy violations may be retained for up to two years, and related safety classifications for up to seven years. See Anthropic’s retention policy. The programme’s processing in memory does not change Anthropic’s retention.

If available and selected, the AI-assisted summary receives selected gaps and findings about partial implementation, consistency alerts, maturity indicators and assessment scope, together with the programme's analysis text. These reveal aspects of the institution's governance posture even though its name and raw answer list are excluded. Scoring and detailed findings remain deterministic. If AI synthesis is unavailable, the report uses authored analysis instead. A fallback after an attempted AI request does not undo processing that has already occurred.

Commercial API content is not used for model training by default. This application does not submit provider feedback or opt into data sharing for training. See Anthropic’s commercial training policy. No model training and no data retention are different commitments.

Choose AI assistance only if you are authorised to share the findings about your institution. Clearing browser progress does not delete information already transmitted to Anthropic. Anthropic does not support ad hoc deletion of API submissions; its retention policy applies. You can obtain the same scores and detailed findings without selecting AI assistance.

Browser storage and cookies

Assessment progress uses browser localStorage. The diagnostic does not use an assessment-session cookie or analytics cookies. The separate operator administration area uses a secure authentication cookie. Cloudflare supplies the anti-bot service described above; it is not used for audience analytics.

Data subject rights

You may request information about data processing or exercise your rights under applicable data protection laws, including Singapore's Personal Data Protection Act (PDPA), by contacting privacy@governed-autonomy.com.

Governing law

This privacy policy is governed by the laws of Singapore.

Operator

This tool is part of Governed Autonomy, Adrien Pesa's self-funded, non-commercial research programme in Singapore. For privacy enquiries, contact privacy@governed-autonomy.com.

Changes to this policy

This policy may be updated from time to time. The current version is always available at this URL.