Founding Expedition newsletter privacy

The newsletter accepts an email address and explicit consent only.

The temporary Phase 0 newsletter exists so people can receive occasional public project updates and opportunities to inspect, play, review, or contribute. It is not an account, authentication system, game registration, health-data intake, research enrollment, provider intake, donation flow, or advertising profile.

What is collected

Do not submit health, medical, genetic, wearable, location, Chronicle, or other sensitive information. The form has no field for those categories.

Where it goes

The server forwards an accepted signup through the existing private Google Apps Script webhook into the project’s private Google Sheet. The webhook address and any token remain server-only Vercel environment variables. Subscriber addresses are not written to GitHub, public logs, website analytics, or the open-source repository.

Retention, correction, and deletion

The list is retained only for the Founding Expedition update purpose while Phase 0 remains active, unless you unsubscribe or request deletion sooner. The storage and provider choice must be reviewed again at Phase 0 exit or before migration to another newsletter system.

To unsubscribe, correct your address, request access, or request deletion, reply to any project update or email tom@calypsospromise.org. Requests will be handled manually while this temporary system is in use.

Failure, abuse, and incidents

The form uses explicit consent, email validation, a bot honeypot, bounded request size, best-effort per-source throttling, an HTTPS-only server webhook, and a delivery timeout. The in-memory throttle is not a durable distributed rate limiter and remains an explicit Phase 0 limitation. Provider failure returns a public-safe error and does not silently claim a successful signup.

If the webhook or private sheet is suspected of compromise, intake can be disabled by removing the server configuration or restoring the no-intake route. Protected incident details and real subscriber records must never be posted publicly.

Open gate

The preserve-and-activate direction is tracked in issue #63 (opens in a new tab). The issue remains open until implementation, deployed behavior, manual verification, limitations, and founding-steward acceptance are reconciled.

Review public support and contribution routes