Back to home

Privacy Policy

Effective date: April 6, 2026 Last updated: July 10, 2026


1. Who We Are and What This Policy Covers

This Privacy Policy explains how PoweredAI Solutions LLC ("we," "us," "our") collects, uses, stores, and protects information when you use Read the Room.

This policy covers:

  • The Read the Room web application
  • The real-time communication server (WebSocket)
  • All API services that support the platform

Read the Room is used by universities, government agencies, and corporate teams for decision-making training exercises. It processes two categories of users: participants (who join simulations using nicknames) and facilitators (who manage simulations using authenticated accounts).

By using Read the Room, you agree to the practices described in this policy. If you do not agree, do not use the platform. Use of the platform is also governed by our Terms of Service.


2. What Data We Collect

We collect different data depending on whether you are a participant or a facilitator.

2.1 Participant Data

Participants join simulations through a team join code and a self-chosen nickname. No account creation is required.

Data you provide:

FieldRequiredPurpose
NicknameYesIdentifies you to teammates and facilitators during the simulation

Data generated during use:

FieldPurpose
Chat messages (team, cross-team, public, facilitator channels)Core simulation functionality
Direct messagesPrivate communication between participants
Deliverable submissions (press releases, reports)Simulation exercise outputs
Cross-team request messagesInter-team coordination

Data collected automatically:

FieldPurpose
Session tokenAuthentication (stored as an HTTP-only cookie)
Activity status (active/inactive)Allows facilitators to monitor participation
Last active timestampPresence tracking for facilitators
Session start time, end time, durationEngagement tracking for facilitators
Session end reason (tab hidden, browser closed, disconnected)Facilitator visibility into participation patterns
Typing activity indicators (that you are composing in a chat context; never the text of unsent drafts)Participation measurement for facilitators
Simulation material viewing (which simulation materials you open, such as a role sheet or scenario update, and approximate viewing time)Participation measurement for facilitators
Contribution volume (the approximate amount of text you contribute in messages and submissions, measured as word counts; the measurement uses volume only and never evaluates what you wrote)Participation measurement for facilitators
IP address (recorded once with the consent record at join time)Security, audit, and abuse prevention. Used to provide non-repudiation for the consent record. Not used for tracking, advertising, profiling, or geolocation lookup.

Facilitators may receive participation notifications derived from the signals above, such as a note that a previously active participant has gone quiet. These notifications are visible to the facilitators running the simulation only.

Data we do NOT collect from participants:

  • Real names (you choose your own nickname)
  • Email addresses
  • Passwords
  • Precise location or GPS data (the IP address recorded with consent is not resolved to geolocation; aggregate traffic analytics records only coarse, city-level region, never linked to a participant)
  • Device fingerprints
  • Browsing history outside the platform

Participant identity mapping (linking nicknames to real identities) is the responsibility of the facilitating institution, not this platform.

2.2 Facilitator Data

Facilitators create authenticated accounts to manage simulations.

Data you provide:

FieldRequiredPurpose
Email addressYesAccount identification and authentication
PasswordYesAccount authentication (stored as a bcrypt hash, never in plaintext)
NicknameYesDisplay name within the platform

Data generated during use:

FieldPurpose
Simulation configurations (scenarios, teams, injects)Core platform functionality
Facilitator notes on cross-team requestsSimulation management
Simulation ownership records (which facilitator created each simulation)Attribution and access control
Access grants (who was granted access to which simulation, when, and by whom)Multi-facilitator collaboration and audit trail

Data collected automatically:

FieldPurpose
Session tokenAuthentication (NextAuth session cookie)
Audit log entries (action taken, timestamp, IP address)Security accountability and compliance
Role (Admin or Co-Facilitator)Access control
Account status (active/inactive)Account management
Account creation dateRecord keeping

2.3 Data We Do Not Collect (All Users)

  • No advertising or marketing trackers
  • No third-party advertising or behavioral analytics tools (no Google Analytics, Mixpanel, or Hotjar). We measure aggregate site traffic with Vercel Web Analytics: cookieless, anonymous page-view counting with no persistent identifiers and no cross-site tracking; access tokens are stripped from page addresses before collection. Participation measurement inside a simulation (described in section 2.1) is first-party, stays within the platform, and is never shared with advertisers or data brokers
  • No social media tracking pixels
  • No precise location or GPS data (aggregate traffic analytics records coarse, city-level region derived from IP, never linked to any account or participant)
  • No device fingerprinting
  • No browsing history outside the platform
  • No biometric data

This is a deliberate design choice. The platform collects only what is necessary to operate the simulation service.


3. Why We Collect It (Legal Basis)

Under the GDPR and similar data protection laws, we must have a lawful basis for processing personal data. The table below sets out each processing purpose and its legal basis.

PurposeData involvedLegal basis (GDPR)
Operating the simulation (chat, deliverables, team coordination)Nickname, messages, deliverables, cross-team requestsContract performance (Art. 6(1)(b))
Participant authenticationSession tokenContract performance (Art. 6(1)(b))
Facilitator account management (registration, login)Email, password hash, nicknameContract performance (Art. 6(1)(b))
Facilitator engagement analytics (session duration, activity status)Session timestamps, active status, session end reason, material viewing time, message and submission word countsLegitimate interest (Art. 6(1)(f)): facilitators need to assess participation in the training exercise
Security and abuse prevention (facilitator audit logs)Facilitator IP address, action type, timestampLegitimate interest (Art. 6(1)(f))
Non-repudiation of participant consentParticipant IP address (recorded once with the consent record)Legitimate interest (Art. 6(1)(f)): protecting the integrity of consent records and detecting abuse. We have conducted a balancing test and concluded that the limited collection (one IP per consent record, retained for 12 months, never used for tracking) does not override participant rights.
Audit loggingFacilitator ID, action, details, IP addressLegal obligation (Art. 6(1)(c)) and legitimate interest (Art. 6(1)(f))

Where we rely on legitimate interest, we have conducted balancing tests to ensure that our interests do not override your rights. Engagement analytics exist solely to help facilitators evaluate participation in the educational exercise. Audit logs exist to maintain platform security and accountability.


4. Cookies and Similar Technologies

We use only strictly necessary cookies for authentication. We do not use advertising cookies, analytics cookies, or tracking cookies. Because all cookies are strictly necessary for the service to function, no cookie consent banner is required.

Cookie inventory

Cookie namePurposeTypeDurationAttributes
participant_sessionAuthenticates participants during a simulationEssential7 daysHTTP-only, Secure, SameSite=Lax
authjs.session-tokenAuthenticates facilitators (NextAuth)EssentialSessionHTTP-only, Secure
__Secure-authjs.session-tokenAuthenticates facilitators (NextAuth, HTTPS variant)EssentialSessionHTTP-only, Secure

We do not use localStorage or sessionStorage for tracking. The platform uses no third-party cookies.


5. How We Use Your Data

We use collected data for the following purposes and no others:

  1. Providing the simulation service. Delivering messages between participants, displaying team communications, processing deliverable submissions, and enabling cross-team coordination.

  2. Authenticating users. Verifying that participants and facilitators are who they claim to be for the duration of their session.

  3. Facilitator monitoring. Allowing facilitators to see which participants are active, how long they have participated, and whether they are engaged in the exercise. This data is visible only to the simulation's facilitators.

  4. Security and accountability. Recording facilitator actions (creating simulations, sending injects, approving requests, managing accounts) in audit logs. This protects against unauthorized changes and supports incident investigation.

  5. Service operation. Maintaining platform performance, debugging errors, and enforcing rate limits.

We do not use your data for advertising, profiling, automated decision-making, or any purpose beyond operating the simulation service.


6. Who We Share It With

We do not sell personal data. We do not share personal data with third parties for their own marketing purposes.

The following sub-processors handle data on our behalf as part of delivering the platform:

ProviderRoleData processedLocationDPA
Vercel Inc.Application hosting (Next.js frontend and API routes)All request data, HTTP headersUnited Statesvercel.com/legal/dpa
Neon Inc.PostgreSQL database hostingAll stored data (accounts, messages, deliverables, sessions, audit logs)United Statesneon.com/dpa
Fly.io (Deno Land Inc.)WebSocket server hosting (real-time messaging)Real-time message content in transit, connection metadataUnited StatesNo public DPA available (see note below)

Note on Fly.io: Fly.io does not currently publish a standard Data Processing Agreement. For deployments subject to GDPR Article 28, we are pursuing a bilateral DPA with Fly.io. Contact us for current status.

All sub-processors are contractually bound to process data only on our instructions and to implement appropriate security measures. Vercel and Neon maintain their own sub-processor lists (see their respective DPA pages).

We may also disclose data if required by law, court order, or governmental request, or to protect the rights, property, or safety of PoweredAI Solutions LLC, our users, or the public.


7. International Data Transfers

All platform infrastructure is located in the United States. If you access Read the Room from outside the United States, your data will be transferred to, stored, and processed in the US.

For users in the European Economic Area (EEA), United Kingdom, or Switzerland:

We rely on Standard Contractual Clauses (SCCs) approved by the European Commission as the legal mechanism for transferring personal data to the United States. Our sub-processors Vercel and Neon maintain their own transfer mechanisms under their respective DPAs.

If the EU-US Data Privacy Framework applies to any of our sub-processors, transfers to those sub-processors may also rely on that framework.

You have the right to request a copy of the safeguards we use for international data transfers by contacting us at the address in Section 14.


8. How Long We Keep Your Data

We retain data only as long as necessary for the purposes described in this policy. For full details, see our Data Retention Policy. A summary:

Data categoryRetention period
Active simulation data (messages, deliverables, participant records)Retained while the simulation exists
Completed simulation data (messages, deliverables, session records)12 months after simulation completion, then deleted
Direct messagesDeleted when the simulation ends (by design)
Participant recordsDeleted when the simulation is deleted, or on request
Facilitator accountsRetained while active, plus 6 months after deletion
Audit logs24 months, then deleted
Consent records (version, timestamp, accepted checkboxes)Retained indefinitely (legal requirement under GDPR Art. 7(1))
Participant IP address on consent record12 months from consent creation, then nulled. The rest of the consent record is retained indefinitely.

9. Your Rights Under GDPR

If you are in the European Economic Area, United Kingdom, or Switzerland, you have the following rights under GDPR Articles 15 through 22:

Right of access (Art. 15). You can request a copy of the personal data we hold about you.

Right to rectification (Art. 16). You can ask us to correct inaccurate data. Participants can update their nickname through the platform. Facilitators can update their email and nickname.

Right to erasure (Art. 17). You can ask us to delete your personal data. For participants, this means deleting your nickname, messages, deliverables, and session records. For facilitators, this means deleting your account and associated data. Note: Your nickname may appear in historical message records as a denormalized sender name. When you request erasure, we overwrite these occurrences with a placeholder (e.g., '[deleted]') as part of the deletion process. This requires a separate data scrubbing operation beyond deleting your participant record.

Right to restriction (Art. 18). You can ask us to limit how we process your data in certain circumstances.

Right to data portability (Art. 20). You can request your data in a structured, commonly used, machine-readable format (JSON).

Right to object (Art. 21). You can object to processing based on legitimate interest. We will stop processing unless we have compelling legitimate grounds that override your interests.

Right related to automated decision-making (Art. 22). We do not engage in automated decision-making or profiling based on your personal data. If this changes, you have the right not to be subject to decisions based solely on automated processing.

Right to withdraw consent. Where processing is based on consent, you can withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Right to lodge a complaint. You have the right to file a complaint with your local data protection supervisory authority.

How to exercise your rights: Contact us using the details in Section 14. We will respond within 30 days. We may need to verify your identity before processing your request.

Participant identity verification: Because participants use nicknames and do not provide email addresses, we may verify your identity by confirming your nickname, team assignment, and simulation details with the facilitator. Facilitators can also submit deletion requests on behalf of participants.


10. Your Rights Under CCPA

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights.

Categories of personal information we collect:

  • Identifiers (facilitator email, nickname; participant nickname)
  • Internet or network activity (session tokens, facilitator IP addresses in audit logs)
  • Professional or employment-related information (only if provided within simulation content)

Your CCPA rights:

Right to know. You can request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collection, and the categories of third parties with whom we share it.

Right to delete. You can request deletion of personal information we have collected from you, subject to certain exceptions under CCPA.

Right to opt out of sale. We do not sell personal information. We have never sold personal information. No opt-out is necessary, but you may still submit one and we will record it.

Right to non-discrimination. We will not discriminate against you for exercising your CCPA rights.

How to exercise your rights: Contact us using the details in Section 14. We will respond within 45 days.

Where both GDPR and CCPA apply to a request, we respond within the shorter applicable timeframe.


11. Users in the Middle East

Saudi Arabia (Personal Data Protection Law). If you are in Saudi Arabia, we process your data in accordance with the PDPL. You have the right to access, correct, and request deletion of your personal data. Data transfers outside Saudi Arabia are conducted with appropriate safeguards. For questions about your rights under the PDPL, contact us using the details in Section 14.

United Arab Emirates (Federal Decree-Law No. 45 of 2021). If you are in the UAE, we process your data in accordance with the UAE PDPL. You have the right to access, correct, and delete your personal data. Cross-border data transfers are conducted in compliance with applicable UAE regulations. For questions about your rights, contact us using the details in Section 14.

If your jurisdiction requires data localization or specific transfer mechanisms not addressed above, please contact us before using the platform so we can assess compliance.


12. Children

Read the Room is designed for professional training environments: universities, government agencies, and corporate teams. The platform is not directed at children.

Minimum age. Users must be at least 16 years old, or the minimum age required by applicable local law, whichever is higher.

Institutional authorization. If a facilitator plans to use Read the Room with participants under 16 (or the locally applicable age), the facilitator and their institution are responsible for obtaining verifiable parental or guardian consent before those participants join. The facilitator must confirm this authorization before allowing participation.

If we learn that we have collected data from a child without proper consent or institutional authorization, we will delete that data promptly. Contact us using the details in Section 14 to report such cases.


13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes:

  • Material changes: We will notify facilitators by email and display a notice on the platform. Where a change affects the legal basis for processing, we will seek renewed consent where required.
  • Non-material changes: We will update the "Last updated" date at the top of this policy.

We encourage you to review this policy periodically. Continued use of the platform after changes take effect constitutes acceptance of the updated policy.

Previous versions of this policy will be made available on request.


14. Contact Us

If you have questions about this Privacy Policy, want to exercise your data protection rights, or need to report a concern:

Data Controller: PoweredAI Solutions LLC

Email: info@poweredai.ai

Postal address: 1950 Barrett Lakes Blvd NW, Apt 215, Kennesaw, GA 30144

If you believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local data protection supervisory authority.


This Privacy Policy should be read alongside our Terms of Service, Acceptable Use Policy, Simulation Disclaimer, Data Retention Policy, and Security Overview.