Privacy Policy
Effective date: April 6, 2026 Last updated: July 10, 2026
1. Who We Are and What This Policy Covers
This Privacy Policy explains how PoweredAI Solutions LLC ("we," "us," "our") collects, uses, stores, and protects information when you use Read the Room.
This policy covers:
- The Read the Room web application
- The real-time communication server (WebSocket)
- All API services that support the platform
Read the Room is used by universities, government agencies, and corporate teams for decision-making training exercises. It processes two categories of users: participants (who join simulations using nicknames) and facilitators (who manage simulations using authenticated accounts).
By using Read the Room, you agree to the practices described in this policy. If you do not agree, do not use the platform. Use of the platform is also governed by our Terms of Service.
2. What Data We Collect
We collect different data depending on whether you are a participant or a facilitator.
2.1 Participant Data
Participants join simulations through a team join code and a self-chosen nickname. No account creation is required.
Data you provide:
| Field | Required | Purpose |
|---|---|---|
| Nickname | Yes | Identifies you to teammates and facilitators during the simulation |
Data generated during use:
| Field | Purpose |
|---|---|
| Chat messages (team, cross-team, public, facilitator channels) | Core simulation functionality |
| Direct messages | Private communication between participants |
| Deliverable submissions (press releases, reports) | Simulation exercise outputs |
| Cross-team request messages | Inter-team coordination |
Data collected automatically:
| Field | Purpose |
|---|---|
| Session token | Authentication (stored as an HTTP-only cookie) |
| Activity status (active/inactive) | Allows facilitators to monitor participation |
| Last active timestamp | Presence tracking for facilitators |
| Session start time, end time, duration | Engagement tracking for facilitators |
| Session end reason (tab hidden, browser closed, disconnected) | Facilitator visibility into participation patterns |
| Typing activity indicators (that you are composing in a chat context; never the text of unsent drafts) | Participation measurement for facilitators |
| Simulation material viewing (which simulation materials you open, such as a role sheet or scenario update, and approximate viewing time) | Participation measurement for facilitators |
| Contribution volume (the approximate amount of text you contribute in messages and submissions, measured as word counts; the measurement uses volume only and never evaluates what you wrote) | Participation measurement for facilitators |
| IP address (recorded once with the consent record at join time) | Security, audit, and abuse prevention. Used to provide non-repudiation for the consent record. Not used for tracking, advertising, profiling, or geolocation lookup. |
Facilitators may receive participation notifications derived from the signals above, such as a note that a previously active participant has gone quiet. These notifications are visible to the facilitators running the simulation only.
Data we do NOT collect from participants:
- Real names (you choose your own nickname)
- Email addresses
- Passwords
- Precise location or GPS data (the IP address recorded with consent is not resolved to geolocation; aggregate traffic analytics records only coarse, city-level region, never linked to a participant)
- Device fingerprints
- Browsing history outside the platform
Participant identity mapping (linking nicknames to real identities) is the responsibility of the facilitating institution, not this platform.
2.2 Facilitator Data
Facilitators create authenticated accounts to manage simulations.
Data you provide:
| Field | Required | Purpose |
|---|---|---|
| Email address | Yes | Account identification and authentication |
| Password | Yes | Account authentication (stored as a bcrypt hash, never in plaintext) |
| Nickname | Yes | Display name within the platform |
Data generated during use:
| Field | Purpose |
|---|---|
| Simulation configurations (scenarios, teams, injects) | Core platform functionality |
| Facilitator notes on cross-team requests | Simulation management |
| Simulation ownership records (which facilitator created each simulation) | Attribution and access control |
| Access grants (who was granted access to which simulation, when, and by whom) | Multi-facilitator collaboration and audit trail |
Data collected automatically:
| Field | Purpose |
|---|---|
| Session token | Authentication (NextAuth session cookie) |
| Audit log entries (action taken, timestamp, IP address) | Security accountability and compliance |
| Role (Admin or Co-Facilitator) | Access control |
| Account status (active/inactive) | Account management |
| Account creation date | Record keeping |
2.3 Data We Do Not Collect (All Users)
- No advertising or marketing trackers
- No third-party advertising or behavioral analytics tools (no Google Analytics, Mixpanel, or Hotjar). We measure aggregate site traffic with Vercel Web Analytics: cookieless, anonymous page-view counting with no persistent identifiers and no cross-site tracking; access tokens are stripped from page addresses before collection. Participation measurement inside a simulation (described in section 2.1) is first-party, stays within the platform, and is never shared with advertisers or data brokers
- No social media tracking pixels
- No precise location or GPS data (aggregate traffic analytics records coarse, city-level region derived from IP, never linked to any account or participant)
- No device fingerprinting
- No browsing history outside the platform
- No biometric data
This is a deliberate design choice. The platform collects only what is necessary to operate the simulation service.
3. Why We Collect It (Legal Basis)
Under the GDPR and similar data protection laws, we must have a lawful basis for processing personal data. The table below sets out each processing purpose and its legal basis.
| Purpose | Data involved | Legal basis (GDPR) |
|---|---|---|
| Operating the simulation (chat, deliverables, team coordination) | Nickname, messages, deliverables, cross-team requests | Contract performance (Art. 6(1)(b)) |
| Participant authentication | Session token | Contract performance (Art. 6(1)(b)) |
| Facilitator account management (registration, login) | Email, password hash, nickname | Contract performance (Art. 6(1)(b)) |
| Facilitator engagement analytics (session duration, activity status) | Session timestamps, active status, session end reason, material viewing time, message and submission word counts | Legitimate interest (Art. 6(1)(f)): facilitators need to assess participation in the training exercise |
| Security and abuse prevention (facilitator audit logs) | Facilitator IP address, action type, timestamp | Legitimate interest (Art. 6(1)(f)) |
| Non-repudiation of participant consent | Participant IP address (recorded once with the consent record) | Legitimate interest (Art. 6(1)(f)): protecting the integrity of consent records and detecting abuse. We have conducted a balancing test and concluded that the limited collection (one IP per consent record, retained for 12 months, never used for tracking) does not override participant rights. |
| Audit logging | Facilitator ID, action, details, IP address | Legal obligation (Art. 6(1)(c)) and legitimate interest (Art. 6(1)(f)) |
Where we rely on legitimate interest, we have conducted balancing tests to ensure that our interests do not override your rights. Engagement analytics exist solely to help facilitators evaluate participation in the educational exercise. Audit logs exist to maintain platform security and accountability.
4. Cookies and Similar Technologies
We use only strictly necessary cookies for authentication. We do not use advertising cookies, analytics cookies, or tracking cookies. Because all cookies are strictly necessary for the service to function, no cookie consent banner is required.
Cookie inventory
| Cookie name | Purpose | Type | Duration | Attributes |
|---|---|---|---|---|
participant_session | Authenticates participants during a simulation | Essential | 7 days | HTTP-only, Secure, SameSite=Lax |
authjs.session-token | Authenticates facilitators (NextAuth) | Essential | Session | HTTP-only, Secure |
__Secure-authjs.session-token | Authenticates facilitators (NextAuth, HTTPS variant) | Essential | Session | HTTP-only, Secure |
We do not use localStorage or sessionStorage for tracking. The platform uses no third-party cookies.
5. How We Use Your Data
We use collected data for the following purposes and no others:
-
Providing the simulation service. Delivering messages between participants, displaying team communications, processing deliverable submissions, and enabling cross-team coordination.
-
Authenticating users. Verifying that participants and facilitators are who they claim to be for the duration of their session.
-
Facilitator monitoring. Allowing facilitators to see which participants are active, how long they have participated, and whether they are engaged in the exercise. This data is visible only to the simulation's facilitators.
-
Security and accountability. Recording facilitator actions (creating simulations, sending injects, approving requests, managing accounts) in audit logs. This protects against unauthorized changes and supports incident investigation.
-
Service operation. Maintaining platform performance, debugging errors, and enforcing rate limits.
We do not use your data for advertising, profiling, automated decision-making, or any purpose beyond operating the simulation service.
6. Who We Share It With
We do not sell personal data. We do not share personal data with third parties for their own marketing purposes.
The following sub-processors handle data on our behalf as part of delivering the platform:
| Provider | Role | Data processed | Location | DPA |
|---|---|---|---|---|
| Vercel Inc. | Application hosting (Next.js frontend and API routes) | All request data, HTTP headers | United States | vercel.com/legal/dpa |
| Neon Inc. | PostgreSQL database hosting | All stored data (accounts, messages, deliverables, sessions, audit logs) | United States | neon.com/dpa |
| Fly.io (Deno Land Inc.) | WebSocket server hosting (real-time messaging) | Real-time message content in transit, connection metadata | United States | No public DPA available (see note below) |
Note on Fly.io: Fly.io does not currently publish a standard Data Processing Agreement. For deployments subject to GDPR Article 28, we are pursuing a bilateral DPA with Fly.io. Contact us for current status.
All sub-processors are contractually bound to process data only on our instructions and to implement appropriate security measures. Vercel and Neon maintain their own sub-processor lists (see their respective DPA pages).
We may also disclose data if required by law, court order, or governmental request, or to protect the rights, property, or safety of PoweredAI Solutions LLC, our users, or the public.
7. International Data Transfers
All platform infrastructure is located in the United States. If you access Read the Room from outside the United States, your data will be transferred to, stored, and processed in the US.
For users in the European Economic Area (EEA), United Kingdom, or Switzerland:
We rely on Standard Contractual Clauses (SCCs) approved by the European Commission as the legal mechanism for transferring personal data to the United States. Our sub-processors Vercel and Neon maintain their own transfer mechanisms under their respective DPAs.
If the EU-US Data Privacy Framework applies to any of our sub-processors, transfers to those sub-processors may also rely on that framework.
You have the right to request a copy of the safeguards we use for international data transfers by contacting us at the address in Section 14.
8. How Long We Keep Your Data
We retain data only as long as necessary for the purposes described in this policy. For full details, see our Data Retention Policy. A summary:
| Data category | Retention period |
|---|---|
| Active simulation data (messages, deliverables, participant records) | Retained while the simulation exists |
| Completed simulation data (messages, deliverables, session records) | 12 months after simulation completion, then deleted |
| Direct messages | Deleted when the simulation ends (by design) |
| Participant records | Deleted when the simulation is deleted, or on request |
| Facilitator accounts | Retained while active, plus 6 months after deletion |
| Audit logs | 24 months, then deleted |
| Consent records (version, timestamp, accepted checkboxes) | Retained indefinitely (legal requirement under GDPR Art. 7(1)) |
| Participant IP address on consent record | 12 months from consent creation, then nulled. The rest of the consent record is retained indefinitely. |
9. Your Rights Under GDPR
If you are in the European Economic Area, United Kingdom, or Switzerland, you have the following rights under GDPR Articles 15 through 22:
Right of access (Art. 15). You can request a copy of the personal data we hold about you.
Right to rectification (Art. 16). You can ask us to correct inaccurate data. Participants can update their nickname through the platform. Facilitators can update their email and nickname.
Right to erasure (Art. 17). You can ask us to delete your personal data. For participants, this means deleting your nickname, messages, deliverables, and session records. For facilitators, this means deleting your account and associated data. Note: Your nickname may appear in historical message records as a denormalized sender name. When you request erasure, we overwrite these occurrences with a placeholder (e.g., '[deleted]') as part of the deletion process. This requires a separate data scrubbing operation beyond deleting your participant record.
Right to restriction (Art. 18). You can ask us to limit how we process your data in certain circumstances.
Right to data portability (Art. 20). You can request your data in a structured, commonly used, machine-readable format (JSON).
Right to object (Art. 21). You can object to processing based on legitimate interest. We will stop processing unless we have compelling legitimate grounds that override your interests.
Right related to automated decision-making (Art. 22). We do not engage in automated decision-making or profiling based on your personal data. If this changes, you have the right not to be subject to decisions based solely on automated processing.
Right to withdraw consent. Where processing is based on consent, you can withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Right to lodge a complaint. You have the right to file a complaint with your local data protection supervisory authority.
How to exercise your rights: Contact us using the details in Section 14. We will respond within 30 days. We may need to verify your identity before processing your request.
Participant identity verification: Because participants use nicknames and do not provide email addresses, we may verify your identity by confirming your nickname, team assignment, and simulation details with the facilitator. Facilitators can also submit deletion requests on behalf of participants.
10. Your Rights Under CCPA
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights.
Categories of personal information we collect:
- Identifiers (facilitator email, nickname; participant nickname)
- Internet or network activity (session tokens, facilitator IP addresses in audit logs)
- Professional or employment-related information (only if provided within simulation content)
Your CCPA rights:
Right to know. You can request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collection, and the categories of third parties with whom we share it.
Right to delete. You can request deletion of personal information we have collected from you, subject to certain exceptions under CCPA.
Right to opt out of sale. We do not sell personal information. We have never sold personal information. No opt-out is necessary, but you may still submit one and we will record it.
Right to non-discrimination. We will not discriminate against you for exercising your CCPA rights.
How to exercise your rights: Contact us using the details in Section 14. We will respond within 45 days.
Where both GDPR and CCPA apply to a request, we respond within the shorter applicable timeframe.
11. Users in the Middle East
Saudi Arabia (Personal Data Protection Law). If you are in Saudi Arabia, we process your data in accordance with the PDPL. You have the right to access, correct, and request deletion of your personal data. Data transfers outside Saudi Arabia are conducted with appropriate safeguards. For questions about your rights under the PDPL, contact us using the details in Section 14.
United Arab Emirates (Federal Decree-Law No. 45 of 2021). If you are in the UAE, we process your data in accordance with the UAE PDPL. You have the right to access, correct, and delete your personal data. Cross-border data transfers are conducted in compliance with applicable UAE regulations. For questions about your rights, contact us using the details in Section 14.
If your jurisdiction requires data localization or specific transfer mechanisms not addressed above, please contact us before using the platform so we can assess compliance.
12. Children
Read the Room is designed for professional training environments: universities, government agencies, and corporate teams. The platform is not directed at children.
Minimum age. Users must be at least 16 years old, or the minimum age required by applicable local law, whichever is higher.
Institutional authorization. If a facilitator plans to use Read the Room with participants under 16 (or the locally applicable age), the facilitator and their institution are responsible for obtaining verifiable parental or guardian consent before those participants join. The facilitator must confirm this authorization before allowing participation.
If we learn that we have collected data from a child without proper consent or institutional authorization, we will delete that data promptly. Contact us using the details in Section 14 to report such cases.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes:
- Material changes: We will notify facilitators by email and display a notice on the platform. Where a change affects the legal basis for processing, we will seek renewed consent where required.
- Non-material changes: We will update the "Last updated" date at the top of this policy.
We encourage you to review this policy periodically. Continued use of the platform after changes take effect constitutes acceptance of the updated policy.
Previous versions of this policy will be made available on request.
14. Contact Us
If you have questions about this Privacy Policy, want to exercise your data protection rights, or need to report a concern:
Data Controller: PoweredAI Solutions LLC
Email: info@poweredai.ai
Postal address: 1950 Barrett Lakes Blvd NW, Apt 215, Kennesaw, GA 30144
If you believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local data protection supervisory authority.
This Privacy Policy should be read alongside our Terms of Service, Acceptable Use Policy, Simulation Disclaimer, Data Retention Policy, and Security Overview.