Privacy
How Monderman handles your data.
This page explains, in plain language, how Monderman handles the information you provide and the diagnostic work you do on the platform: what is collected, when, why, and what control you have over it.
See also: Security & data handling for the technical posture and Public Beta Terms for the rules of use.
This edition explains how selected original answers from your own saved runs and grouped campaign answers can inform AI-assisted Synthesis. It requires a new, separate choice before optional written observations are used for this processing. Your account or campaign shows the edition you are asked to acknowledge. Publishing this notice does not change an earlier acknowledgement or grant permission to process optional observations. The Terms are unchanged; earlier acknowledgements remain recorded against the editions originally shown.
IDENTITY & SCOPE
Who operates Monderman and what this notice covers
Monderman, LLC, a South Dakota limited liability company with a mailing address at 41 W Highway 14, Unit #1225, Spearfish, SD 57783, operates Monderman, which is currently in public beta. Questions and privacy requests can be sent to connect@monderman.com.
This notice describes how the service handles personal information for accounts, authentication, billing, security, support, the 30-day Pattern beta trial, Workspaces, Diagnostics, campaigns, participant responses, reports, Synthesis and related product functions.
Monderman does not currently sell personal information, share it for cross-context behavioral advertising, or use customer or participant information for targeted advertising.
OUR ROLE
Monderman's role depends on the processing activity
Monderman determines why and how it processes account and authentication data, billing records, service-security and fraud-prevention data, legal-acceptance records, direct support and contact communications, service-administration records, and the optional website measurement described below. For those activities, Monderman generally acts as the controller or business.
For customer-directed Workspace campaigns, participant responses, customer reports and related organizational content, the sponsoring customer generally determines the business purpose and Monderman processes the information to provide the service. For that processing, Monderman generally acts as the customer's processor or service provider and follows the customer's documented instructions. Limited technical and security records may also be processed by Monderman for its own security, legal and compliance purposes.
The actual facts and applicable law determine these roles; a contractual label does not override the processing that occurs.
INFORMATION WE HANDLE
Accounts, Workspaces and service use
Account information can include your email address, name, sign-in provider identifiers, authentication events, organization membership, role and legal-acceptance records. Workspace administration can include the organization name, members, invitations, permissions, plan, usage allowances and settings.
Saved customer content can include Diagnostic context, structured answers, optional written observations and interview messages, derived scores and bands, charts, findings, generated interpretation, reports, Synthesis, Action Plans, comments, exports and related run metadata. Signed-in and campaign Diagnostic completions may be saved automatically as part of the requested workflow.
Billing and trial records can include Stripe customer and subscription identifiers, plan, billing interval, status, transaction or webhook references, and the limited Pattern-trial anti-abuse record. Support and contact records contain the information a person submits and related correspondence.
CAMPAIGNS
Recipient and participation data
If a Workspace administrator sends a Diagnostic campaign, Monderman may store the recipient's email address, name, business unit, team, assignment settings, delivery status and participation status so the campaign can be delivered and managed.
A directed assignment link can be completed without the recipient creating a Monderman member account. The Diagnostic response is still processed by the Monderman API and stored in the sponsoring Workspace according to the campaign settings.
PURPOSES & LEGAL BASES
Why Monderman processes information
Monderman uses account, Workspace, billing and product information to create and administer accounts; authenticate users; deliver requested outputs; manage plans, trials and billing; communicate about the service; provide support; maintain Terms-acceptance records; prevent fraud and abuse; and meet legal obligations. Technical operating records help us secure and improve the service. Customer responses, written observations, reports and organization history are not used to train models, develop cross-customer benchmarks or produce research for other customers.
Where EU or UK data-protection law applies to processing for which Monderman is controller, Monderman relies as appropriate on performance of a contract or steps requested before a contract, compliance with legal obligations, and legitimate interests in operating, securing, supporting and improving a business service, preventing misuse, communicating with users, and maintaining appropriate business records. Monderman considers those interests against the rights of affected people. Where Monderman specifically asks for consent for an optional activity, consent is the basis for that activity and can be withdrawn without affecting earlier lawful processing.
For customer-directed organizational and participant processing, the sponsoring customer is responsible for selecting and communicating its lawful basis where it acts as controller. Monderman does not treat a participant's acknowledgement of the collection notice as blanket consent to the sponsoring organization's processing.
ORGANIZATION DATA & RESEARCH
Your organization's content is used for your organization
Customer responses, written observations, reports and saved history remain within the customer's Workspace access rules. Authorized users can use their organization's saved results in its reports and Synthesis. Monderman does not pool this content across customers, use it to train or fine-tune a model, submit it as model-provider feedback, or add it to a shared research or benchmark library. De-identifying customer content does not create an exception to this restriction.
External practice guidance and any research-based comparisons use reviewed public or properly licensed sources, separate from customer content. A research estimate is not a Monderman peer percentile. Where comparable evidence is unavailable, the report says so. Technical service statistics, such as request counts, delivery status, error codes, latency and token usage, may be retained to operate and improve the service; they exclude response content and report prose.
ANONYMITY
Anonymous campaign responses
When a campaign is configured as anonymous, the completed Diagnostic result is not saved with an assignment ID or run-ID join back to the named recipient in the customer Workspace. Monderman still processes invitation records and necessary request, delivery, and security metadata to operate and protect the service. The Workspace can retain organizational context such as business unit or team, which may make a person inferable in a small group.
Because the customer Workspace has no direct completed-result-to-recipient join, a specific anonymous result ordinarily cannot later be located from the recipient identity alone. Monderman will still assess a rights request against any invitation, security, or other records that can be verified.
AUTHORIZED REVIEW
Support and advisory access is limited to the work you ask us to do
When your organization asks Monderman for support, troubleshooting or advisory work, authorized Monderman personnel may need to review relevant Workspace settings, Diagnostic results or related records to provide that service or investigate an issue. That access is for operating and supporting Monderman or delivering the engagement, not for advertising or sale.
AI PROCESSING
AI-assisted reports use Anthropic's commercial API when enabled
For enabled Diagnostic reporting, Monderman sends selected structured answers, computed results and relevant context to Anthropic's commercial API.
For Synthesis of your own saved runs, Monderman can send selected original structured answers and their questions, computed results, and each selected run's Diagnostic, chosen perspective, run length and questionnaire version. These are records saved under one account, not evidence from independent participants.
For campaign Synthesis, Monderman can send descriptive distributions of recorded answers to the same question, with the Diagnostic, role, run length, questionnaire version, units, answer conditions and response counts. These are grouped summaries, not named participants' individual answer records. Small or insufficiently supported groups are withheld. Grouped information can still be sensitive; it does not establish anonymity, representativeness or a peer benchmark.
Individual and Synthesis reports may also use a bounded selection of participant observations with their role and Diagnostic context, but only with the participant's recorded permission under this edition for those saved observations. A permission recorded for an earlier notice does not authorize this expanded use. Earlier observations are not automatically made eligible for this new processing. Leaving the optional choice unchecked does not change the structured score; the notes may still be saved and displayed under the Workspace's access rules. Written observations are not measurements or independently verified facts. The report identifies missing or omitted information.
The same permitted report evidence and proposed report text may also be sent to Anthropic to check request size before drafting or review. This check can occur even when no interpretation is generated. Monderman does not send Stripe card details or service credentials with report evidence.
The public assistant and Hans, the Workspace assistant, use Anthropic's commercial API for product questions and guidance. When you send a message, a limited recent conversation and approved public product information are sent to Anthropic. Hans also receives the current Workspace page and the plan and role checked by Monderman. The assistants do not automatically retrieve Diagnostic answers, saved reports, participant records or other organizations' data. Information you type into chat can be sent to Anthropic, so do not include personal, confidential, classified or controlled information, credentials or report contents.
Chat history is stored in this browser tab to support follow-up questions. New chat clears that local conversation; it does not recall requests already processed by Anthropic. Monderman's assistant application does not store chat transcripts in its database or intentionally write message contents to application logs. It keeps limited usage and security metadata for spending controls and troubleshooting. Some requests receive a rule-based refusal or an availability message without a model-provider call.
Report features are enabled in stages. The report's version and status identify the processing used for that result; publication of this notice does not activate a feature or regenerate an earlier report. The Monderman diagnostic engine determines scores, classifications, evidence limits and available action options. Where authored explanations are enabled for a report, Claude writes supporting explanations from authorized evidence within these rules. Automated checks and a separate AI review screen the completed text before release. These checks do not establish scientific validity or guarantee the suitability or effectiveness of a recommendation.
A separate public-research process may check primary sources using only a predefined sector category, Diagnostic type and date. Customer answers, observations, organization names and Workspace history are not sent to that search or included in its shared research library. Reports using this research process identify its date and limitations, or state that no newly checked research was available. Issued reports retain their original evidence and research snapshot.
Experiential-text cleanup runs in Monderman's application without a model-provider call. Interview mode is not currently available. These functions and the assistants are separate from AI-assisted report interpretation.
Quantitative Diagnostic scores are calculated deterministically by Monderman's scoring code from structured inputs. Anthropic does not calculate or set those scores. Current Depth Synthesis and Cross-Lens Synthesis calculations are also deterministic. Monderman does not use the AI provider to make employment or other decisions about participants; sponsoring organizations decide how to interpret and use the reports they receive.
Monderman does not use customer content for model training or fine-tuning, opt it into provider training programs, or submit it as provider feedback. Anthropic's commercial API does not use inputs and outputs for training by default. Standard API content can remain with Anthropic for up to 30 days, subject to its stated safety, legal and contractual exceptions. This is not a zero-retention arrangement. No-training and no-retention are different commitments.
BILLING & TRIALS
Stripe and the one-time Pattern trial
Stripe handles payment details through Stripe-hosted payment systems. Monderman stores billing identifiers and subscription state needed to provide access, such as Stripe customer and subscription identifiers, plan, billing interval and status. Monderman does not receive or store your full card number.
The 30-day Pattern beta trial is one-time per eligible account identity, not merely per Workspace. To enforce that rule, Monderman retains a small one-time Pattern-trial anti-abuse record containing the user identifier, normalized email address, associated Workspace identifier and trial dates. This record is designed to survive Workspace deletion so deleting and recreating a Workspace does not create another trial.
TECHNICAL DATA
Service, security and delivery records
Operating the service creates technical records such as request times, delivery events, authentication events, error logs, browser or network information supplied to service providers, and security or bot-verification signals. We use these records to operate, secure, troubleshoot and improve the service.
Contact forms, feedback and support requests store the information you submit so we can respond and investigate issues.
The signed-in product uses first-party browser storage for Supabase authentication, the selected theme, user-saved Diagnostic context, in-tab report/Synthesis state, assistant conversation history, checkout selection, and a short-lived Cloudflare bot-verification token. Session-scoped values normally end with the browser tab; saved preferences and authentication remain until logout, expiry, deletion, or browser clearing.
Stripe and Google can use essential cookies or browser storage on their own domains when you choose checkout or Google sign-in. Monderman does not use advertising pixels, cross-context behavioral advertising, or session-replay tooling. Authentication, security, service preferences and checkout storage support functions you request. Optional website measurement uses separate first-party browser storage only after the choice described below.
OPTIONAL MEASUREMENT
Choose whether to help us understand the first-run experience
Monderman asks before using optional measurement to understand which outreach sources bring people to the free Decision Velocity diagnostic and where people continue or stop before applying for the pilot. Choose Allow measurement or Continue without measurement. Either choice leaves the diagnostic, results, reports, sign-in and pilot application available. This choice is separate from account Terms acceptance and Privacy Notice acknowledgement.
We store your choice and its version in this browser so we can respect it. Before you allow measurement, we do not read or create a measurement visit identifier, read campaign labels for measurement, send measurement events, or add measurement labels to links. With permission, a random identifier stored for this browser tab groups limited events such as opening a diagnostic page, choosing a run length, clicking Start, displaying a result, requesting account access, entering a report view or following the pilot link. These events show browser activity, not proof that a diagnostic was accepted, a report was saved, or a customer purchased anything.
Each measurement event can contain the event time, random visit identifier, a recognized page path, event name, selected 10-, 30- or 60-minute run length, the measurement-choice version, and limited outreach labels. The source label is limited to LinkedIn, Facebook, X, email, referral, direct or unknown; the campaign label identifies our first Decision Velocity outreach or is empty. We do not put names, email addresses, account or Workspace identifiers, answers, scores, report text, full URLs, arbitrary query text, referring URLs, IP addresses or user-agent strings or device fingerprints in the measurement event table. Normal hosting and security systems can still receive request and network metadata when they serve the site or receive a request. We do not use device fingerprinting for this measurement.
If you allow measurement and then apply for the pilot, the same limited outreach labels and choice version may be stored with the application you submit. That application already contains the contact and organizational information needed to review it. It also records a recognized entry-page label, such as the homepage or Decision Velocity, and your answer about completing Decision Velocity. Those application details are separate from optional outreach labels. We do not attach the random measurement visit identifier to the application or use it to join your browsing events to your identity. Separately, application, invitation and billing records can be used to count applications, activations and confirmed payments. Those service records are not a record of an anonymous visitor's complete journey.
You can reopen Measurement choices near the footer on pages that offer measurement and choose Continue without measurement at any time. That stops new measurement and clears the measurement visit identifier and labels from this browser tab without clearing your sign-in or saved work. Your choice applies to this browser; make the choice separately on other browsers or devices. Clearing browser storage can also clear the preference. Withdrawal does not recall a request already sent or automatically erase earlier server records. You may contact connect@monderman.com about deletion. We cannot normally locate random-identifier events from an email address alone and will explain what can be verified without asking for unnecessary information.
Browser measurement identifiers and labels use tab-scoped storage. The choice preference remains until you change it, clear browser storage, or a changed measurement version requires a new choice. Event records become eligible for routine deletion after 90 days. Cleanup is triggered by accepted measurement events, at most once a day, so it may occur later when there is no traffic or a cleanup fails. Outreach labels stored with a pilot application remain with that application and can be addressed through the verified privacy-request process. They are not subject to the event table's 90-day cleanup. Related invitation, billing and trial records follow their separate purposes and periods below.
SERVICE PROVIDERS
Who processes data for Monderman
Core providers currently include Supabase for database and authentication, Render for the API, Anthropic for specified AI-assisted product functions, Resend for email delivery, Stripe for billing, Google for optional sign-in, and Cloudflare for bot verification. GitHub and browser content-delivery networks support the public site and browser libraries.
These providers receive information only as needed for their function. Depending on the function, recipients can also include the sponsoring customer and its authorized Workspace users, professional advisers, authorities or other parties where required by law, and a successor in a business transaction subject to appropriate protections.
The maintained Subprocessors and infrastructure page describes each provider's purpose, broad data category, and whether customer content may be processed. Organizational data-processing terms may be made available where required for an engagement. This page does not represent that a particular transfer mechanism, certification or data location applies.
RETENTION & DELETION
Retention follows the record's purpose
- In-progress Diagnostic recovery sessions expire after four hours.
- Customer Workspace content, including Diagnostic and Synthesis runs and related organizational records, is retained while the Workspace or customer relationship remains active, subject to verified deletion requests.
- After a verified customer or Workspace deletion request, affected records are removed from active systems within 30 days, except records that must be retained for billing, tax, legal, security, fraud or anti-abuse purposes and copies remaining in provider backups.
- Campaign invitation records are retained for the life of the campaign plus 12 months.
- Support and contact inquiries are retained for 24 months after the last substantive interaction.
- Optional website measurement events become eligible for routine deletion after 90 days; the traffic-triggered cleanup and browser-storage limits are described in Optional measurement.
- Ordinary operational and security logs are kept for up to 12 months, unless they are reasonably required longer for an incident, investigation, dispute or legal obligation.
- Billing and tax records are retained for seven years.
- Legal-acceptance records are retained for seven years after the relationship ends.
- The Pattern-trial anti-abuse record is retained for three years.
Service-provider backups follow the provider's controlled deletion schedule and may not be removed immediately from backup media. Any retained exception is limited to the purpose that requires it and is not returned to ordinary product use.
YOUR CHOICES
Privacy rights and requests
You can update ordinary Workspace information through the product where controls are available. You may also contact Monderman to request access to, correction of or deletion of personal information. Depending on the law that applies, you may also have rights to receive a portable copy, restrict or object to processing, withdraw consent for an activity based on consent, appeal a decision, or receive information about recipients and international processing. Monderman verifies requests and may retain information where an applicable legal, billing, security, fraud-prevention, dispute or backup exception requires it.
Anonymous campaign responses have a special limitation: the customer Workspace does not retain a direct completed-result-to-recipient join, so a particular anonymous result ordinarily cannot be located later from the recipient identity alone. Other verifiable invitation or security records remain subject to the applicable request process.
When Monderman processes participant or Workspace information for a sponsoring customer, Monderman may route the request to that customer because the customer controls the processing decision; Monderman will assist the customer as required. For information Monderman controls directly, send the request to connect@monderman.com.
You may lodge a complaint with the privacy or data-protection regulator available under the law that applies to you, including the regulator where you live or work or where an alleged infringement occurred. Monderman welcomes the opportunity to address a concern directly first, but contacting Monderman does not limit that right.
RESTRICTED INFORMATION
The self-service beta is for adult organizational use
Monderman is not directed to children or intended for use by people under 18. Do not intentionally submit payment-card data into Diagnostic fields, passwords or credentials, Social Security or other government identification numbers, financial-account credentials, classified information, biometric identifiers, children's data, protected health information, or other specially regulated or sensitive data that requires a separate legal or contractual arrangement. Payment-card details belong only in Stripe-hosted payment fields.
Monderman does not claim that the self-service beta is configured for HIPAA, FedRAMP or another specialized regulatory program. If information requires a separate arrangement, do not submit it until that arrangement is in place.
LOCATION
The beta is operated from the United States
Monderman and its service providers may process information in the United States and other jurisdictions where those providers operate. Privacy protections and government-access rules can differ from those in a person's home jurisdiction.
The self-service beta does not currently offer customer-selected data residency or a specially negotiated international-transfer arrangement. Monderman does not represent that EU Standard Contractual Clauses, a UK IDTA or Addendum, or another customer-specific transfer mechanism has been executed for self-service use. A customer whose information requires a specific transfer or residency arrangement must not submit that information through the self-service beta unless the required arrangement has first been established for the engagement.
CHANGES
Notice updates
Monderman may update this notice when the service or its data practices change. The version and date at the top identify this edition. Material changes will be presented through the service or another appropriate channel. Where a new acknowledgement is required, Monderman asks for it before allowing access to the affected features. Permission to use optional written observations is a separate choice and is not granted by acknowledging this notice.
CONTACT
Questions about privacy
Monderman, LLC
41 W Highway 14, Unit #1225
Spearfish, SD 57783
connect@monderman.com
You may also use the Connect form. Do not send passwords, authentication links, invitation tokens or full payment-card information with a privacy request.