Status: working draft, not final legal copy — see ProblemBank_Legal_Scaffolding_Outline.md and have a lawyer review before this is relied on for real users at scale.
Account information you give us directly: name, email, and password (stored as a salted hash, never in plain text). If you enable two-factor authentication, we store a TOTP secret used only to verify your login codes. Activity you generate on the platform: problems you submit, ideas you propose, votes you cast, and role activation requests. Every one of these actions is also written to an internal, tamper-evident audit log (see the Trust & Security page) — this exists to keep votes and submissions honest, not to profile you.
ProblemBank does not currently process payments, bank account information, or any data through Plaid or a similar financial data aggregator. If that changes — for example, to support Investor payouts — this policy will be updated first, and that section will describe exactly what's collected, why, and how it's protected before the feature goes live.
To operate your account, show you your own dashboard and role activity, weight votes by reputation, and let you propose or fund solutions to problems. We don't sell personal data, and as of this writing no AI feature on the platform is live in production — see the Trust & Security page for the current, honest status of AI features and the guardrails that will apply once they ship.
You can delete your account at any time from your Profile page. Deleting your account removes your name, email, password, and MFA credentials immediately. Problems, ideas, and votes you contributed remain on the platform, re-attributed to "Deleted User" — this is a deliberate tradeoff (not an oversight): those contributions are shared platform content that other users' votes and reputation depend on, not private data about you once your identifying information is removed. If you have concerns about this, contact us using the details on the Trust & Security page before deleting your account.
Account data is kept for as long as your account is active. Audit log entries are retained indefinitely in hash-chained form to preserve the integrity of the voting and reputation system, but they reference actor IDs, not personal profile data, once an account is deleted.
Creating an account requires actively checking a box agreeing to this policy and the Terms of Service — consent isn't inferred from account creation alone, and the timestamp of that consent is recorded on your account.
Questions about this policy or your data: [fill in a real, monitored security/privacy contact email before this goes live — see SECURITY.md].