Herding Cats

Trust

Security

How Herding Cats keeps each person's results private, and what we do to protect the service.

Last updated 11 October 2026PLAYNICELY PTY LTD, South Africahello@herdingcats.team

In short

Herding Cats is built to keep each person's results their own. Admins never see them, colleagues see only a name and an archetype, and the most sensitive things you type are evaluated and then thrown away.

AreaWhat we do
Where data livesMain database in the EU (AWS, Stockholm)
EncryptionTLS for everything in transit; encrypted at rest
Who can see whatDatabase rules mean each person can reach only their own data
AdminsSee seats and invitations, never results or content
AIClaude by Anthropic, not used for model training
Sign-inHashed passwords; authenticator-app two-factor sign-in available on every account
TrackingNo tracking or advertising cookies, no third-party analytics

Each person's data is their own

  • Row-level security in the database means every request can reach only the data that belongs to the signed-in person. This is enforced by the database itself, not just by the app's screens.
  • Every server function checks who you are against your signed-in identity before it does anything.
  • Colleague connections need both people to agree, and both must share a work email domain. A colleague sees your name and archetype, never your talent themes.
  • Admins manage seats and invitations. There is no admin view of anyone's results, chats, notes or reads.
  • Our own staff do not look at personal content, except when you ask us for help or the law requires it.

Keeping less

  • Your CliftonStrengths® PDF is deleted as soon as your theme data has been taken from it.
  • Chats end 24 hours after your last message, and never more than 7 days after they began. The full conversation is then deleted.
  • Text entered into the Agreement, Feedback and Conflict Navigators is evaluated and discarded. Nothing is kept unless you save the read, and a saved Feedback or Conflict read never contains what you wrote.
  • Before text reaches the AI, our system removes internal identifiers.

Technical controls

  • TLS on every connection, and encryption at rest with our database provider
  • Passwords stored only as secure hashes
  • Two-factor sign-in with an authenticator app, available to every account
  • Email confirmation required before an account can be used
  • Bot and abuse protection on sign-up and sign-in (Cloudflare Turnstile)
  • Per-person limits on AI features to prevent abuse
  • API keys kept as server-side secrets, never sent to the browser
  • Administrative access limited to verified administrators

Our providers

We use a small set of established providers: Supabase (database, EU), Anthropic (AI), Dodo Payments (merchant of record), SendGrid (email), Cloudflare (abuse protection and delivery), Google (optional sign-in), Railway (app hosting) and Hostinger (website hosting). Each one processes data only to provide its service to us, under a data processing agreement. The full list, with locations, is in our Privacy Policy.

Card details go straight to Dodo Payments. They never reach us.

Privacy law

We follow South Africa's POPIA as our home framework, and apply GDPR standards to everyone. Access, export, correction and deletion are all self-service in Account Settings. A data-protection impact assessment for the platform has been completed and signed off by our Information Officer.

Reporting a security issue

If you think you have found a security problem, email hello@herdingcats.team with the subject "Security report". Please give enough detail for us to reproduce it, and do not access other people's data, disrupt the service or make the problem public before we have had a chance to fix it. We will reply as soon as we can and keep you updated.

For procurement and IT teams

If your company needs more detail for due diligence, such as a data processing agreement or answers to a security questionnaire, email hello@herdingcats.team.