In short
Herding Cats is built to keep each person's results their own. Admins never see them, colleagues see only a name and an archetype, and the most sensitive things you type are evaluated and then thrown away.
| Area | What we do |
|---|---|
| Where data lives | Main database in the EU (AWS, Stockholm) |
| Encryption | TLS for everything in transit; encrypted at rest |
| Who can see what | Database rules mean each person can reach only their own data |
| Admins | See seats and invitations, never results or content |
| AI | Claude by Anthropic, not used for model training |
| Sign-in | Hashed passwords; authenticator-app two-factor sign-in available on every account |
| Tracking | No tracking or advertising cookies, no third-party analytics |
Each person's data is their own
- Row-level security in the database means every request can reach only the data that belongs to the signed-in person. This is enforced by the database itself, not just by the app's screens.
- Every server function checks who you are against your signed-in identity before it does anything.
- Colleague connections need both people to agree, and both must share a work email domain. A colleague sees your name and archetype, never your talent themes.
- Admins manage seats and invitations. There is no admin view of anyone's results, chats, notes or reads.
- Our own staff do not look at personal content, except when you ask us for help or the law requires it.
Keeping less
- Your CliftonStrengths® PDF is deleted as soon as your theme data has been taken from it.
- Chats end 24 hours after your last message, and never more than 7 days after they began. The full conversation is then deleted.
- Text entered into the Agreement, Feedback and Conflict Navigators is evaluated and discarded. Nothing is kept unless you save the read, and a saved Feedback or Conflict read never contains what you wrote.
- Before text reaches the AI, our system removes internal identifiers.
Technical controls
- TLS on every connection, and encryption at rest with our database provider
- Passwords stored only as secure hashes
- Two-factor sign-in with an authenticator app, available to every account
- Email confirmation required before an account can be used
- Bot and abuse protection on sign-up and sign-in (Cloudflare Turnstile)
- Per-person limits on AI features to prevent abuse
- API keys kept as server-side secrets, never sent to the browser
- Administrative access limited to verified administrators
Our providers
We use a small set of established providers: Supabase (database, EU), Anthropic (AI), Dodo Payments (merchant of record), SendGrid (email), Cloudflare (abuse protection and delivery), Google (optional sign-in), Railway (app hosting) and Hostinger (website hosting). Each one processes data only to provide its service to us, under a data processing agreement. The full list, with locations, is in our Privacy Policy.
Card details go straight to Dodo Payments. They never reach us.
Privacy law
We follow South Africa's POPIA as our home framework, and apply GDPR standards to everyone. Access, export, correction and deletion are all self-service in Account Settings. A data-protection impact assessment for the platform has been completed and signed off by our Information Officer.
Reporting a security issue
If you think you have found a security problem, email hello@herdingcats.team with the subject "Security report". Please give enough detail for us to reproduce it, and do not access other people's data, disrupt the service or make the problem public before we have had a chance to fix it. We will reply as soon as we can and keep you updated.
For procurement and IT teams
If your company needs more detail for due diligence, such as a data processing agreement or answers to a security questionnaire, email hello@herdingcats.team.