Draft, requires legal review before production use
This document was written from what the running system actually does: the edge gate, the database and its row level security, and the third party requests these pages make. It has not been reviewed by a lawyer. Anything that is a business decision rather than a fact about the software is marked in place rather than guessed at.
Privacy
What DrivenMemory stores, and what leaves your browser
DrivenMemory is a website with accounts. That means it does hold data about you, and this page says which data, where it goes and who can read it. It does not claim to collect nothing, because that would not be true.
Reading without an account
The marketplace, listing pages, company pages, published Passports, the community forums and these legal pages are readable without signing in. No account is created by reading them, and no profile of you is built by reading them.
Typefaces are served from this site itself; since 26 August 2026 no font request reaches a third party. Two third parties receive a request from your browser while you use the site: Cloudflare serves the site (every request passes through it, so it sees your IP address and the usual request headers), and hCaptcha loads on the sign in page only, as the anti-abuse check for sign in. Their handling of those requests is described in their own privacy documentation.
There is no analytics service on this site. No Google Analytics, no product analytics, no session recording, no advertising pixel, no fingerprinting. One thing is recorded first-party: when a signed in visitor opens a listing or company or runs a search, a small event row is written recording what was looked at or searched, and when. That row carries no account identifier: the table has no user column, so it cannot say who looked. It exists so the marketplace can one day report honest aggregate interest to sellers; today nothing reads it at all.
When you create an account
Authentication is handled by Supabase. Your email address and your password go to Supabase directly; we never see or store a password, and account email (confirmation, password reset) comes from that authentication service. What our own database then holds about you:
- A profile row: display name, handle, bio. It is private by default and becomes publicly readable only when you turn community visibility on in Settings.
- Settings: interface preferences, stored as a small document. This includes two advertising preference switches (sponsored placements, personalisation) which today control nothing, because no advertising or personalisation system runs; they exist so the choice is already yours if such a thing ever ships.
- Interests: topics you add in Settings, shown on your profile only when your profile is visible.
- Blocks: your list of blocked community members, readable by you alone.
When you use the marketplace as a buyer
- Saved listings, and the private note you can write on each. Both are readable by you alone. The company that published a listing is never told that you saved it, and never sees a note. Saving while signed out is kept in your browser only and sent nowhere.
- Enquiries. Sending an enquiry stores the name, email address and message you typed. That row is deliberately shared: every member of the receiving company's team can read it, because answering it is their job. You can read the enquiries you sent, with the status the company set. Replies, if any, happen by email outside DrivenMemory.
- Comparison lives in the page address while you use it and stores nothing.
When you publish as a company
The company profile, its listings, an optional logo and listing images, membership rows (who belongs to the company, with which role), and invitation records are stored. An invitation stores the role offered and a cryptographic hash of the invitation token, never the token itself, plus who created it and who accepted it. A subscription row records the plan and status that publishing requires; no payment provider is connected, so no payment data of any kind exists anywhere in the system.
In the community
Threads, replies and votes are public by design; posting needs an account. Reporting content stores your report (what you reported and why); the report is readable by you and by platform administrators, and its status changes when it is handled.
What we do not store
No password. No payment card, at any point, in any form. No location, no contacts, no address book, and no content from your device beyond what you type into the product and the images a company chooses to upload. We keep no server-side log of which pages your account visited.
Cookies and browser storage
DrivenMemory itself sets exactly one cookie: driven_session, created when you sign in and removed when you sign out. It is HttpOnly (not readable by script) and SameSite=Lax, and it exists so the access gate at the edge can tell a signed in request from an anonymous one. It is strictly required for signing in, and nothing optional or promotional is set, which is why there is no cookie banner. The hCaptcha widget on the sign in page may set its own cookies under its own policy.
Browser storage on your device holds your session token (so the browser can talk to the database as you), your saved-listings list, your selected company, and your appearance choice. The appearance choice never leaves your device. Signing out ends the session; the saved list stays on the device by design, so an anonymous shortlist survives.
Who processes it
Two processors, both named because you should be able to check them yourself:
- Supabase hosts the database, authentication and file storage. This project runs in Supabase's eu-west-1 region (AWS, Ireland). Supabase publishes a data processing addendum that applies together with its terms of service.
- Cloudflare serves the site and runs the access gate in front of it. Cloudflare offers a customer data processing addendum.
Needs a decision: confirmation that each processor's data processing addendum has been reviewed and applies to this account, the legal basis relied on for each processing purpose, and the international transfer analysis. Those are contractual and legal determinations, not properties of the code, so they are not asserted here.
Who can read your data
The database enforces this, not the interface. Every table has row level security, and a hidden button is never what keeps a row private:
- Your profile row is readable by you. It becomes readable by anyone only when you turn community visibility on.
- Your saved listings and private notes are readable by you alone.
- An enquiry you send is readable by you and by the members of the company you sent it to.
- Your blocked list is readable by you alone; your content reports by you and platform administrators.
- Company data is readable by members of that company, and by the public once the company is published.
Deleting your data
Account deletion is not connected yet. The interface shows the flow and keeps the control switched off rather than accepting a request it cannot carry out. Until it exists, write to hello@drivenmemory.com and it is done by hand. An enquiry you sent to a company is also part of that company's correspondence, so removal of already-delivered enquiries involves both sides. Self-service data export is not built either; ask by email.
Needs a decision: how long data is kept after deletion, what is retained for legal or accounting reasons, and how a request is verified.
Children
Needs a decision: a minimum age for an account, and how it is stated at sign up. Nothing in the product asks for or verifies age today.
Changes
This document changes when the product does. It carries a version and the date it was prepared, and a material change should be announced rather than quietly published.
Contact
Questions about any of this go to hello@drivenmemory.com.
Driven Inbox (desktop app)
Driven Inbox, the Windows desktop product, processes mail entirely on your own computer and sends nothing to Driven servers — so nothing it reads is covered by, or added to, the processing described on this page. Its permissions, storage and read-only architecture are documented on its product page.