PRIVACY POLICY

Compass Foundation, LLC

Effective Date: Sept 30, 2026

Compass Foundation, LLC (“CF,” “we,” “us,” or “our”) is committed to protecting the privacy of the people and organizations that use our services.

Our business is providing services to our customers, not advertising to them or monetizing their information. We do not sell Personal Information, use customer information for targeted or behavioral advertising, or use customer content or activity data to train artificial intelligence or machine-learning models.

Some CF services necessarily process sensitive information. DrawBridge must inspect network activity and log resulting activity and filtering decisions to provide filtering and reporting. Daystar email stores and transmits customer messages. Clarion messaging protects private conversations with end-to-end encryption by default.

This Policy explains what information we process, why we process it, who may access it, and how we protect it.

CF collects, uses, retains, and discloses information only as reasonably necessary to provide and secure our services, administer customer relationships, fulfill the purposes described in this Policy, and comply with applicable law.

1. Scope and Definitions

This Policy applies to Personal Information processed through CF websites, accounts, support services, DrawBridge network filtering, Daystar email, Clarion messaging, and related services.

“Personal Information” means information that identifies or can reasonably be associated with an individual.

“Customer” means a person or organization that purchases or subscribes to a CF service.

“End User” means a person whose device, account, communications, or network activity is processed through a CF service.

“Authorized Administrator” means a person authorized by a Customer to administer a service or access information made available through it. This may include account owners, parents or guardians, employers, IT administrators, or accountability personnel.

A Customer and an End User may be different people. For example, a parent may administer a child’s device, or an employer may administer its network or corporate devices.

2. Account, Billing, and Support Information

CF may collect:

  • name and contact information;
  • account credentials and identifiers;
  • organization and service information;
  • billing and transaction information;
  • correspondence and support history; and
  • other information voluntarily provided to us.

Payment-card details are processed by our payment processor and are not retained in CF systems.

We use this information to establish and administer accounts, provide and bill for services, communicate with Customers, provide support, maintain security, and meet administrative obligations.

3. Security and Employee Access

CF maintains administrative, technical, and organizational safeguards designed to protect Personal Information from unauthorized access, use, disclosure, alteration, loss, or destruction.

Access to customer systems and Personal Information is limited to personnel whose roles require it. All CF personnel with authorized access to customer information are subject to contractual confidentiality obligations. Violations are subject to discipline or termination.

No Internet-connected system can be guaranteed completely secure. Customers are responsible for protecting their credentials, devices, and accounts.

If a security incident affects Personal Information, CF will investigate under its incident-response procedures and notify affected Customers and individuals as required by applicable law.

4. DrawBridge Network Filtering

Network Activity

DrawBridge provides network filtering, security, accountability, and reporting. To perform these functions, it necessarily inspects Internet and network activity on devices and networks configured to use the service and logs resulting activity and filtering decisions.

Depending on configuration, these records may include domains and URLs, DNS requests, search queries, IP addresses, timestamps, usernames, device identifiers, application or protocol information, filtering decisions and categories, and security events.

Where DrawBridge is configured to inspect encrypted (HTTPS) traffic, it may process the content of web pages and other information transmitted over the network to make filtering and security decisions. Inspection of content does not mean that the underlying content itself is retained in filtering records.

Internet activity can reveal highly sensitive information about a person. CF treats filtering records as confidential customer information.

Use of Filtering Information

CF uses filtering information to enforce Customer-selected policies, identify applicable devices or users, produce reports, troubleshoot problems, and secure and maintain the service.

Access to Filtering Information

Filtering information is available to the Customer and its Authorized Administrators. For family and individual accounts, this may include parents, guardians, account owners, or accountability personnel. For organizations, administrators may access activity on their networks or managed devices.

Authorized CF support personnel and engineers have technical access to filtering systems when reasonably necessary to operate, maintain, secure, diagnose, or troubleshoot the service; provide requested support; investigate misuse or security incidents; or perform another function necessary to provide the service.

Customer Responsibility

Customers are responsible for determining who may access filtering information and for using monitoring functions in accordance with applicable law. Organizations monitoring employees, students, members, or other End Users are responsible for providing required notices and obtaining required permissions or consents.

Retention

Detailed filtering records are retained as reasonably necessary to provide reporting, security, and support. Some information may subsequently be retained in summarized reports.

When an account is terminated, associated devices, accounts, and Personal Information are removed from active filtering systems. Residual copies may remain in backups until those backups expire or are overwritten.

5. Daystar Email

CF operates and hosts Daystar email infrastructure. Messages are encrypted in transit where supported by the communicating systems. Daystar email is not end-to-end encrypted.

CF sales and support personnel may access email account management interfaces to assist Customers with requested account maintenance, such as managing addresses and aliases. These interfaces do not provide access to email messages.

CF personnel do not access customer messages through webmail or other mailbox interfaces. Authorized CF system administrators may access message content through server-side administrative tools, such as command-line utilities, only when reasonably necessary to:

  • provide requested support;
  • diagnose or correct problems;
  • maintain, secure, back up, or restore the service;
  • investigate spam, malware, abuse, compromise, or security incidents; or
  • perform other necessary administrative functions.

6. Clarion Messaging

End-to-end encryption is enabled by default for private Clarion rooms. For properly end-to-end encrypted conversations, message content is encrypted so that CF cannot read it from the server.

Users or administrators may create unencrypted rooms, including public or server-wide channels. Content in unencrypted rooms may therefore be technically accessible to authorized CF system administrators.

End-to-end encryption protects message content but does not necessarily conceal operational metadata. Clarion may process account, device, connection, room, timing, delivery, server-log, and similar information necessary to operate and secure the service.

Clarion servers may be hosted on CF infrastructure or on DrawBridge equipment at a Customer’s location. In both cases, administrative access to the server is held by CF.

Federation

Customers may choose to allow their Clarion server to connect with other compatible messaging servers. When federation is enabled, other participating servers may receive and store messages and related metadata necessary to participate in a conversation. End-to-end encrypted content remains encrypted.

Information stored on servers not operated by CF is governed by those servers’ operators and policies. CF cannot control information held by servers it does not operate, including its retention or deletion.

7. Cookies and Tracking

CF does not use advertising cookies, behavioral-tracking cookies, advertising pixels, or third-party analytics services.

We use session and authentication cookies only as necessary to provide sign-in, account security, and requested functionality. These cookies do not track users across other websites.

Our systems may generate operational error information, such as the code path associated with a server error. CF does not intentionally include customer content in error alerts.

8. Location Information

CF does not collect GPS or other precise device location.

Our systems process IP addresses and other network information necessary to provide Internet-based services. This information may reveal an approximate geographic location but is not used to track users’ physical movements.

9. Service Providers and Disclosure

CF self-hosts most of its infrastructure, including remote support, customer relationship management, newsletters, email, and backup storage, to limit disclosure of customer information.

We use a small number of third-party providers where necessary, including data-center hosting, DNS, and payment-processing providers. We disclose to them only the information reasonably necessary to perform those functions.

CF does not disclose customer information for advertising or data-broker purposes. We may disclose Personal Information:

  • At the Customer’s direction, including to Authorized Administrators;
  • To provide our services, including through necessary infrastructure and service providers;
  • For legal purposes, when we reasonably believe disclosure is required by applicable law or valid legal process;
  • For security and protection, when reasonably necessary to investigate fraud, abuse, attacks, unauthorized access, or security incidents, or to protect CF, its systems, users, or others; or
  • In a corporate transaction, such as a merger, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality protections.

Where legally permitted and practical, CF will notify the affected Customer before disclosing Customer information in response to a legal demand.

10. Data Retention and Deletion

CF retains Personal Information only as long as reasonably necessary for the purposes described in this Policy, including providing our services, maintaining security and business records, and resolving disputes.

Filtering records are retained as described in Section 4. Email and Clarion content stored by CF is generally retained until deleted by the user or the applicable account is closed, subject to operational recovery periods and backups.

Account, billing, support, correspondence, and other business records may be retained after account closure where reasonably necessary for accounting, tax, security, dispute resolution, or other legitimate business purposes.

Information deleted from active systems may remain in backups until those backups expire or are overwritten.

For Clarion conversations involving servers not operated by CF, deletion from CF systems does not necessarily delete copies held by other participating servers.

11. Communications and Newsletters

CF may contact Customers about their accounts, services, security, support, and other administrative matters.

CF may also send current and former Customers newsletters and information about CF products or services where permitted by applicable law. Recipients may unsubscribe from marketing communications at any time.

Unsubscribing does not stop necessary transactional, security, or administrative communications.

12. Children’s Privacy

CF services are not directed to children under 13, and CF does not knowingly provide services directly to children under 13. Persons under 13 may not independently establish or administer a CF account.

CF is not responsible for unauthorized use of its services by a person who misrepresents or conceals their age. If CF learns that a child under 13 is independently using a CF service, CF will take appropriate action.

13. Privacy Rights and Requests

Depending on applicable law, individuals may have rights to access, correct, or delete Personal Information CF holds about them, or to learn how it has been used or disclosed.

CF will respond to verified requests and may verify a requester’s identity and authority before acting. Some information may be exempt or may need to be retained for security, operational, or other permitted purposes.

Where an organizational Customer controls the relevant information, CF may direct an End User’s request to that Customer or require the Customer’s involvement.

14. International Processing

CF is headquartered in Pennsylvania, United States, and serves Customers in the United States, Canada, and other countries.

Depending on the service and infrastructure used, Personal Information may be processed or stored in the United States or other countries where CF or its providers operate. Information processed in another country may be subject to that country’s laws, including lawful access by its courts and authorities.

15. Changes to this Policy

CF may update this Policy as our services or practices change. The current version will be published with a revised “Last Updated” date.

If a change materially affects how we collect, use, or disclose Personal Information, CF will provide additional notice where appropriate or required by law.

16. Contact and Complaints

Questions, privacy requests, or complaints about this Policy or CF’s handling of Personal Information may be directed to:

Compass Foundation, LLC

Attn: Privacy Officer

PO Box 488

Waynesboro, PA 17268 USA

Email: support@compassfoundation.io

If you are not satisfied with our response, you may have the right to complain to the applicable privacy regulator in your jurisdiction.