Privacy Policy
Last reviewed: August 7, 2026
Ode'min Circle is operated by Chi Mino Ozhitoowin LP("we," "our," or "us"), the organization accountable for the personal data described here. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our AI-assisted grant matching and project planning services.
1. Information We Collect
1.1 Information You Provide Directly
- Account Information: Email address (used for one-time-code login), and any name or affiliation you choose to enter on your profile.
- Idea Wizard (Phase 1): When you use our Idea Wizard, we collect project descriptions, goals, location pins, sector tags, and any constraints you enter. We also store the artifacts generated during this process — strategic roadmap, project charter snapshots, generated paths and tasks, and grant rationales.
- Grant Selections: Which grants you view, pin, or unpin, used to refine our matching algorithms for your project.
- Phase 0 Handoff (if used): If you import a brief from a Phase 0 entry point, we receive your project intent, context, and readiness assessment data, plus a temporary handoff code.
- Communications: Anything you send us when contacting support or making a privacy/access request.
1.2 Automated Data Collection
- Usage Data: Pages visited, features used, server-side request timing, and AI tool-call counts. Used to operate, secure, and improve the platform.
- Device Information: Browser user-agent string and approximate IP geolocation, used for security (rate limiting, abuse detection) and basic analytics.
- Error Reports: When the application encounters an error, we record the error message, stack trace, and the page URL where it occurred. We may store the request method and route. We do not capture form values, idea text, or other content you have entered when reporting these errors.
2. How We Use Your Information
- To provide, maintain, and improve our AI-assisted grant matching and planning services.
- To generate project artifacts (charters, roadmaps, paths, draft application sections) tailored to your inputs. Note: outputs are AI-generated and require your review before submission to any funder.
- To send authentication codes (one-time login codes) via email.
- To send product news and feature updates, only if you have given express consent (CASL). You can withdraw this consent at any time from your notification settings or via the unsubscribe link in any such email.
- To prevent abuse, including rate-limiting requests and detecting automated traffic.
- To respond to your support, access, correction, or deletion requests.
3. Data Retention
How long we keep something depends on what it is. Every window below is the same number the software uses — the policy and the code read one shared value, so this page cannot quietly fall out of date with what actually runs. You can ask us to delete your data at any time (see section 7).
| What | How long | How it's kept |
|---|---|---|
| Anonymous drafts (started without an account) | 30 days after your last activity | Deleted when we run the clean-up — not yet on a fixed schedule |
| Phase 0 handoff codes | 24 hours | Deleted when we run the clean-up — not yet on a fixed schedule |
| One-time login codes | 5 minutes | Deleted when we run the clean-up — not yet on a fixed schedule |
| Accounts and project data | While your account is open; 30 days after you close it | Done by a person, when you ask |
| Error reports | Until triaged | Done by a person, when you ask |
- Anonymous drafts (started without an account): You can start an idea before you have an account. That draft — its title, your conversation with Boozhoo, and any image generated for it — is tied to this browser, not to you. Once nothing has been added to it for 30 days it is due for deletion, along with its conversation and the activity records that reference it. The clock reads the conversation and nothing else: it is the later of when the draft was started and the last message in it. Other things you do to a draft — pinning a grant, editing the canvas — do not reset it, so if you are still working on something, send a message or sign in. Signing in moves the draft onto your account, where the account rules below apply instead. You can delete it yourself at any time from the wizard, without signing in — that happens immediately. The clean-up that removes anything past its window is built but is not yet running on a schedule, so something may sit past its window until we run it. You can ask us to delete it sooner (section 7); we answer those requests within 30 days.
- Phase 0 handoff codes: A handoff payload carries an idea from an intake tool into the wizard. It stops working 24 hours after it is created and is then due for deletion — whether or not it was ever used. The clean-up that removes anything past its window is built but is not yet running on a schedule, so something may sit past its window until we run it. You can ask us to delete it sooner (section 7); we answer those requests within 30 days.
- One-time login codes: A login code stops working 5 minutes after it is sent. Using it deletes it immediately; a code that is never used is due for deletion once it expires. The clean-up that removes anything past its window is built but is not yet running on a schedule, so something may sit past its window until we run it. You can ask us to delete it sooner (section 7); we answer those requests within 30 days.
- Accounts and project data: Your ideas, charters, plans and conversation history are kept while your account is open. Ask us to delete your account (section 7) and that data is removed within 30 days, except where the law requires us to keep something. This one is done by a person on request — there is no automatic account expiry.
- Error reports: When something breaks we record the failure so we can fix it. These records are reviewed and closed by hand and are not on an automatic deletion schedule; we do not promise a fixed expiry for them. The structured details our code attaches to a report — named fields such as an email address or a phone number — are scrubbed before the record is written. The failure message, the stack trace and the page address are stored as written: we work to keep personal information out of them, and an automated check flags the known cases before code ships, but that is a practice we follow, not something the software guarantees. If you think a report holds information about you, ask us and we will remove it (section 7).
4. Service Providers and Cross-Border Transfers
We do not sell your personal data. To operate the platform we share information with the following service providers, each of whom is bound by their own privacy commitments and data-processing terms.
- Google (Gemini API)— generates AI text and embeddings from your idea/charter inputs. Subject to Google's API privacy terms. Used for: chat assistant, charter summary, grant rationale, embeddings, planning, application drafts.
- Supabase, Inc. — primary database and authentication infrastructure. Stores your account, ideas, charters, plans, tasks, and error logs.
- Vercel, Inc. — application hosting, serverless function execution, and edge networking.
- Resend — transactional email delivery (one-time login codes, account-related notifications).
- Cloudflare, Inc. (Turnstile) — bot deterrent on anonymous AI calls. Receives an opaque interaction token; no idea content is sent to Cloudflare.
- Upstash, Inc. (Redis) — request rate-limiting counters keyed on hashed identifiers. No idea or account content is stored in Upstash.
- Mapbox — map tiles and place geocoding when you set a project location.
We may also disclose information when required by law, in response to valid legal process, or to protect the rights, safety, and property of Ode'min Circle, its users, or the public.
5. Security
We use TLS encryption for data in transit, encrypted-at-rest storage at our infrastructure providers, row-level security policies in the database, and per-caller rate limiting on sensitive endpoints. Service-role credentials are stored only in the deployment platform's secret store. No method of transmission over the Internet or electronic storage is 100% secure, but we follow industry-standard practices proportional to the sensitivity of the data we hold.
6. Cookies and Tracking
We use a small number of cookies to operate the service. There are no others — every cookie this site sets is listed below, with how long it lasts.
| Cookie | Set by | Lasts | What it does |
|---|---|---|---|
session | First-party | 7 days | Your signed-in session — an encrypted, HTTP-only token set after a successful one-time-code login. Without it you would have to re-enter a code on every page.The 7-day clock is renewed when you come back after a day or more away, so an account in regular use stays signed in and an abandoned one expires. Signing out deletes it immediately. |
anon_session | First-party | 30 days, renewed while you keep using it | An anonymous identifier so you can start drafting an idea before you have an account. It links this browser to that draft — it is how we know the draft is yours to reopen.The 30-day clock restarts whenever you come back, so a draft you are still working on does not lock you out; it runs out only after 30 days away, which is also when the draft itself is deleted. Signing in does not clear it by itself — it is removed when your draft transfers to your account, which happens the next time you open the Idea Wizard while signed in. You can clear it from your browser at any time, and the draft it points to becomes unreachable from this browser if you do. |
wizard_verified | First-party | 30 minutes | Records that this browser passed the Cloudflare Turnstile human check, so the Idea Wizard doesn't challenge you again on every single message.It holds no personal data beyond the anonymous identifier above. |
Cloudflare Turnstile | Third-party | Short-lived; set by Cloudflare | Cloudflare's bot deterrent on the Idea Wizard. Cloudflare receives an opaque interaction token; none of your idea content is sent to them. |
We do not use third-party advertising or cross-site tracking cookies.
7. Your Rights
Under PIPEDA and applicable provincial privacy legislation, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data.
- Withdraw consent for non-essential processing where applicable.
- Make a complaint to the Office of the Privacy Commissioner of Canada.
Self-serve data export and account deletion are on our public-launch roadmap. In the meantime, use the form below to make a request and we will respond within 30 days, as required under PIPEDA. You do not need an account.
One deletion you can do yourself, today: a draft you started in the idea wizard without an account can be deleted from the wizard itself, and that happens immediately.
8. AI-Generated Content
Our service uses generative AI (currently Google Gemini) to draft project charters, paths, tasks, and application sections from your inputs. AI-generated content is clearly marked in the interface. You are responsible for reviewing any AI-generated text before submitting it to a funder, sharing it externally, or relying on it for decisions. We make no warranty as to the accuracy or completeness of AI-generated content.
9. Children
The platform is intended for use by adults. We do not knowingly collect personal information from individuals under the age of 16. If you believe a child has provided us with information, contact us and we will delete it.
10. Changes to This Policy
When we update this Privacy Policy we will revise the "Last reviewed" date at the top. Material changes will be announced here and via email to registered users where we have an address on file.
Contact Us
For access, correction, deletion, or consent-withdrawal requests, use the request form in Your Rights above — it reaches us directly and gives you a reference number.
Chi Mino Ozhitoowin LP
724 A City Rd, Fort William First Nation, ON P7J 1K4
(807) 577-8033
See also our Terms of Service.