Privacy
Private information must be treated as a duty.
Last updated September 14, 2026.
What HPG Initiation collects
When you choose to complete HPG Initiation, HPG receives the name and email address you provide, your selected arena and season, baseline scores, Vision, present constraint, Big Five, covenant, seven-day proof, and any optional Exchange contribution you write. HPG also records the consent choices, completion time, report identifier, and limited security information needed to prevent abuse.
Your on-device draft
Before completion, the reading stack, Performance System, HPG Initiation, and Exchange composer can save entries in local browser storage on the device you are using. Clearing browser data or changing browser or device may remove or hide those drafts. The browser draft is separate from the completed server record.
Completion, encryption, and private storage
Nothing in HPG Initiation is transmitted until you deliberately complete the final consent step. The completed profile is encrypted at the application layer before it is written to the profile database. The generated PDF is stored in a private object store without a public bucket address. Encryption keys and provider credentials are kept as encrypted hosting secrets and are not stored with the profile data.
No internet service can promise absolute security. HPG limits the information exposed for routing and cohort analysis, restricts access to operating personnel with a legitimate need, and reviews the system when its purpose or providers change.
Why the information is used
HPG uses the completed record to generate and deliver your report, preserve continuity between Initiation and member services, understand your present performance context, and support your requested community experience. If you separately select personalization, HPG may use your arena, season, and baseline pattern to shape relevant guidance, introductions, learning paths, and community experiences. Declining optional personalization does not prevent report delivery.
Private member access
Requesting a private sign-in link creates a limited member access record linked to the email address you provide, even when you have not completed Initiation. HPG does not store an account password. The single-use email link expires after 15 minutes. After verification, HPG places a secure, HTTP-only session cookie on the device. The session lasts for up to 30 days unless you sign out, it expires, or HPG revokes it for security.
The raw sign-in token is not stored in the member database. HPG stores keyed representations of sign-in tokens and session tokens, their creation and expiry times, use or revocation status, and limited keyed device or network information needed to enforce access and prevent abuse.
Your report and access emails
Your PDF and private access links are sent through HPG's transactional email provider to the address you supply. That provider and your own email service process the messages and attachment for delivery. Email security also depends on your provider, devices, and account practices. Keep the report and access links private.
The private member Exchange
After private sign-in and acceptance of the Exchange covenant, members may publish contributions, responses, useful signals, and outcome returns. Contribution and response content is encrypted at the application layer before storage. Operational fields such as channel, status, timestamps, activity order, and aggregate counts remain structured so the private room can filter, order, and govern the record.
Exchange content is presented only through authenticated member requests. Other signed-in members may read what you deliberately publish to the room. The private workbook, member profile, and stored report never become forum posts automatically. Initiation Note controls let you select and edit what enters the Exchange before publishing.
What HPG does not do
HPG does not sell initiation profiles or Exchange content, use them for third-party advertising, or place advertising trackers on this site. HPG does not treat a baseline or self-description as a medical, psychological, employment, financial, or legal diagnosis.
Retention and member control
HPG keeps member, Initiation, report, session, and Exchange records only while they support the membership, community, security, or recordkeeping purposes described here. You may request a copy, correction, deletion, or withdrawal of optional personalization consent. A deletion request removes the active HPG profile, member access record, active sessions, private report copy, and linked Exchange content after identity and request authority are reasonably confirmed. Copies already delivered to your email account remain under your control and that provider's practices.
Community privacy
Private member content should not be copied, exposed, or distributed outside HPG without the author's permission. HPG may restrict or remove access when conduct threatens member privacy, safety, or the integrity of the room.
Basic hosting data
Hosting and security providers may process technical information such as IP address, browser type, request time, and requested page to deliver and protect the service. HPG uses keyed, non-reversible representations of email and network identifiers for lookup and rate limiting where practical rather than retaining those raw identifiers in the initiation profile database.
Command Center records
When you confirm private storage and save a Command Center record, HPG stores your mission, Big Five, daily plans and actual activity, evidence notes, corrections, and weekly reviews in your member account. Record content is encrypted before database storage. Record type, date, revision number, and update time remain structured to retrieve your history and prevent accidental overwrites between devices.
Draft changes remain in the open page until you save. Command Center records are available only to your authenticated account and are never posted to the Exchange automatically. You can download the open record or draft, delete individual saved records, or request a complete account export or deletion through the contact below. Deleting a mission does not delete daily records that preserve the commitments from that mission.
Contact and privacy requests
Send questions, access requests, corrections, deletion requests, or personalization withdrawals to marc@asabove.tech. Include the private report ID when available, but do not email additional sensitive information unless it is necessary.