Introduction
Welcome to Chapter OS. Chapter OS ("we," "our," or "us") is committed to protecting the privacy of our customers, their chapter members, and all users of our platform. This Privacy Policy explains how we collect, use, store, and protect your information when you use the Chapter OS platform, website, and related services (collectively the "Services").
Who we are
By accessing or using Chapter OS, you agree to the terms of this Privacy Policy. If you do not agree with this policy, please do not use our Services.
Information we collect
Information You Provide to Us:
Chapter Information: When a chapter subscribes to Chapter OS, we collect the chapter name, organization name, city, state, country, timezone, website URL, and contact email address. Each chapter is a fully isolated tenant workspace.
Administrator Information: We collect the name and email address of chapter administrators (Chapter Owner, module admins, and role holders) who manage the platform on behalf of their chapter.
Member Information: Chapter administrators may input member information into Chapter OS. This may include member names, email addresses, phone numbers, company names, business URLs, revenue ranges, employee counts, LinkedIn profiles, business descriptions, ownership structures, entrepreneurial backgrounds, goals, and connections to other members. Home addresses are collected for the Membership Map and are kept behind a separate permission.
Forum & Engagement Data: Chapter administrators and members generate data through forum activities including meeting agendas, 5% Reflections, parking lot topics, accountability goals, attendance records, health survey responses, Forum DNA questionnaires, Forum Preferences surveys, and engagement check-ins.
Billing Information: All payment processing is handled securely by Stripe via hosted Checkout and Payment Links. We do not store your full credit card number, CVV, or banking details on our servers. Stripe manages subscriptions, invoices, prorated upgrades, and scheduled downgrades on our behalf.
Communications: If you contact us via email or support channels we collect the content of your communications and your contact details.
Information We Collect Automatically
Usage Data: We automatically collect information about how you use Chapter OS, including pages visited, features used, actions taken, and login timestamps. Sessions last 7 days and use secure, HTTP-only cookies.
Device Information: We collect information about the device you use to access Chapter OS, including browser type, operating system, and IP address.
Cookies and Tracking: We use secure, HTTP-only session cookies to maintain your authenticated session. Chapter OS does not use third-party advertising trackers. You can control cookies through your browser settings; however, disabling cookies will prevent you from using the platform.
How We Use Your Information
We use the information we collect for the following purposes:
To Provide Our Services: To create and manage your chapter workspace, process your subscription, deliver platform features across all four modules, and support your chapter operations including forum management, member placement, engagement tracking, and budget allocation.
To Process Payments: To process annual subscription fees and manage billing through Stripe. This includes handling prorated upgrades, scheduled downgrades, and failed-payment recovery.
To Communicate with You: To send transactional emails including account activation, invitation links, role assignments, onboarding nudges, placement renewals, and password resets. Chapter OS does not send marketing emails, newsletters, or digest emails.
To Improve Chapter OS: To analyze usage patterns, identify bugs, improve existing features, and develop new functionality. AI-assisted features (compatibility scoring, health scoring, 5% Reflection summaries, forum overviews) use OpenAI by default. Sensitive health survey answers are never sent to AI models.
To Ensure Platform Security: To enforce database-level tenant isolation via PostgreSQL Row-Level Security, detect unauthorized access, and maintain audit records of all administrative actions.
To Comply with Legal Obligations: To meet applicable legal, regulatory, and contractual requirements.
Data Storage and Security
Where We Store Your Data: Your data is stored on DigitalOcean App Platform servers located in the United States, using a managed PostgreSQL 16 database. Uploaded files are stored in Cloudflare R2 (S3-compatible) with a private bucket per environment, namespaced per chapter.
How We Protect Your Data: We implement the following verifiable security measures:
Database-enforced tenant isolation: PostgreSQL Row-Level Security on every chapter-owned table ensures isolation is enforced by the database itself, not by application code.
Every request is pinned to exactly one chapter, running in its own transaction under a restricted database role. If no chapter is pinned, queries match no rows — the failure mode is 'see nothing,' never 'see everything.'
Every administrative action by Chapter OS staff is recorded to a durable audit table (actor, action, target, detail) committed atomically with the change.
Passwords are never set by administrators. Every admin-added person receives a secure link to set their own password. Invitation responses are identical whether or not the email already exists.
Non-membership returns 'not found,' not 'forbidden.' The platform never reveals that other chapters exist. There is no cross-chapter query layer — the only sanctioned cross-tenant path is the Product Owner staff portal.
Data Retention: We retain your information for as long as your chapter subscription is active or as needed to provide our Services. If a payment is missed, the chapter is locked behind a hold page but nothing is deleted — everything is preserved and returns the moment billing is back in good standing. Upon cancellation, data is retained for a reasonable period before permanent deletion unless a longer retention period is required by law.
Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal information:
Access: You have the right to request a copy of the personal information we hold about you. Chapter administrators can view and export member data directly within the platform.
Correction: You have the right to request that we correct inaccurate or incomplete information. Members can update their own profile and account settings directly.
Deletion: You have the right to request that we delete your personal information, subject to certain legal exceptions. Chapter deletion permanently removes all chapter data and is irreversible.
Portability: You have the right to request that we provide your data in a structured, commonly used, and machine-readable format.
Objection: You have the right to object to certain types of processing of your personal information.
To exercise any of these rights, please contact us at: marlon@forumos.co
We will respond to your request within 30 days.
Third Parties
Chapter OS integrates with the following third-party services to deliver our platform: Stripe (payment processing, subscriptions, and invoicing), Cloudflare R2 (file storage), OpenAI and Anthropic (AI-assisted features such as compatibility scoring, health scoring, and content summaries), OpenStreetMap/Nominatim (geocoding for the Membership Map), and SMTP email providers (transactional emails via nodemailer). We share only the minimum data necessary for each service to function. We do not sell your personal information to any third party.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Last Updated" date at the top of this page and notify active chapter administrators via email at least 30 days before the changes take effect.
Your continued use of Chapter OS after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. If you do not agree with the changes, you may cancel your subscription before the changes take effect.