Privacy Policy
Last updated: March 2026
OfficePoll is operated by Maxwell Cyberlogic LLC, a Delaware limited liability company. This Privacy Policy explains how we collect, use, and protect your information when you use OfficePoll ("the Platform"). Privacy is not a feature we added — it is the foundation on which the entire Platform is built.
1. Information We Collect
Account Information (via LinkedIn OAuth)
When you sign up, we receive the following from LinkedIn:
- Your name
- Your email address
- Your LinkedIn ID
- Your profile photo URL
We use this information to create your account, generate your profile slug, and match escrow feedback to your account when you sign up.
Feedback Data
When someone submits feedback, we collect:
- Numerical ratings across professional categories (1-5 scale)
- Freeform text feedback (immediately anonymized, original permanently deleted)
- The relationship between reviewer and recipient (e.g., peer, manager, report)
Session Data
We use session cookies managed by NextAuth.js to keep you signed in. See our Cookie Policy for details.
2. Information We Permanently Delete
This is what makes OfficePoll different from most platforms. We are aggressive about deleting data:
- Original feedback text is permanently deleted immediately after AI-powered anonymization. There is no soft delete, no archive, no backup of the original. It is gone.
- Escrow feedback for non-users is permanently deleted after 90 days if unclaimed.
- Deleted accounts have their profile and associated data removed. A 90-day cooldown period applies before re-registration.
3. Information We Never Collect
We have made deliberate architectural decisions to avoid collecting certain data entirely:
- IP addresses on feedback submissions. We do not log, store, or process the IP address of anyone submitting feedback. This is enforced at the application level.
- The social/feedback graph. While we technically process who submits feedback for whom (to prevent duplicates and enforce rules), this relationship data is never exposed to any user. No one can see who reviewed them or who they reviewed.
- Tracking cookies or advertising identifiers. We do not use any analytics trackers, advertising pixels, or third-party tracking cookies.
- Browsing behavior. We do not track pages visited, time on site, or click patterns.
4. How We Use Your Information
- To create and maintain your account.
- To process, anonymize, and store feedback.
- To generate synthesized aggregate feedback reports.
- To match escrow feedback to your account upon signup.
- To send at most one notification email to non-users who may have feedback waiting in escrow (no follow-ups or reminders).
- To enforce platform rules (give-to-get, crowd thresholds, opt-outs).
5. Third-Party Services
We use the following third-party services to operate the Platform:
AI Language Model Providers (currently OpenAI) — Used for feedback anonymization (PII scrubbing, stylometric neutralization), report synthesis, and AI career coaching. Feedback text is sent to the provider's API for processing. We select providers whose API data usage policies do not use inputs and outputs for model training. The specific provider may change over time.
Supabase — PostgreSQL database hosting. Stores anonymized feedback, user profiles, and platform data. Hosted with row-level security policies.
Vercel — Application hosting and serverless function execution.
Resend — Transactional email delivery. Used exclusively for one-time escrow notifications to non-users.
LinkedIn — OAuth authentication provider. We receive profile data you authorize during sign-in.
Sentry — Error monitoring. May capture technical error data to help us fix bugs. Does not capture feedback content.
6. Data Retention
- Account data: Retained until you delete your account.
- Original feedback text: Deleted immediately after anonymization (seconds, not days).
- Anonymized feedback and reports: Retained as long as the recipient's account is active.
- Escrow feedback: Automatically deleted after 90 days if unclaimed.
- Session cookies: Expire when your browser session ends or after a set period (see Cookie Policy).
7. Your Rights
Access
You can access your profile information and feedback reports through your account dashboard.
Deletion
You can delete your account through your account settings. This removes your profile and associated data. Note that anonymized feedback already incorporated into other users' synthesized reports cannot be individually extracted, as the original text no longer exists and the content has been aggregated.
Opt-Out
Any person may permanently opt out of OfficePoll, preventing all future contact and feedback submissions. Opting out requires an OfficePoll account with a verified LinkedIn profile to ensure accurate identity matching. Visit our opt-out page to exercise this right.
Data Portability
You may request a copy of your data by contacting us. This includes your profile information and any synthesized reports generated for you.
8. No Data Selling
We do not sell, rent, or trade your personal information to third parties. We do not display advertising. Your data is used exclusively to operate the Platform as described in this policy.
9. CCPA Notice (California Residents)
If you are a California resident, you have the right to:
- Know what personal information we collect and how it is used.
- Request deletion of your personal information.
- Opt out of the sale of personal information (we do not sell data).
- Not be discriminated against for exercising your privacy rights.
To exercise these rights, contact us at privacy@officepoll.com.
10. GDPR Notice (European Users)
If you are located in the European Economic Area, you have additional rights under the General Data Protection Regulation, including the right to access, rectify, erase, restrict processing, and port your data. Our legal basis for processing is your consent (provided through LinkedIn OAuth) and our legitimate interest in operating the Platform.
To exercise your GDPR rights, contact us at privacy@officepoll.com.
11. Security
We implement reasonable technical and organizational measures to protect your data, including row-level security on our database, encrypted connections (HTTPS), secure session management, and API authentication. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
12. Children's Privacy
OfficePoll is designed for working professionals and is not intended for use by anyone under 18 years of age. We do not knowingly collect information from minors.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by posting the revised policy on the Platform with an updated date. Continued use of OfficePoll after changes are posted constitutes acceptance.
14. Contact
For privacy-related questions or to exercise your rights, contact us at:
Maxwell Cyberlogic LLC
Delaware, United States