Your Privacy at a Glance
You are trusting this app with material about your marriage, your faith, your money and your children. The summary below is the short version of what happens to it. The full policy follows, and it is written to be read.
Stored on Our Own Server
One database on a server we run, encrypted in transit, with encrypted backups.
The AI Reads What You Write
Anthropic's Claude processes your conversations, your statements and the documents you upload. There is no setting that turns it off.
No Marketing Analytics
No Google Analytics, pixels, or ad tracking. Only error monitoring to keep the app working.
100x Staff Can See Your Work
Coaches and administrators can read your statements, scores and recaps, and can open the app as you.
Export Everything, Anytime
Download your complete record as JSON, or your roadmap as an Excel workbook.
Clear Your Data
Clear what the AI remembers about you, or delete all of your content, from Settings.
1. Introduction
100x Roadmap ("we," "our," or "the app") is a life planning tool created by 100x Forum. This Privacy Policy explains how we collect, use, and protect your information when you use our application.
Your reflections, goals and life plans are private material, and this policy describes what the app does with them in specific terms rather than general ones. Where something may surprise you, we have said so plainly instead of leaving it to be inferred.
2. Information We Collect
Information You Provide
Everything you write in the app is stored on our server as you wrote it. That includes:
- Your mission, who you want to become, your metrics and your strengths
- Reflections such as Retracing My Steps and My 80th Birthday
- Your answers to the eight Setting the Stage questions and to the steps in the guide
- Action areas and the plans inside them
- Your Platform, Family, Faith, Philanthropy and Time Allocation entries, including sliders and scenarios
- Notebook entries and any edits you make to them
- Items you put in the parking lot
- Every message you send to the AI coach, stored word for word
- Names, relationships and notes about the people in your relationship map, including family members and children
- Photos you upload of those people, and your own profile photo
- Whether you are married and whether you have children
- Documents you upload: CliftonStrengths results, a Strengths Matrix, Foundation Assessment results, your life story
- Text you paste in from another AI when you use Memory Sync
Information Collected Automatically
We collect a small amount of technical data:
- Sign-in sessions: each session records your IP address and your browser's user agent.
- Navigation: we record the pages you open inside the app and when, so the app can offer to return you to where you left off.
- AI usage: for each AI request we record the feature, the model and the number of tokens in and out. No prompt text and no reply text is stored in that record.
- Error reports: when something goes wrong we collect error details (stack traces, browser type, page URL) via Sentry to fix bugs. See below for what is removed first.
- We do not use analytics services (no Google Analytics, Mixpanel, or similar)
- We do not use tracking pixels or cookies for advertising
- We do not use device fingerprinting
Signing In
You can sign in two ways, and both are required to identify your account and nothing else.
- Google Sign-In. We receive and store your Google account email address, your display name, your given and family names, your Google account identifier and the URL of your Google profile photo. We verify a single identity token. We do not request access to Gmail, Drive, Calendar or any other Google service, and we make no other calls to Google on your behalf.
- Email sign-in link. We email you a link that signs you in. A link you request yourself lasts twenty minutes. A link sent to you by 100x staff, such as an invitation or a nudge, lasts seven days. Either link can be used up to five times so that a mail scanner opening it first does not lock you out.
Once you are signed in you stay signed in until you sign out. Sessions do not expire on a timer.
3. How Your Data is Stored
| Where Data Lives | Details |
|---|---|
| Our application server (system of record) | A single database on a server we run at DigitalOcean. Encrypted in transit over HTTPS. Sign-in required. |
| Uploaded files | Documents you upload, photos and avatars are stored in DigitalOcean Spaces object storage in the San Francisco region (sfo3). They are served back through the app after a sign-in check, never from a public link. |
| Continuous replica | The database is replicated continuously to that same DigitalOcean storage so we can recover from a server failure. The replica holds a rolling fourteen days. |
| Nightly offsite backup | An encrypted copy of the database is sent nightly to Amazon Web Services in the us-east-1 region. It is encrypted with a key whose private half is held offline, so the server cannot read its own backups. Each copy is write-locked for ninety days. |
Access
- Signing in is required to use the app
- Data is transmitted over an encrypted connection (HTTPS)
- Your data is the same on every device you sign in from
- You cannot read another member's data
- 100x coaches and administrators can read much of your work. Section 6 describes exactly what.
4. AI Processing
Every conversation in this app is processed by Anthropic's Claude. There is no AI setting to choose and no way to turn the AI off. Some steps offer a set of written questions instead of a chat; your answers to those questions are still sent to Claude so it can draft a statement from them. Requests are made from our server, so your browser never sees our API key.
What Travels With a Chat Message
- Your message, and the recent messages in that thread
- A running summary of the earlier part of a long conversation, which a separate Claude request wrote from those older messages
- A memory block about you, described in section 5
- The current draft of the statement you are working on, and the answers you gave on related steps
- Instructions about how the coach should respond
Other Features That Send Your Content to Anthropic
| Feature | What Is Sent |
|---|---|
| Drafting a statement | The conversation transcript and your current statement |
| Refining a draft | The draft text only, with no memory and no history |
| Nightly recap and notebook insights | What you wrote and changed that day |
| Cross-module insights | Your statements from across every module |
| Memory extraction, nightly | Your own messages. The coach's replies are not sent back. |
| Memory Sync | The memory text you pasted in from another AI |
| Reading an uploaded document | The file itself, in full |
| Coach session prep | Your memory block and your progress through the modules |
| The Foundation Assessment debrief | Your own scores, plus the names, scores and score differences of the peers who rated you |
Documents You Upload
When you upload a PDF or a photo of an assessment result, we send that file to Claude to read it. The file goes in whole, as an image or a PDF, up to eight megabytes. A CSV is parsed on our own server without AI. Your life story document and a Strengths Matrix are sent to Claude as text so it can distil them.
Search in Ask Lloyd and In-App Help
In the Ask Lloyd and in-app help conversations, the question you type is also sent to Voyage AI, which converts it into a numeric vector so we can find the relevant passages in our library. The vector is held in a short-lived cache for five minutes and is not stored. Your coaching conversations elsewhere in the app never reach Voyage.
What We Do Not Control
Anthropic's privacy policy and Voyage AI's privacy policy apply to the content they receive. We send no additional instruction with our requests about how long they may keep it or whether they may use it for training; whatever their terms provide is what applies.
5. What the AI Remembers About You
The app keeps a memory of you in eight layers, and that memory is included with the messages sent to Claude so conversations stay coherent across modules.
| Layer | What It Holds | Ageing |
|---|---|---|
| Identity | Your mission, who you want to become, your values and strengths | Does not age |
| Life context | Life stage, key relationships, capacity, health considerations you have mentioned, faith practices | Marked as dated after 90 days |
| Journey state | Where you are in the process, current experiments, recent wins and setbacks, open questions | Marked as dated after 30 days |
| Interaction history | Topics discussed, advice given, patterns, how you prefer to be spoken to | Marked as dated after 60 days |
| Commitments | What you have committed to, and milestones | Does not age |
| Assessments | Your CliftonStrengths themes and their descriptions, Strengths Matrix, Foundation Assessment scores, life story | Does not age |
| Session state | The mode and thread of the day | Reset every night |
| Parking lot patterns | Themes drawn from your conversations | Does not age |
Ageing is not deletion. An item past its window keeps its content and is marked as possibly out of date, so the coach treats it as old news rather than current fact. Session state is the only layer that is erased.
Where the Memory Comes From
- What you wrote in your Roadmap and in the guide steps
- A nightly pass over your own messages, which extracts commitments and themes
- Documents you uploaded
- Memory Sync, which shows you every extracted fact in a checklist so you can edit or discard each line before anything is saved
What Is and Is Not Put in Front of the Model
- The memory block sent with your conversations names your CliftonStrengths themes and includes their full descriptions.
- Foundation Assessment scores are deliberately kept out of that memory block. The one place they are used is the debrief step, where your own scores and your peers' scores are sent so the coach can talk you through them while you are looking at the same numbers.
- You can read the exact memory text the app holds about you at any time in Settings under AI Memory, and you can clear it.
6. Who at 100x Can See Your Data
100x Forum staff hold one of three roles: coach, player coach, or super administrator. Access to member records is not limited to the coach assigned to you. Any 100x coach or administrator can open any member's record.
What Staff Can See
- Your written statements from every module, in full
- Your assessment results, including your CliftonStrengths themes and your Foundation Assessment scores
- The documents you uploaded, which they can download
- Your peer raters' names, email addresses and scores, the difference between each peer's score and your own, and a spreadsheet of the same
- Your nightly recaps in full, and your notebook insights
- The titles and dates of your AI conversations
- Your progress through the journey, your activity over the past year, and when you were last active
- Your email address and the date you joined
- Whether you are married and whether you have children, which only super administrators see
What Staff Do Not See in That Panel
The text of your conversations with the AI coach, your parking lot items and your unsaved drafts are not shown in the staff panel.
Session Prep Briefings
Staff can generate an AI-written briefing about you before a coaching session. It is produced by sending your memory block and your module progress to Claude, so it draws on your Setting the Stage answers, any health considerations or key relationships you have mentioned, the names of people who come up in your conversations, and the themes extracted from those conversations. Each briefing is kept. You are not shown your own briefings.
Viewing the App as You
Coaches and administrators can open the app as you. In that mode they see the app exactly as you see it, including the text of your conversations and your full data export, and any change they make is saved to your account. A coach may do this for a member; only a super administrator may do it for another staff member. Each time it starts and stops, we write a line to our server logs recording who did it and to whose account.
Staff Auditing
We record specific administrative actions in an audit table with the staff member, the member affected and what was done: sending a nudge, uploading or entering a document for you, changing your role or cohort, and sending invitations. We also record which staff member last opened your record and when. Reading your record and generating a briefing are not written to that audit table.
7. Information About Other People
Peer Raters
The Foundation Assessment lets you ask up to four people to score you. For each one you give us their name, their email address and their relationship to you. We email them a private link. They do not have an account and do not sign in. They enter scores on the eleven life areas and nothing else; there is no comment box. If they have not responded we email them a reminder up to twice.
Their name, relationship and scores are shown to you, are shown to 100x staff, and are sent to Claude during your debrief step. We do not use their email address for anything other than sending the invitation and the reminders.
Family, Friends and Colleagues
Your relationship map and your family plan hold the names, relationships, photos and whatever notes you write about the people in your life, including your spouse and your children. That material is stored, is visible to 100x staff as part of your written work, and is included in what is sent to Claude when it is part of a statement or a memory layer.
8. Third-Party Services
These are the services that receive data, and what reaches each of them.
| Service | Purpose | Data Shared |
|---|---|---|
| Anthropic | The AI coach and every other AI feature | Your conversations, statements, memory block, uploaded documents and assessment scores, as described in section 4 |
| Voyage AI | Search inside Ask Lloyd and in-app help | The question you type in those two conversations |
| Google Sign-In | Verifying who you are | An identity check. Google returns your email, name, account identifier and photo URL to us. |
| Mailgun | Sending email | Recipient addresses and the contents of our emails: your sign-in links, invitations, and the peer rating invitations, which carry your name |
| Sentry | Error and performance monitoring | Error details, browser info, the page path and your numeric user id |
| DigitalOcean | Hosting, file storage and the continuous database replica | Everything in the app, as the infrastructure it runs on |
| Amazon Web Services | Nightly offsite backup | An encrypted copy of the database that Amazon cannot read |
| Vimeo | Playing the module videos | Standard player requests from your browser (IP address, browser info, which page), and Vimeo's own cookies |
| Google Fonts and jsDelivr | Loading fonts and a stylesheet | Standard HTTP requests from your browser (IP address, browser info) |
What Your Browser Loads From Elsewhere
Pages in this app load fonts from Google, a stylesheet from the jsDelivr network, the error monitoring script from Sentry, the sign-in widget from Google, video players from Vimeo, and your profile photo from Google's servers. Each of those requests tells that company your IP address, your browser details and which page you were on. This is true of the sign-in page and of this policy page as well, before you have signed in.
Error Tracking (Sentry)
- Technical error details (stack traces, browser info, the page path) are sent to Sentry
- Your numeric user id is attached so we can tell which errors affect the same person. Your email and name are removed.
- Before an event is sent we strip out fields whose names we recognise as personal or free-form, including email, names, message content, mission, reflections and notes, and we drop cookies entirely. The filter works by field name, so it is thorough rather than absolute.
- Demo accounts are excluded from browser error tracking entirely
9. Data Security
We implement the following security measures:
- API key protection: our Anthropic and Voyage keys are held on the server and are never exposed to browsers
- Access controls: requests are authenticated and scoped so you can only reach your own data
- HTTPS: all network communication is encrypted
- Server-side processing: AI requests are made from our server, never from your browser
- Uploaded files: served through the app after a sign-in check, never from a public link
- Backups: encrypted with a key the server does not hold, so a compromised server cannot read them
- Sign-in links: expire and are limited to five uses
10. Your Rights and Controls
Export Your Data
From the Export menu you can download an Excel workbook of your roadmap, a printable version for saving as a PDF, and a complete JSON file. The JSON covers twenty-seven kinds of record, including every conversation and every message, your memory layers, your assessments and peer ratings, your recaps and your photos. A test in our build fails if a new kind of record is added without being covered. Account identity fields such as your email, role and cohort are left out. You can import a JSON file back into your account.
See What the AI Knows
Settings has an AI Memory panel that shows you the exact memory text the app assembles about you, in the form it is sent to Claude.
Clear the AI's Memory
Clearing AI memory deletes all eight memory layers and stops the nightly extractor from rebuilding them out of your older conversations, so only what you say afterwards feeds memory again. Your conversation transcripts themselves remain.
Delete Your Data
- Delete all data: this erases your content across every module, your memory layers, your conversations and messages, your assessments and uploads, your recaps, your insights and your navigation records. Your account and sign-in remain, along with your cohort, the AI token counts described in section 2, and the staff audit records described in section 6.
- Your account: there is no self-serve account deletion. Contact us at the address below and we will delete your account and its data.
11. Retention
We keep what you write until you delete it. Nothing you enter is deleted automatically, and that includes your conversations, your sign-in sessions and the record of pages you have visited. Memory layers age as described in section 5, which marks them as old rather than removing them.
Deleting data from the app does not immediately remove it from backups. The continuous replica holds a rolling fourteen days. The nightly encrypted copies at Amazon are write-locked for ninety days and cannot be altered or removed inside that window, by us or by anyone else. So content you delete can persist in backups for up to ninety days before it ages out.
12. Children's Privacy
100x Roadmap is designed for adults engaged in life planning and is not intended for children under 18. We do not knowingly create accounts for children.
Two features touch on people who may be minors. Your family plan and relationship map hold names and notes about your children, written by you. The Foundation Assessment lets you invite someone you identify as your child to score you, which sends them an email with a rating link. In both cases you are choosing what to write and whom to invite.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of significant changes by updating the "Last Updated" date below. Continued use of the app constitutes acceptance of the updated policy.
14. Contact Us
If you have questions about this Privacy Policy or want to exercise your data rights, please contact us at:
Email: privacy@100xforum.com
Organization: 100x Forum
Last Updated: August 15, 2026