- Status
- Published
- Version
- 1.0
- Effective
- 4 August 2026
- Last reviewed
- 4 August 2026
- Review cycle
- Annually
- Last updated
- 4 August 2026
Purpose
To set out how information created by signed-in members — including journals, reflections and saved records — is stored, protected, shared and deleted.
Scope
All member accounts on Foundation-operated platforms, and the member workspace features operated with our partner platform Funeora.
Responsibilities
Platform administrators are responsible for technical protection. Members are responsible for what they choose to share.
Private by default
- Journal entries, reflections and personal records are private to the member who created them.
- Row-level security is enforced on every table holding member content, so records are only readable by their owner.
- Foundation staff do not browse member journals, and journal content is never used in public reporting, marketing or impact material.
- Member content is not made available to artificial-intelligence services by default.
When something is shared
Nothing is shared unless the member deliberately shares it. When a member chooses to share an entry or request human support, they select exactly what is included, and that choice is recorded.
- Sharing is per entry, not account-wide.
- Sharing can be withdrawn, after which access ends.
- Support requests are seen only by the people responsible for responding.
Safeguarding limits
There is one limit to confidentiality. Where there is a serious and immediate risk to the life or safety of a member or another person, or where the law requires disclosure, the minimum necessary information may be shared with an appropriate professional, protection service or emergency service. This is a protective step, not a routine review.
Adults only
Member journal features are for adults. Accounts are not offered to children, and any account identified as belonging to a minor is closed and its content removed.
Deletion
A member may delete an entry at any time, or close their account and have their content removed. Deleted entries are removed from live systems immediately and clear from backups on the normal backup-expiry cycle. Requests can be sent to info@eflegacy.org.
Questions about this policy? Email info@eflegacy.org and a member of our team will respond within five working days.