Privacy and deployment boundaries
Technical information for this project site and independently operated Masterplan instances.
This information site
The published site source does not configure advertising, behavioural analytics or cross-site tracking. It stores a theme preference in localStorage. The site operator, hosting platform and network providers may still process request metadata such as IP addresses, timestamps and user-agent values according to their actual configuration and retention settings.
Self-hosted Masterplan instances
Each deployment is operated by its own controller. That controller selects purposes, providers, countries, retention periods and optional features, and publishes the notice that applies to its participants. This project page is not a substitute for an instance notice. Use the privacy link on the instance you access.
Supported browser storage
The supported release uses strictly necessary session and CSRF cookies, localStorage preferences, a versioned static application-shell cache and temporary tab state. Authenticated API responses are not cached. A participant can optionally enable a bounded offline schedule in IndexedDB. Expiry, logout and revocation trigger cleanup only in application-controlled stores; browser profile synchronisation and any browser or device backup remain outside application control. The exact configured names, lifetimes and enabled features belong in the applicable instance notice.
Providers and transfers
Email, Web Push, hosting, support, backup and high-availability paths depend on deployment configuration. The controller must identify enabled providers, their roles, countries, support access, agreements and transfer assessment. The software does not infer those external facts.
Retention, deletion and evidence
Masterplan supplies retention, purge, account-deletion and signed evidence workflows. Their records describe controlled actions and detected outcomes. They do not establish that every external or physical copy has been removed; controllers must reconcile providers, exports, backups and other copies separately.
Review the applicable record
Operators should follow the governance publication workflow. Engineers and reviewers can inspect the technical data model. Questions about participant data belong to the controller named by the relevant instance.