Effective 22 July 2026
Privacy, in plain English.
security.xyz collects only what it needs to run verified community conversations, deliver intelligence and provide the experiences you request.
What we collect
When you connect LinkedIn, LinkedIn provides the approved identity data used by the experience, such as your name, profile photo and optional email address. Standard LinkedIn sign-in does not reliably provide employer or job-title data. If you choose to add a private member profile, we collect the company, position, function, seniority, industry, company size, location and interests you confirm. Public posts, replies and votes use a separate stable pseudonymous profile ID and generated handle. Other members do not receive your LinkedIn identity, email or private profile.
Account and community login clearly includes the daily brief before you continue to LinkedIn. We record that action as newsletter consent, use the email LinkedIn returns for delivery and include an unsubscribe link in every edition. Event-ticket imports and other LinkedIn connections do not subscribe you unless the interface says they include the brief.
When you use an event agent, we record pseudonymous operational events such as the time, question length and one-way question fingerprint, request category, source records returned, safety outcome and response time. The activity log does not contain the text of your question or your raw IP address. Questions that require AI reasoning are sent to our AI provider for processing.
If you save an agent shortlist, we store the email address you provide and the public source records attached to that session. This does not subscribe you to a newsletter unless you separately select that option.
How we use it
- Confirm that community participants have connected a real LinkedIn account while keeping their public activity pseudonymous.
- Operate, moderate and protect community discussions.
- Rank community and intelligence recommendations using the profile signals you choose to provide.
- Deliver and personalise Today's Brief and weekly summaries when separately requested.
- Create event plans and other requested experiences.
You can disable recommendation personalisation or edit the profile at any time. Authorised administrators can access the private identity record for account support, trust and safety, product analytics and separately consented communications. That means the system is privacy-preserving and pseudonymous, but it is not literal zero knowledge. We do not sell member data or permit vendor outreach without explicit member permission.
Your control
You can view, correct and disable use of your private recommendation profile from the profile page. Every email includes an unsubscribe link. You can ask to see or delete the information held about you by contacting us. Event-pass visibility and introduction permissions can be changed independently of newsletter preferences.
Security and retention
The public community store does not contain email addresses or LinkedIn identifiers. The mapping between a verified identity and a public pseudonym remains in the private identity layer. We use access controls and encrypted connections in production, and production identity access should be purpose-bound and audited. We retain information while your membership is active or while it is needed for the purpose you requested, then remove or anonymise it where practical.
Contact
For privacy requests or questions, email hello@security.xyz.