Every piece of information this protocol touches, and exactly who can see it. There are three places it can go. They do not overlap.
The protocol asks you to write things down. None of what you write ever reaches us. Not because we promise not to look. Because there is no route by which it could arrive.
This is a structural claim, not a policy one. A policy can be changed by whoever wrote it. Structure cannot. Below is the structure.
The route mapThree places. No overlap.
Everything the protocol touches sits in exactly one of these three places. What you write stays in the first one and has no route out of it. The only thing that ever reaches the third one is a number describing the whole group.
One
Your device
Yours alone. PRC has never held any of it and has no mechanism to.
The pattern, as you first described it
Your if/then
What the pattern was costing you
Every worksheet answer
Your log, and the file you save from it
Your note file, which is built in your browser and never sent
Your 90-day record, assembled on your own machine on Day 91
Not stored by PRC. Not transmitted. Not recoverable by anyone but you.
Two
The PRC system
Held by PRC so the protocol can run. Your employer never sees any of it.
Your email address, because that is how the emails reach you
A random seat token, which is not derived from anything about you
The date you started
Your PRC Index scores at Days 1, 30, 60 and 90
Your thirteen weekly numbers, filed against the token and not your name
Which cohort you belong to
Numbers you chose yourself. No words. No name.
Three
Your employer
What the organisation that bought the licence actually receives.
How many seats are occupied
What percentage of the group completed
The group's average PRC Index at each checkpoint
How that average moved across ninety days
The same, broken down by the seven measures
A description of a group. Never a description of a person.
The barrier
One gate, and only numbers fit through it
What PRC holds and what your employer receives are not the same system reading different views. They are separated in code. An employer's access key resolves to exactly one cohort and returns exactly one shape of answer. There is no parameter they can change, no permission they can be granted, and no report they can request that would return an individual.
Held by PRC
Email address
Seat token
Individual scores
Individual weekly numbers
Start date
The gate
Reaches the employer
Seats occupied
Completion rate
Cohort average
Cohort movement
Nothing else
And a floor. Below five completed seats, even the average is withheld. An average of two people is two people's scores wearing a disguise. The system refuses to return it.
Never
What your employer cannot receive
Not "will not". Cannot. There is no endpoint, no export and no escalation path that produces any of the following.
Your name
Your email address
Your seat token
Any score you entered
Any weekly number you entered
Any word you wrote
Whether you personally completed
Whether you personally enrolled
Whether you opened an email
Any list of who is taking part
The protocol exists for the people who will not raise their hand. Those people are right to be careful. An assurance is only worth what the architecture behind it will bear.
So we did not write you an assurance. We built it so that the thing you are afraid of has nowhere to travel.
Internal reference. Not for circulation. Does not print.
Where each item physically lives
Item
Store
Keyed on
Email address, seat token, start date
Kit subscriber record
Email address
PRC Index, 7 measures × 4 checkpoints
Kit custom fields, 28 in total
Email address
Thirteen weekly numbers
D1 weekly_scores
seat_token, not email
Cohort membership
Kit tag cohort:<name>
Email address
Employer licence and access key
D1 clients
hr_access_key
Sequence email archive
D1 emails, 74 rows
Not personal
Everything the participant writes
Their device only
Never transmitted
How the employer surface is enforced
/api/hr
Key resolves to exactly one cohort_tag in clients. No parameter can override it.
MIN_COHORT_SIZE = 5
Below five seats the aggregate is withheld and the endpoint says so.
/api/worksheet
Returns 410. The free-text write path into Kit is closed.
/api/note-sheet
Generated in the response. Never stored, here or in Kit.
Day 91 merge
FileReader in the browser. No network call. Works offline.
Known gap, do not paper over it. There is no retention period on this document because none is currently enforced. The Day 180 deletion job is written but not deployed. Do not add a retention claim to this page until it is live.
Second gap. PRC holds the email address alongside the scores, so PRC can join a named person to their numbers. The employer cannot. This page says exactly that and must continue to. Never claim the participant is anonymous to PRC.