Data handling

Privacy and security

Your answers never leave your browser. Nothing you type, including statuses, notes, owners or next actions, is transmitted to Ceiba or stored on a server.

We count which screens are reached, approximate engaged time, return visits and exports so we can improve the review. The counter does not include anything you type.

What stays in your browser

Your selected pathways, answers, notes, owners, next actions and 90-day test remain inside the browser tab. Nothing is retained after a reload unless you choose to save it on your device.

What happens if you do not save

Your answers disappear when you close or reload the page unless you turn on "Save on this device." The browser still remembers a random identifier and the time of the previous visit so return visits can be counted. It also keeps tab-level markers to avoid counting the same screen twice. None contains assessment answers.

Invitation access

The server checks the code against a protected version of each active invitation code. It does not keep the code you type or add failed attempts to the product analytics table.

After a valid code, the application sets one strictly necessary, signed access cookie. It contains an invitation identifier and expiration time, not your name, email address or assessment answers. It lasts for up to 30 days and may end sooner if the invitation expires or is revoked. Usage is associated with the organization that received the invitation, not a named person.

What Ceiba counts

The tool records starting and returning to the review, screens and decisions reached, approximate engaged time in 30-second intervals, reaching the action plan, export actions and an optional Yes, Partly or No usefulness response.

It never records which status you choose, your selected pathway, organization or person names, URLs, notes, owners, next actions, colleague roles or 90-day test text. It does not use browser fingerprinting, advertising identifiers or third-party analytics.

Each event contains the event name, the organization invitation, pseudonymous browser and visit identifiers, and only the fields needed for that event, such as a screen, numeric position, engaged seconds or usefulness response. Random browser and visit identifiers are protected with a one-way server-side fingerprint before storage. The application does not copy an IP address or user agent into the analytics table. Detailed events are kept for a rolling 90 days.

What the website host may receive

Loading any website creates an ordinary request to its host. The hosting provider may process access and security data such as an IP address, timestamp, requested page, response status and browser or device information. Those logs do not contain assessment answers.

Outputs and files

You can read the action plan on screen, copy it as plain text or print it. The optional CSV is generated in your browser only after you request it. It is not uploaded to Ceiba.

Technical controls

  • No account, email address or named user profile is required.
  • One strictly necessary access cookie is used.
  • No advertising cookies, tags or tracking pixels are used.
  • No form submits assessment answers to Ceiba.

Security or source review

An organization's security team can request the current source code, a data-flow note or a self-hosting copy through Ceiba Partners.

Request a security review

This page describes the application's design. It is not a legal privacy notice or a certification.