Working private-beta draft · Updated August 10, 2026
Information we handle
Republic Commons processes information you provide when requesting an invitation, creating or managing an account, building a Commoner profile, operating an Organization, sending a Dispatch, taking training or surveys, receiving recognition, using a Tool, or contacting support. Depending on what you use, this can include identity and contact details, profile content, Organization records, course and survey activity, Certifications, Endorsements, protected files, service settings, and payment status.
An invitation request stores your name, email, selected audience and interests, optional Organization and location details, source information supplied by the browser or campaign link, submission time, consent record, and limited security metadata. An invitation request does not create an account.
Public, protected, and private information
Public profiles and Organization sites begin as private drafts and become public only through an explicit publication command. A Commoner independently chooses which eligible Certifications and Endorsements appear on their public profile. Access codes and search-indexing preferences provide additional controls, although Republic Commons cannot guarantee that every external crawler will obey a request not to index a page.
Protected resources, private Publications, Commons Files, draft content, claim links, account records, and authenticated workspaces are not intended for the open web. Authorization is checked when those resources are requested; private storage paths are not published as direct links.
Public traffic measurement
Public marketing pages send a basic page event so we can understand traffic and conversion flow. This marketing measurement does not assign or read the persistent Republic Commons visitor identifier and does not run browser-fingerprint measurement.
Ordinary server security logs, abuse controls, invitation rate limits, and signed-in security auditing remain separate from marketing measurement.
Security and abuse prevention
Security logging is separate from marketing traffic measurement. We may process request time, route, account identifiers, network address, user agent, authentication events, rate-limit events, and related technical details to prevent abuse, investigate attacks, preserve audit trails, and keep access-controlled material protected. Uploaded files are screened through a fail-closed malware process, and supported images and PDFs receive additional structural validation or safe re-encoding.
Payments
Where Organization payment features are enabled, Stripe-hosted interfaces handle business verification, bank, and payment-card information. Republic Commons stores operational identifiers, amounts, statuses, reconciliation records, and audit events needed to provide the service. It does not store full card or bank-account credentials.
Retention, access, and choices
Retention varies with the record and its purpose. Short-lived Dispatch communications expire according to their displayed lifecycle. Financial, security, recognition, consent, and Organization audit records may be retained longer to preserve provenance, prevent duplicate actions, resolve disputes, or comply with legal obligations. Withdrawing a Publication or certification can remove public and recipient access while preserving an accountable lifecycle record.
You may update many account and publication choices directly inside Republic Commons. During private beta, requests about access, correction, deletion, or privacy can be sent to help.desk@republiccommons.com. We may need to verify identity and may preserve records that must remain for security, fraud prevention, legal obligations, or the rights of others.
Children and national availability
Republic Commons is intended for adults and civic Organizations, not children under 13. Product availability and privacy rights can vary by location. Before national general availability, this notice will be reviewed and expanded to address applicable state and federal requirements.