Privacy and security

Your report stays yours.

This page is the same one page note we give IT security teams, data protection officers and works councils.

Download the note to forward it

For IT security, data protection officers and works councils. One page. Plain language. Community tool by Incubane, a Workday partner.

In one sentence

The kit runs in your browser and saves your work there. You sign in with a free Incubane account first. The kit asks once per device whether to sync between your devices. With a yes, your plan, notes, people, photos and reports are encrypted on the device, with a key only your devices hold, before a copy goes to Incubane's EU storage. You can turn sync off ("Keep everything on this device") at any time. With Incubane AI (the default), your photos and notes pass through incubane.com to Claude by Anthropic to be read, and Incubane stores none of that content. With your own AI tool and sync off, no content reaches Incubane: it goes only to the AI tool you paste it into, the one your company already approved. With your own AI tool and sync on, Incubane stores only the encrypted copy.

Two modes

Incubane AI (default)Your own AI tool
Who reads the slidesClaude, by Anthropic, through incubane.comThe AI tool you choose, for example Microsoft 365 Copilot
AccountThe free Incubane account (email, name, company, area, level)The same free account. It only signs you in.
What passes through IncubaneRedrawn photos (no location or device details), notes, focus questions, tenant details and the people you wrote down without the names you typed (a name printed on a photographed slide or badge is in the photo), in transit onlyNo content for the AI.
What Incubane storesOne usage line per request: account, time, kind, photo count, tokens, cost. Kept 13 months. No content. With sync on, the encrypted copy.With sync off: nothing. With sync on: the encrypted copy only.
Where your work is savedYour browser, and with sync on an encrypted copy for your other devicesYour browser, and with sync on an encrypted copy for your other devices

If your company only allows its own AI tool, pick that tool in the Studio and turn sync off on the home page ("Keep everything on this device"). Everything below marked "own AI" then applies. To block the service at the network level, block /api/rising/ai, /api/rising/sync*, /api/rising/team and /api/rising/handoff; the kit keeps working on the device.

GDPR at a glance

QuestionAnswer
Who is the controller?Own AI: your organisation; the content stays on your device and in your AI tool. Incubane AI: Incubane BV for the service and the account; a DPA with Incubane is available on request (privacy@incubane.com).
Does Incubane process the content?Own AI with sync off: no. Incubane AI: yes, in transit only, to send it to Anthropic and return the answer; it is not stored. With sync on (either mode): Incubane stores the encrypted copy and does not get the key.
Who else is involved?Incubane AI: Vercel (hosts the route), Supabase (sign-in and usage rows), Anthropic (the model; processor under the Anthropic DPA with EU Standard Contractual Clauses, may process in the US, no training on the content), Cloudflare Turnstile (bot check on the sign-in step, loaded only there). If the model declines a request, the same request can be answered once by another Claude model of Anthropic, under the same terms. Team mode: Resend sends the invite emails (team name, the lead's first name and a join link). Both modes: Plausible (EU hosted) counts events; team spaces use Supabase in Frankfurt and store encrypted data only.
Where is data stored?Photos, notes and reports: in your browser (IndexedDB), and an encrypted copy in Supabase (EU, Ireland) so your devices stay in sync. Incubane does not get the key to that copy; this relies on the code incubane.com serves, so a changed deploy could change that. Delete either at any time on this page; deleting the synced copy stops every device from syncing until you turn sync on again yourself. Everything synced is deleted on 15 January 2027. Account and usage log: Supabase (the account in both modes).
PeopleSession data has no speaker or attendee fields. Conferences are about networking, so your own content can hold people: who you met, badges you photograph (quick capture reads the name, company and role; the photo is not kept), and who presented, read from your title slides. They go into your own report, with a LinkedIn link where the badge QR code has one. With Incubane AI, the people you wrote down go through incubane.com to Claude by Anthropic when you write the report, without their names (D93): the AI sees company, role and what you wrote, and the kit puts the name back next to its line. They are not stored. With your own AI, they go only into your own AI chat. Never add email addresses or phone numbers.
Help with one piece (D77)Signed in with Incubane AI, "Improve with AI", "Suggest a done-when" and "Split into tasks" send only that one text or action, plus the report's headline, your focus items and your Workday modules, through incubane.com to Claude by Anthropic. Not the report, not your notes, not people. Nothing is stored, only a usage row.
Ask the agent in the deck editor (D95)The same route, with one slide: its words and the request you type, plus the same small context. The edited deck itself is stored only with your report, on your device (and in sync or a team space, encrypted, if you use them).
Propose the big projects on the roadmapThe same route, with your big bets for next year, the products you consider and your plans for them after Rising, the report's theme names and up to 40 action titles with their lane. Not your notes, not people. The agreed projects and blocks are stored only with your report, on your device (and in sync or a team space, encrypted, if you use them). Without Incubane AI the kit makes the proposal itself and nothing is sent.
Email when the report is readyOptional, while Incubane AI works. One short email to your own sign-in address: "your report is ready" and a link. Nothing from your report is in it. We keep only a salted hash of your account with the time, to limit how many we send.
Your Workday setup and questions, for follow-up (D93, D102)The kit keeps Incubane up to date with the Workday products you run and consider, when you expect to decide, your take on them after Rising, and what you came to Rising for, with your company domain and the notice version you saw. Legitimate interest: the notice is at the account step, and the privacy page has the opt-out. Used to send relevant ideas and offers and to count interest in totals. Company level only: no photos, notes, report or people. Kept 18 months after your last change. Never sold, never shared with Workday without asking you separately. Opt out: the data is deleted at once, and a marker keeps it from being kept again. Report content reaches Incubane only when you press "Request a debrief" in the Brief, with the summary you see and can edit.
Emails around Rising (D113)At most five short emails to the address of your account: the morning of the first full day, the end of each main day for the daily recap, and when Post Rising opens. Sent through Resend from incubane.com; no tracking pixels, no content from your kit. Everyone who uses the kit signed in is on the list; a one click link in every email or the switch on the privacy page turns them off, and a no stays a no. The list and the send log hold your account id, email address, first name and which mail went when; both go with your account and on 15 January 2027.
Your account (D93)On this page: download a copy of everything Incubane holds about you, or delete your account. Deleting removes the sign-in, the library profile, the newsletter subscription, synced data, team data, shared Workday plans and usage lines. Team invites nobody accepted are deleted after 30 days.
DPIAOwn AI: assess the processing in your AI tool. Incubane AI: our record of processing and assessment are available on request.

Please do not upload

Screenshots of a Workday tenant, employee data or anything confidential from your employer. The kit is for conference slides and your own notes.

What the kit is

A web app at incubane.com/rising. The core runs in the browser. Hosting: Vercel. Incubane AI adds one server route (/api/rising/ai) that checks the sign-in and the limits, calls the Anthropic API and streams the answer back. Team spaces use Supabase in the EU (Frankfurt) and store encrypted data only.

Data flow

DataWhere it goesWho can read it
Slide photosStay on your device. Resized copies are made in the browser. Incubane AI: sent in batches of up to 12 to incubane.com and on to Anthropic, not stored. Own AI: you attach them in your AI tool.You; Anthropic while processing (Incubane AI); your AI tool (own AI)
Notes, focus items, tenant context, people you metStay on your device (IndexedDB). They are part of the prompt, sent as above.As above
Your answers to the questions before the report (Incubane AI only)Saved with your Studio work on your device and synced encrypted. Sent with the report request, as above, not stored. Please name roles, not colleagues, and no employee data.You; Anthropic while processing
The AI replyChecked in the browser, then saved there.You
The reportStays on your device, or in files you export.You, and anyone you send a file to
Sync between your devicesEncrypted on the device with AES-GCM 256 before it leaves, with a key made on your first device. The key reaches another device only when you link it: the new device shows a 6 digit code, you confirm the same code on a device you already use, and that device hands over the key encrypted for the new one (ECDH P-256). Incubane stores ciphertext, sizes, version numbers and a hash of the key.You, on your linked devices
Team space (optional)Encrypted in the browser with AES-GCM 256 before it leaves. The server stores ciphertext only. The key is in the link fragment (#k=...), which browsers never send to servers.People with the link
AnalyticsCounts of the events listed below, and page views by route with ids removed (/report/r/:id). No content, file names, session choices or free text.Incubane

What Incubane receives

With your own AI tool, your account and the anonymous event counts below, through Plausible (EU hosted, no cookies). With Incubane AI, also the usage line described above. Each event has at most one property, and its value is a fixed word or a range, never your input.

EventProperty
Kit: Studio startedattendance: in-person or virtual
Kit: Plan skippedaudience: in-person or virtual
Kit: Photos sortedphotos: 1-49, 50-199, 200-499, 500+
Kit: Package createdtool: incubane, copilot, chatgpt, claude, other; path: full or fast
Kit: Hosted runstep: photos, report, plan or questions; result: ok, failed or limit
Kit: Reply importedresult: ok, fixed, failed
Kit: Report generatedlens: the report view picked (action, config, technical, learning, deep-dive, leadership)
Kit: Exportformat: pdf, png, pptx, xlsx, jira, ado, planner, csv, json, html, zip
Kit: Team space creatednone
Kit: Capture usednone
Kit: Contact capturednone
Kit: Skills kit downloadednone
Kit: Booking clickedoffer: landing, debrief, review, plan, innovation, security-plus, 360-feedback, education, ai-goals
Kit: LinkedIn sharemoment: before, during, after; step: opened, posted (never the post text)
Kit: Audience chosenaudience: in-person, online, emea, learn, us-2025, emea-us
Kit: EMEA choicechoice: now, wait (Rising US report now, or wait for Rising EMEA)
Kit: Sign in sentnone
Kit: Account creatednone
Kit: Signed innone

The list is enforced in code (packages/core/src/analytics/events.ts); an event or value that is not on it is dropped. Page views send the route only, with report and team ids replaced by :id.

Browser security

  • Content Security Policy: scripts only from the kit itself, the analytics script and Cloudflare Turnstile. The policy is one header for every kit path, so it allows Turnstile everywhere; the code loads it on the sign-in step only. No other third-party scripts, fonts or CDNs. frame-ancestors 'none', object-src 'none'.
  • Referrer-Policy: no-referrer, so a team link never leaks in a referrer header.
  • Permissions-Policy: camera, microphone, location and payment are off.
  • HSTS, X-Content-Type-Options: nosniff.
  • The prompts and data schemas are published under the MIT license, so anyone can check what the AI is asked to do.

Sync details

  • Stored in Incubane's Supabase project in the EU (eu-west-1, Ireland): one row per item and one file per photo, all ciphertext. Only the site's sync routes can reach it; they check your sign-in and never see the key.
  • What syncs: your plan and Studio work, quick capture notes, voice notes and their audio, people you met and daily recaps, photos and thumbnails, reports and team links. The names in "Who covers what" on the plan stay on the device.
  • If two devices changed the same thing, lists are joined (notes, people, photos) and the device that syncs last keeps its own value for single fields.
  • The QR code on the home page is a one-time pass, made only when you tap "Show the QR code". It works once, for 2 minutes, and signs the phone in as you and links it, so only show it on your own screen. Your sync key travels sealed with a secret that is only in the QR code (after the #, which browsers never send to a server); incubane.com stores the sealed key and a hash of the pass, hands the sealed key to the phone once, then deletes it. Used or expired passes get nothing. At most 10 passes an hour; all are deleted after a day.
  • Lost every linked device: no device holds the key any more, so the synced copy is useless. Start over from a new device; the old copy is deleted.
  • Sync off ("Keep everything on this device", on the home page): this device sends nothing and keeps its data; what is already synced stays until you delete it.
  • "Delete your synced data" on this page deletes every synced item and photo (in rounds for a large library; the nightly cleanup finishes anything left) and leaves a marker. Every device that sees the marker forgets its key and stops; sync only starts again when the person turns it on themselves.
  • The 6 digit link code checks that the right device asks; it is not a proof against a dishonest server. The keys stay with your devices only as long as the code incubane.com serves does what is described here.
  • Limits: 900 MB and 5,000 items per person. Deleted after 15 January 2027, or at once with "Delete your synced data" on this page.

Team mode details

  • For people who went to Rising together. One lead invites colleagues by email. Opening the invite does not join: the colleague first sees what goes to the lead, then chooses "Join and share" or "Not now". Once joined, their part (their role, plan, sessions, notes with their times and slide findings) goes to the lead's kit on its own, and the lead writes one team report. The people they met go only if they tick "Also share the people I met"; badge photos count as people met. A member can change that, pause sharing (which removes what they shared from the team) or leave at any time. In works council terms: nothing flows without the member's own choice, and it can be stopped.
  • What Incubane stores: the team name, the email addresses invited, who joined and when, and ciphertext. It sends the invite emails through Resend (see docs/legal/dpa-tracker.md); the email holds the team name, the lead's first name (or their email address when no first name is registered) and a join link, no content and no key.
  • Keys: every account has a key pair; its private half is encrypted with the person's own sync key. The team key is made on the lead's device and reaches a member only wrapped for that member's public key (ECDH P-256, AES-GCM 256). Incubane never holds a key that opens a pack or the report.
  • The finished report is shared as a team space (below); the link to it is sealed with the team key, so only team members can open it.
  • Hosted with the sync data in the EU (eu-west-1). A lead can remove a member (what they sent goes too); a member can leave. Everything is deleted on 15 January 2027, or at once with "Delete your synced data", which also deletes the teams you lead. The team report itself lives in a team space (below), which has its own deletion.
  • Limits: 25 people per team, 60 invites a day per lead (counted in a log that deleting a team does not reset), 5 new teams a day. Invites go to work addresses only. The email subject has no free text; the body holds the team name, the lead's first name (or their email address when no first name is registered) and a link.

Team space details

  • Hosted on Supabase in Frankfurt (eu-central-1), in Incubane's own project. No accounts.
  • The report is encrypted in the browser with AES-GCM 256 before it leaves. The server stores one ciphertext per space, a random IV, a version number and dates. It cannot read the report.
  • The key is in the link fragment (#k=...). Browsers never send the fragment to a server. After a link opens, the kit removes the key from the address bar.
  • Two kinds of link. An edit link also carries a random write token (&w=...); the server keeps only its SHA-256 hash. A view link has no token, so it can read but never save.
  • Saves carry a version number. If a teammate saved first, the kit merges their comments and votes before it writes, so nothing is silently overwritten.
  • In "roles" mode, team members' names are replaced by their roles before encryption, like a review file. The people the team met (contacts) and presenters stay in the report; leave them out before sharing if they should not be in the space.
  • Deleted 90 days after the last save, so a team that keeps saving keeps its space longer than the 15 January 2027 sync cleanup. "Delete your synced data" does not delete it; anyone with the edit link can delete the space at once.
  • No direct table access: the public key can only call four functions (create, read, save, delete). A global cap stops a script from filling the database.
  • Supabase keeps standard platform logs (for example IP addresses and request times) for a limited period. Request bodies are ciphertext.
  • Limit: anyone who has the link can read the space. Share it like you would share a document link.

People and works councils

  • Session data has no speaker or attendee fields. When reading slide photos, the AI lists presenters from title slides and people on conference badges, as printed, and never copies email addresses or phone numbers or describes faces.
  • Quick capture has a People tab for conversations, braindates and booth visits. The user types in a name, company and role if they want to, and what was discussed. This is saved on their device and goes into their team's pack files and their outputs (the field guide and the action plan, not the leadership email). With Incubane AI, the people you wrote down go through incubane.com to Claude by Anthropic when you write the report. They are not stored. With your own AI, they go only into your own AI chat. The team space stores it encrypted. Users are asked to write down only what the other person is happy to share.
  • Owners the AI writes are roles ("HRIS lead"). In Act the team can pick a person from the team as owner; that is their own content, saved and synced like the rest, and shown by role in roles mode.
  • Teams can switch to "roles only", so votes and comments show a role instead of a name, and can switch off the activity feed.

What we ask you to check

  • That your company allows the AI tool you pick for slide photos from a conference.
  • That forward-looking slides may be used internally. The kit flags them.

Delete everything on this device

Removes every report, the Studio work and all photos the kit stored in this browser. Files you downloaded are not touched. Synced copies stay until you delete them below.