
Legal Center
Privacy Policy
Last updated September 29, 2026· v1.1
1. Who this covers
Anyone who visits espritdcf.org or holds an account on any Foundation portal (Team Portal, Ranks, Volunteer Portal).
2. What we collect
- Account data: name, email, phone, mailing address, headshot, role, and permission scope.
- Community data: military affiliation (self-reported), city/state, connections, groups, chapter, posts, messages you send.
- Program data: event RSVPs, volunteer hours, program applications, submissions.
- Payment data: donation history + billing details (handled by our processors; card numbers never touch our servers).
- Usage data: page views, feature interactions, IP (hashed), device fingerprint, session state.
3. What we do with it
- Operate the Foundation’s programs, portals, community, and events.
- Contact you about the Foundation and your involvement.
- Steward donors and comply with IRS 501(c)(3) recordkeeping.
- Comply with Illinois Attorney General Charitable Trust reporting.
- Audit for safety and security.
- Improve internal operations and measure mission impact.
4. What we never do
- Sell your personal information.
- Share your data with cross-context behavioral advertising networks.
- Broker or rent contact lists.
5. Product analytics, telemetry, and AI monitoring
To keep Foundation surfaces reliable, improve programs, and understand how the community uses what we build, we measure how the platform is used. When you use a Foundation surface, you consent to the following collection and processing:
- Feature usage and engagement.Which pages, actions, buttons, tools, programs, resources, and search terms are used, and in what sequence. Used in aggregate to understand what’s working and what to invest in next.
- Errors, crashes, and defects. Automated diagnostic data (browser, device, viewport, stack traces, request IDs, timing) captured when a page or feature fails so we can reproduce and fix it.
- Performance telemetry. Load times, render times, and network reliability signals used to keep the platform responsive.
- AI usage. The prompts you send to EDC AI or Magic Pencil, the model response, tools invoked, and error signals. Used to keep the AI safe, prevent abuse, improve the product, and satisfy the safety rules in the AI Policy. AI logs are never used to build a personality profile of you and are not sold or shared with advertisers.
- Safety and moderation signals. Reports, flags, and automated safety-scan hits (e.g., profanity, sensitive-info detection). Used to enforce the Community Guidelines and Acceptable Use Policy.
- User-submitted bug reports.When you use the “Report a bug” affordance inside a portal, the report includes the current page URL, an anonymized browser/device summary, any client-side error code, and your description. A page screenshot is only attached if you explicitly grant consent on that dialog. Screenshots are treated as sensitive support artifacts, restricted to admins working the ticket, and deleted per the Data Retention Policy.
Wherever practical this data is used in aggregate(measuring behavior across users, not you as an individual). Some categories — account-holder actions, moderation events, AI conversations tied to your account — are recorded against your account to operate the service safely.
Third-party processors that support telemetry: our hosting provider, error-reporting service (Sentry), and the AI provider we route requests through. Each of these providers processes data under its own terms and is bound by contract not to sell it.
6. Your controls (opt-outs)
You control the following through your account settings (Team Portal, Ranks, or Volunteer). Opting out of analytics does not disable transactional communications (receipts, safety notices, legal notices) or safety enforcement.
- Product analytics. Opt out of non-essential feature-usage tracking.
- Performance telemetry. Opt out of non-essential performance sampling.
- AI history. Delete individual AI conversations, or opt out of persistent AI history entirely (each conversation is then discarded after the session).
- Marketing emails. Unsubscribe from any marketing email via the link in the message or by emailing privacy@espritdcf.org.
- Directory + community visibility. Per-field privacy controls in your profile determine who sees what.
Some data is essential to operating the service and cannot be opted out of while you use it: authentication + session state, security + fraud signals, moderation records, donation records, and records required by law. To remove essential data, close your account per the Data Retention Policy.
7. Portal-specific handling
Portal-specific data-handling rules are folded into these Terms and the Acceptable Use Policy. Team Portal notebooks and chat, Ranks posts, and Volunteer forms each have their own retention and moderation treatment described in those documents.
8. Retention
See the Data Retention & Records Policy.
9. Your rights
See the Regional page for state and international-specific rights (Illinois PIPA, California CCPA/CPRA, EEA/UK GDPR).
10. Contact
Privacy questions: use the Contact page or email privacy@espritdcf.org.