Trilemma Foundation Privacy Policy

Effective Date: 7 September 2026

Last Updated: 7 September 2026

1. Who we are

1.1 Trilemma Tournament Foundation is a Canadian federal not-for-profit corporation (corporation number 1639419-1). It operates publicly as Trilemma Foundation and is referred to in this Policy as Trilemma or we.

1.2 Privacy contact: matt@trilemma.foundation. This is the address for access, correction, deletion, restriction, portability, objection, consent withdrawal, and complaints.

1.3 This Policy covers the public websites www.trilemma.foundation, trilemma.foundation, data.trilemma.foundation, build.trilemma.foundation, 2026.trilemma.foundation. The complete legal corpus is published only at https://www.trilemma.foundation on https://www.trilemma.foundation/privacy, https://www.trilemma.foundation/terms, and https://www.trilemma.foundation/charter. Other Foundation sites link to those URLs and do not publish a second policy.

1.4 This Policy is a global baseline. Canadian and British Columbia privacy law is the starting point because that is where Trilemma is established. GDPR, UK GDPR, and US state privacy laws may also apply to a particular person because of where they live or how they interact with us. We do not claim that every statutory right listed below applies to every person in every situation.

2. Information we collect

2.1 We collect the following categories when you use our sites or programs:

  • Identifiers and contact details you submit: name, email address, LinkedIn or other profile URL, organization, and similar fields on a form.
  • Application content: role applied for, resume/CV/portfolio URLs, cover notes, background, goals, availability, and related answers.
  • Public contributor records we publish: name, project, contribution role, public profile URL, and headshot URL, when consent or a partner’s documented publication rule allows it.
  • Technical data: IP address used only as a short-lived rate-limit key; ordinary hosting logs; page paths sent to cookieless Vercel Analytics after search and unknown query values are stripped.
  • Communications you send to Foundation mailboxes, including privacy requests.
  • Donation, Discord, and GitHub data processed by those providers when you leave our sites, as described in the service schedules.

2.2 Sources include: information you provide; university or program partners who supply consented public records; public repositories and profiles you publish; and service providers named in section 7.

2.3 We do not ask for unsolicited sensitive data (health, government identifiers, precise financial accounts, immigration files, confidential student records, employer-confidential or client data). Do not send those unless we expressly request them in writing. We may refuse, delete, or restrict unsolicited sensitive information.

3. Purposes and lawful bases

3.1 We use personal information to operate websites and programs; review applications; communicate with you; publish consented public attribution; protect security; comply with charitable, tax, and legal duties; and respond to privacy requests.

3.2 Where GDPR or UK GDPR apply, the bases we rely on are: steps prior to a contract or performance of a contract (applications and program participation); legitimate interests in operating a charitable education mission, securing our systems, and publishing public program records; consent where we rely on it for publication or optional communications; and legal obligation where a statute requires us to keep or disclose information. CASL consent, if marketing email is ever used, is collected separately and is optional. We do not send marketing email from the application forms.

3.3 We do not sell personal information, do not use it for cross-context behavioural advertising, and do not run advertising cookies or a cookie consent banner while the sites remain cookieless and free of non-essential device storage.

4. Cookies, logs, analytics, and rate limiting

4.1 Vercel Analytics on Foundation sites is cookieless. We configure it to send the page path after stripping search strings and unknown query values. Data catalog search queries (`q`) are not sent. Build local-search queries are not sent.

4.2 Vercel may keep ordinary server logs that include IP address, user agent, and requested URL for a short operational period under Vercel’s then-current practices. We do not operate a separate visitor-log warehouse.

4.3 Application endpoints store the client IP only as a rate-limit key (5 submissions per 15 minutes per IP per form type), in Upstash Redis when configured or in memory otherwise. Those keys expire after 15 minutes. Application bodies are not cached and are not written to application logs.

5. Public publication

5.1 Names, photos, profile links, project titles, and contribution descriptions appear on Foundation sites only with documented opt-in or documented institutional collection of consent. Email addresses are not a public field.

5.2 You may request removal or limitation of non-essential public attribution by writing to the privacy contact. Git history, third-party platforms, and legal or archival duties may limit what we can erase.

6. Service providers and international processing

6.1 We use: Vercel (hosting, logs, cookieless analytics); Upstash (rate-limit keys and short-lived parsed public sheet cache); Resend (transactional email); Google Workspace/Sheets/Drive (public program workbooks, images, and mail); CanadaHelps (donation checkout); Discord (community); GitHub (source and contribution); and, where we post, LinkedIn, X, and YouTube.

6.2 These providers may process data in Canada, the United States, the European Union, the United Kingdom, or other countries where they operate. Where GDPR or UK GDPR apply, we use the transfer tools those providers offer (such as Standard Contractual Clauses) once those agreements are in place. Until counsel confirms the transfer file, treat this clause as describing the intended mechanism, not a completed legal assessment.

7. Retention, deletion, and security

7.1 Organizational baseline pending owner confirmation, then used as the published periods:

  • Career, mentorship, and mentor applications: 24 months after the last decision or substantive contact, then deleted from the applications mailbox and email provider copy.
  • Rate-limit IP keys: 15 minutes.
  • Parsed public sheet cache: 1 hour.
  • Monitor and operations alert email: 90 days.
  • Public contributor and event records: while published.
  • GitHub history: for the life of the repository, subject to platform limits.
  • Donation receipts we receive (not card data): 6 years for Canadian charity and tax records. CanadaHelps holds checkout data under its policy.
  • Breach records: at least 24 months.

7.2 When information is no longer required, we delete, anonymize, or securely dispose of it where reasonable. Open-source history and third-party copies may remain.

7.3 We use HTTPS, restricted application mailboxes, rate limiting, sanitized public caches, and provider access controls. No method is perfectly secure. We keep an internal breach register and will notify people and regulators when applicable law requires it.

7.4 We do not make solely automated decisions that produce legal or similarly significant effects about you.

8. Your rights

8.1 Depending on the law that applies to you, you may have rights to access, correct, delete, restrict, port, or object to certain processing, and to withdraw consent. Those rights are not unlimited. We may refuse or limit a request where another law, security, another person’s privacy, or an archival or open-source duty requires it.

8.2 Send requests to matt@trilemma.foundation. We may ask you to verify your identity using information already on file.

8.3 You may complain to us first. You may also complain to the Office of the Information and Privacy Commissioner for British Columbia, the Office of the Privacy Commissioner of Canada, a European Data Protection Authority, the UK Information Commissioner’s Office, or a US state attorney general or privacy agency, where that authority has jurisdiction over the processing you are concerned about.

9. Audience, students, and minors

9.1 Foundation programs are designed for university students and adults. We do not target children. If a minor participates through a university or guardian arrangement, we rely on documented guardian or institution consent, including for any public name or photo.

10. Service schedules

10.1 Main website career, mentorship, and mentor intake (`www.trilemma.foundation`). Forms collect the fields listed at the point of collection. Submissions go through Resend to matt@trilemma.foundation. Subjects do not include applicant names. IPs are used only for 15 minutes rate limiting. Notice of the Privacy Policy is an acknowledgment; acceptance of the Terms and Conditions is contractual. Optional marketing consent is not collected on these forms.

10.2 Public member and project records. Google Sheets supply names, projects, universities, public URLs, and headshots. Unpublished columns such as Email are not part of the public dataset and are not cached. The origin cache stores sanitized parsed JSON for 1 hour, not raw spreadsheet CSV. Publication requires documented consent or partner evidence; takedown requests go to the privacy contact.

10.3 Data catalog (data.trilemma.foundation). Browse public dataset metadata. Search queries are stripped from analytics. Contribution and issue reporting that leave the site for GitHub are GitHub’s processing. Security headers match the rest of the Foundation properties.

10.4 Build / playbook (`build.trilemma.foundation`). Public documentation, contributor pages, and an `llms.txt` / agent corpus of **public content intended for third-party retrieval**. Visiting Build does not send your personal data to an AI model operated by Trilemma. Local documentation search queries are not sent to analytics. GitHub accounts used to contribute are processed by GitHub.

10.5 Tournaments, Discord, and donations (2026.trilemma.foundation and related CTAs on www). Event photos follow the publication-consent rules. Discord is a third-party community. Donations are processed by CanadaHelps; the CRA charity account 745663427RR0001 identifies Trilemma only in that charity context. We do not collect payment card numbers on Foundation sites.

11. Changes and prior versions

11.1 We may update this Policy. The Last Updated date identifies the latest text. Material versions are retained by Trilemma. The previous public version was dated 2 May 2026.

12. Contact

12.1 Privacy questions and requests: