Brophy Projects
Privacy Policy
Effective upon first public publication · Operated by Luke Hamman
Brophy Projects is operated by Luke Hamman. It is a workspace for authorized project participants to collaborate on projects, records, and decisions. This notice explains how information is handled in connection with that service. Use of the Brophy name and branding does not mean that the school operates the software.
Information we handle
Account and authentication information includes your name, email address, authentication-provider identifiers, linked login identities, session information, and profile information supplied by you, an administrator, or your sign-in provider. Workspace records may also include your organization or company, phone number, role, project memberships, access settings, and login activity.
Access-related records include invitations, requests for access or permission changes, information supplied with those requests, and administrator decisions. If you contact us to request access, we handle your email, name, any organization details you choose to supply, and the request itself. Signing in does not automatically grant workspace access.
Project information includes project and topic descriptions, comments and revisions, tasks, assignments, review requests, recorded decisions, uploaded documents and file versions, and links. Content may contain personal information about you or others. Technical and audit records include action timestamps, actor and record identifiers, permission changes, notification state, security events, and service errors. Hosting and authentication providers also process connection and request information, which can include IP addresses and browser or device information.
Why information is used
Information is used to authenticate participants; provide collaboration, file access, and shared records; apply workspace and project permissions; manage invitations and access decisions; provide notifications where enabled; and operate, support, troubleshoot, and protect the service. Audit records help explain who performed an action and investigate errors or misuse. Information may also be used to respond to requests and meet applicable legal obligations.
In-app notifications are supported. Ordinary application email notifications are not currently enabled through a production transactional-email service; authentication email is handled separately by Supabase Auth. An email address or a saved notification preference does not guarantee that an email will be sent.
Who can see information
Project information is available to participants whose permissions allow access and to authorized administrators within their administrative scope. Account and directory information may be visible to authorized workspace participants to support collaboration. An administrator may manage access, review access requests, and inspect records needed to operate or secure the workspace.
Information may be shared with service providers as needed to operate the service, in response to a valid legal requirement, or where reasonably necessary to address security incidents and protect rights. Only submit information you are authorized to share with the intended collaborators. Downloaded files, external links, and copies made by recipients may be subject to separate controls and retention.
Hosting, authentication, and Google sign-in
Replit hosts the application and processes application requests and operational logs. Supabase provides authentication, the PostgreSQL database, and private file storage. These providers process relevant account, project, file, authentication, and technical information to perform their functions. Their own terms and privacy notices also describe their services.
Google sign-in supplies basic account information, such as your name, email address, and profile image where provided, to authenticate you through Supabase. Google sign-in by itself does not grant this application access to your Gmail messages or Google Drive files. Any separate connection requesting additional access would require separate authorization. Google and Supabase handle their own authentication pages, sessions, and security processes.
Optional Connected AI
If an administrator separately enables Connected AI for your account and you authorize an external client, that client can request information and permitted actions within your current workspace and project permissions. Depending on the tools used, shared information can include project records, comments, tasks, files, and audit-relevant action details. Approval of workspace access alone does not grant Connected AI access.
External AI services, including ChatGPT or Claude when you choose to connect them, process information under their own terms, privacy policies, and your account settings. Review those policies before sharing confidential or personal information. Revoking a connection restricts future access but does not necessarily erase information already received by that provider. Brophy Projects does not obtain your private external chat history merely because you connect a client.
Browser storage, cookies, and analytics
The application uses browser storage for persistent authentication sessions and interface preferences, such as favorites, recent projects, filters, column choices, and sorting. Supabase manages session persistence and token refresh. Sign-in and hosting services may use their own necessary cookies or similar technology. Clearing browser storage may sign you out or reset preferences; signing out does not delete shared project records.
The inspected application does not include advertising pixels, session-replay tools, or a third-party marketing-analytics SDK. It does record operational and audit events. Hosting and authentication services maintain their own technical logs and may provide operational traffic measurements. This is not a claim that no cookies or technical measurements are used.
Retention and your requests
Information is retained for operational needs, continuing shared project records, recovery, security and audit purposes, and applicable legal requirements. Retention can differ between active records, deleted records, backups, and service-provider systems. Removing an account or ending project access does not automatically remove records that other authorized participants need. This notice does not promise a fixed deletion or backup-expiry deadline.
You may contact Luke Hamman at luke@tellconstruction.com to request access to, correction of, or deletion of personal information, or to ask about other rights available under applicable law. Identity and authority may need to be verified before action is taken. A request may require coordination with the workspace administrator or relevant service provider, and some records may need to be retained for shared-record, security, or legal reasons. No automatic account-wide deletion or request-completion timeline is promised; applicable legal deadlines still apply.
Security and international processing
The service uses authentication, server-side permission checks, private file access controls, and audit records to help protect information. No system, transmission, or storage method is completely secure. Protect your sign-in accounts, use appropriate device security, and promptly report suspected unauthorized access.
The configured Supabase database connection uses a US-region endpoint. Replit, Supabase, Google, and any external services you authorize may process or support information in countries other than your own, where laws may differ. The service does not promise country-exclusive processing. Contact Luke Hamman at luke@tellconstruction.com for questions about processing locations and applicable transfer arrangements.
Intended audience and sensitive information
This service is intended for authorized project participants, not as a public student-facing service. Do not submit sensitive student, education, health, or other specially protected information unless you have appropriate authority and suitable safeguards and agreements are in place. The service is not represented as a dedicated student-record or clinical system.
Contact and updates
For operational, privacy, and legal inquiries, contact Luke Hamman at luke@tellconstruction.com. A request should identify the relevant workspace and concern without including passwords, authentication codes, or unnecessary sensitive information.
This notice takes effect when first published publicly. Material changes will be identified through an appropriate service notice; email will be used only where delivery is available.
Contact details
Luke Hamman · Operational, privacy, and legal inquiries
luke@tellconstruction.com
Back to sign in