Where your data lives
Observer keeps community data in two separated stores with different rules. Knowing the split is most of understanding Observer's privacy posture.
1. Your operational store
The working copy: raw messages, screening results, flags, cases, audit trail. Scoped to your org, visible in your dashboard, governed by your retention window, erasable on request. This is the data your moderators work with every day.
2. The research corpus
A physically separate dataset Observer uses to make its moderation models better for every community. Before a message enters it:
- Usernames and handles are replaced with consistent surrogates.
- Personal information detected in the text — names, addresses, contact details, identifiers — is replaced with typed placeholders.
- The only link back to a real identity is a separate, severable key that exists solely to honor erasure requests. Sever it and the data is permanently disconnected from the person.
Corpus data is never shown to other customers and is used only for content-safety research and model improvement.
Why this design
Screening improves with data; privacy demands erasability. The split gives both: your operational logs delete on schedules and requests, while the corpus's protection comes from pseudonymization plus severability rather than from keeping nothing. One store optimized for your moderation work, one for making the models better — with the identity link designed to be cut.
Messages from trusted roles and whitelisted actors skip screening and contribute only de-identified conversational context — and the full detail lives in the privacy policy your community can read.