Platform & Relay privacy

September 12, 2026

This supplement explains the additional information used when you choose NRD Platform sign-in or NRD Relay. NRD Tech LLC operates these services. The existing privacy policy describes our hosting, billing, security, contact details, and data-request process. Existing Sight data practices are unchanged by this supplement.

Signing in with Google or Microsoft

When you choose a provider, we request basic identity and email information to authenticate your account. We store the provider’s stable account identifier, issuer, your verified email address, and the link to your NRD account. We do not request access to your inbox, files, calendar, or contacts. Provider access and refresh tokens are not retained.

Google and Microsoft handle their own sign-in screens under their respective privacy policies. Microsoft sign-in also requires a one-time mailbox verification when you first connect an account. Connecting a provider to an existing NRD account requires proof of access to that existing account.

A temporary, secure browser cookie binds the sign-in request to its response. We store hashed application session identifiers so sessions can expire and be revoked. Signing out clears the browser session and requests server revocation. Temporary sign-in records expire after ten minutes and are removed after a short operational cleanup period.

Information your organization puts in Relay

Relay stores the people directory, work email addresses, departments, reporting relationships, expectations, check-ins, feedback, examples you attach, responses, and agreed next steps. It also stores review cadence, notification preferences, access grants, subscription capacity, and activity metadata needed to operate the service.

The person being reviewed, their current primary management chain, and explicitly authorized People Ops readers can see published history. Organization ownership alone does not grant access to review content. Drafts remain visible to their author. A dotted-line relationship does not grant access to someone’s history. Named contributors receive only the specific feedback request shared with them.

Email and optional AI

Verification emails contain a short-lived code. Relay reminder emails contain a neutral link to the private inbox; they do not include performance feedback. AWS provides email delivery.

If your organization enables writing assistance and you request it, the selected text is sent to a model through Amazon Bedrock to help with wording or missing specifics. You review the suggestion and decide what to publish. Relay does not automatically score people or make employment decisions. AI draft results expire after thirty days. Sight and Compass evidence is included only through links or excerpts people choose to attach.

Retention, correction, and access

Published feedback can be corrected through a linked amendment that preserves the original record. Recipients can acknowledge feedback or record a disagreement. Archiving a person preserves their history until the organization’s configured retention period ends. The default is seven years, with settings from one to ten years; access audit metadata remains. Ending a subscription does not immediately erase published history.

Your organization manages employee records and access. Contact your organization’s administrator for its retention choices. For privacy questions or an export or deletion request, contact support@nrdsight.com. Please do not put unnecessary sensitive personal information in review notes.