Sticky Board
What this records, and what it does not
Written for the people who will be asked to text the board, and for the steward, manager, or records officer who wants to check. Plain language on purpose. Where a sentence could be read two ways, the stricter reading is the one we mean.
Recorded
- The text of each note, the time it arrived, which column it is in, and whether it has been cleared.
- Photos sent to the board, if any.
- Mobile numbers of the board's members, added by the superintendent, so the board knows whose texts to accept. A member's two phones count as one person.
- Which member sent each note, kept only so that undo can reverse your own clear and the phone page can show your notes first. It is never shown on a card, never in the export, never counted.
- A log of texts received (seven days, for diagnosing a lost message) and of replies sent (ninety days).
- Texts from numbers that are not on the board are kept as pending for the superintendent to accept or dismiss; they never appear on the TV.
Not recorded, not produced
- No per-person statistics. There is no count of notes by person, no clear rate by person, no report, no export that attributes a note to someone. The code that computes board totals excludes the member column entirely, and the automated test suite checks this on every release.
- No location. The board knows a phone number, not where the phone is.
- No reading of other texts. Only messages sent to the board's own number arrive here.
- No marketing texts. The board never texts first. It only replies to a text it received.
Who sees what
- The TV shows open notes and the last day's cleared ones. Never held notes, never pending ones.
- Members' phones show the board, plus each member's own held notes.
- The superintendent sees everything on the board, including held and pending notes, members' numbers, and board totals.
- The operator (JV Digital LLC, us) can see board contents when supporting you, and the system logs above. We do not look otherwise.
Who processes it
Three companies touch the data, each for one job. Cloudflare runs the service and stores the board (United States). Twilio carries the text messages between the phone networks and us, and keeps its own message logs under its own retention policy. Anthropic sorts notes that have no #tag or filing word into a column; it receives the text of those notes only, never a phone number or a name of who sent it, and we do not use a zero-retention arrangement, so its standard API retention applies. We use nobody else and sell nothing.
Text messages are not private end to end. Carriers and Twilio can see them in transit, like any SMS. Do not text anything to the board you would not write on a whiteboard in a room with a window.
The filter
Every note is checked against a short list of patterns that look like customer, account, meter, work-order, outage or long-number data. A match is saved but kept off the TV, and the sender is told. Notes without a #tag also pass through the sorting model, which can hold a note for the same reasons. The superintendent can release or hold any card. This reduces the chance that sensitive data lands on a wall; it does not prevent it. The filter reads text only, not photos.
Keeping and deleting
- Open notes are never deleted automatically. They stay until someone clears them.
- Cleared notes are deleted after the number of days the superintendent sets: never, 7, 30, or 90. Boards for municipal departments start at never, because board contents may be public records under state law. Confirm with your records access officer before turning deletion on.
- The superintendent can export the whole board (spreadsheet or JSON) at any time, and delete the whole board with one confirmation. Delete removes notes, photos, members and links; the phone number is retired for 30 days.
- Private boards are deleted on request by texting the operator or from the board's own manage page.
If something goes wrong, or we stop
If we learn that board data was exposed to someone who should not have it, the board's superintendent hears from us within 72 hours with what we know. If the service shuts down, every superintendent gets 90 days' notice and an export. The core of the service is open source, so a department can run its own copy.