Privacy

How to DAO collects only the information you choose to send when you contact us: your name, email address, organization, optional role, message, and consent to receive a response. Please do not submit confidential, privileged, or sensitive personal information through the form.

We use inquiry information only to assess and respond to your request and, when relevant, prepare a consulting conversation. We do not sell personal information.

How the contact form works

When website delivery is configured, the server sends the inquiry to the How to DAO mailbox through Resend. The website does not write the submission to a database or local file. Resend and the receiving mailbox may retain the message under their own service and account settings. If secure delivery is unavailable, the site opens your email application so you can choose whether to send the message directly.

To limit automated abuse, the server checks submission timing, a hidden form field, and the number of attempts from a network address. The address is converted to a process-specific hash held only in server memory for the ten-minute rate-limit window; it is not included in the inquiry or application logs.

Readiness diagnostic

The readiness diagnostic runs in your browser. Your answers are kept only in that tab's session storage so you can move backward, forward, and edit them; starting over or ending the browser session clears them. A shareable result stores only four dimension scores in the URL fragment, which browsers do not send to this server. Answers and dimension scores are not sent through the measurement endpoint.

If you choose the optional result handoff, the site sends your name, email address, consent, and a generated score summary through the same contact-delivery process described above. Nothing is sent through that contact path unless you submit it.

First-party measurement

The site sends a small set of cookieless conversion events to How to DAO's own /api/event endpoint unless your browser reports “Do Not Track.” Events contain an allowlisted event name, a coarse page category, and limited enum or integer context. They never contain diagnostic answers, dimension scores, result bands, or archetypes.

On the diagnostic page, no measurement request is made before you explicitly submit the optional result handoff. The page holds start and completion markers only in memory and sends them after that opt-in. Anonymous diagnostic usage is intentionally not measured.

The event endpoint does not accept or log names, email addresses, organizations, messages, IP addresses, user agents, raw paths or URLs, query strings, URL fragments, or referrers. It adds a server timestamp and writes the coarse event as one structured line to application stdout. No cookies, persistent visitor identifiers, browser fingerprinting, third-party analytics tags, analytics database, or local event files are used.

Your choices

You can contact us by email instead of using the form. To request access, correction, or deletion of inquiry information held by How to DAO, email puncar@howtodao.xyz. Some records may need to be retained where required by law or an active agreement.

Last updated: August 7, 2026.