PRIVACY & SECURITY
How EURtracker handles project information.
EURtracker is designed as a private project workspace. This page explains the product behaviour and security boundaries in plain language. It is product information, not a substitute for an organisation's own legal notices, data-processing agreements or programme-specific requirements.
Project access
Project content is associated with authenticated users, project memberships and organisations. Project Leaders can work across the project while Partner access is limited to the organisation and project permissions configured for that user.
Session protection
Authenticated application areas are guarded before the workspace is served. Users without a valid session are returned to the sign-in flow.
Reporting data
Quick Updates, reviewed Progress material, report drafts and export metadata are used to support the reporting workflow. The professional report export can include source traceability so a reviewer can understand which reviewed project notes contributed to the handoff.
Report files
Current export history records handoff metadata such as report scope, status and filename. The export history is designed not to store duplicate DOCX file bytes.
Authentication
EURtracker uses Supabase Auth for user authentication. Normal production sign-in and account confirmation use the canonical application domain at app.eurtracker.com.
Passwords
EURtracker does not need to expose user passwords to project members. New-account forms enforce a stronger minimum password length and browser password-manager conventions are used on the sign-in form.
Browser security
The production application uses HTTPS and security headers including HSTS, Content Security Policy, frame restrictions, referrer controls and restrictive browser permissions.
Preview environments
Generated development deployments are treated as internal previews and normal authentication flows are directed back to the verified production application.
AI-assisted work
Current AI-assisted Progress synthesis and reporting drafts use the OpenAI API when a user requests those functions. The selected project context and reporting/source material needed for the request is sent to the API; EURtracker requests use store:false.
Generated wording remains reviewable by people before it is treated as submitted reporting material. OpenAI states that API customer inputs and outputs are not used to train its models by default. Retention and regional-processing guarantees depend on the production OpenAI project configuration and are documented separately for public-sector contracting.
What remains external
Formal EU programme submission, programme authority decisions, formal financial reporting, organisational records-management obligations and contractual compliance processes remain outside EURtracker unless explicitly integrated in a future product version.