Privacy policy
Last updated 7 October 2026
Shamp is run by goimpactnow, a brand of Truthsprout Network ("we", "us"). This policy covers Shamp at joinshamp.com and in the Shamp app. The rest of goimpactnow.org has its own privacy policy. We do not sell your information, and Shamp has no advertising trackers.
What we keep
Your account
Your username, email address and password. The password is never stored as you typed it: only a salted scrypt hash, which cannot be turned back into the password. We also keep whether you are a person or an organisation, when you joined, the causes you follow, and your settings.
Your profile
Anything you add: your name, headline, introduction, photo and background, where you are, your organisation, what you are open to, your experience, education and skills, and endorsements others give you.
What you do on Shamp
Your posts and replies, with any photo, PDF, video or link; reactions; reposts; who you follow; the posts you save; what you have marked on an opportunity (applying, selected); the Circles you start, join, ask to join or are invited to, your role in each, and what you answer when a Circle asks questions before letting you in; the pieces you write on Podium, the drafts of pieces you have not published yet, and the Podiums you subscribe to; Shamp Live sessions you said you would attend; the endorsements you give; the members you block; and what you report to us, with the reason you give. Nobody you block or report is told, and only the Shamp team sees reports.
Programme badges and checked titles
If you ask for a badge for a programme you have been through, the programme, the year, and the proof you send: a letter, certificate, screenshot or link. Only the Shamp team sees the proof, and it is deleted as soon as they decide, whether the badge is approved or not. An approved badge is public on your profile.
If you check a job title with your work email, we send a code to that address and keep only its domain (for example braanda.com), which is shown with the title. The address itself is not kept, apart from the partly hidden record we keep of every email we send. If you check a title with proof instead, the proof is handled as it is for badges. A checked title is public on your profile and under your name on your posts.
Messages
Messages you send and receive. They are kept on our servers and are not end-to-end encrypted.
Notifications
Your list of notifications. If you turn on notifications on a phone or browser, we keep the address your browser gives us for delivering them. In the Shamp app for Android, that address comes from Google Firebase, and we keep it with the app's version and your phone's make and model, so we can tell which phones still receive them. The push itself carries no words: your device fetches what happened from us when it arrives.
Technical information
- A one-way scrambled form (a hash) of your internet address, stored with what you post and used to limit abuse. We do not keep the address itself with your posts.
- How many times each post is viewed, as a plain count, not who viewed it.
- Page views, counted without cookies: the page and the site you came from.
- A record of the emails we sent you (confirming your address, resetting your password), with your address partly hidden.
What is public, and what is not
- Public: your username and profile, your posts and replies, reactions and reposts, your programme badges, the causes you are active in, and how many people follow you and you follow. Public pages can be found by search engines and shown in link previews on other apps.
- Signed-in members only: the lists of who follows you and who you follow, unless you hide them in Settings.
- Circles: what you post in a Public Circle is public, like any other post. What you post in a Private or Secret Circle is read only by that Circle's members; it is left out of search, feeds, profiles and link previews for everybody else, and it cannot be reposted. A Private Circle's name, purpose, rules and who runs it can be seen by anybody; a Secret Circle is shown only to its members and the people it invites. A Circle's list of members is for its members. The people who run a Circle see requests to join it, with the answers given, and a record of what its moderators did. The Shamp team can see what is in any Circle when it is reported, when our screening holds it, or when keeping Shamp safe needs it.
- Podium: a piece you publish on Podium is public, like any other post, and so are your Podium's name, what it is about and how many people subscribe to it. There is no list of who subscribes for anybody to read; a Podium's writer is told when somebody subscribes to it. A piece you are still writing is a draft: it is kept on our servers so that you can carry on from another device, and only you can open it.
- Shamp Live rooms: a session held on Shamp is heard by everybody in its room, and everybody in it sees who is there, who is on the stage and whose hand is up. While you are in a room that is open, your picture may be shown beside the session where it is listed, as one of the people in it. Your voice is carried live by our own media server and is not recorded or kept by us, unless the session's host has it recorded. When they do, everybody in the room is told for as long as it is being recorded, and anybody coming in is told before they are in; what is said on the stage from then until the recording is switched off is kept on Shamp as a sound file, which the host, the goimpactnow team and Premium members who may see the session can download, and which the host can remove. What is written in a room's chat is shown to the people in the room as it is written and is not kept. People in the room can still record what they hear on their own devices. Your microphone is used only while you are on the stage and have turned it on. A session can be held as a video room: there, your camera is used only while you are on the stage and have turned it on, your picture is seen by everybody in the room for as long as it is on, and it goes off when you leave the room's screen. Pictures are carried live and never kept by us: a recording of a video room keeps its sound only. Whoever runs a room can play music into it. A sound file or a link they give is held on Shamp only while it plays and is then removed, and when a host shares what their own phone or computer is playing, that sound is passed on as it plays and nothing of it is kept; in the app, Android asks the host first, and Shamp's own sound is left out. The media server passes sound and pictures on, so it sees your internet address while you are in a room, and the other people in the room do not. What we keep of a room is who hosted it, when it opened and ended, who was on its stage when it ended, who was removed from it, and the most people it held at once.
- Private: your email address, your saved posts, your messages, your notifications and your settings.
How we use it
- To run Shamp: your account, your profile, your posts and the conversations around them.
- To choose what you see: the For you feed uses who you follow, the causes you follow, the Circles you are in, and what people found useful; suggestions of who to follow use the same kind of signals.
- To tell you what happened: notifications, and emails about your account.
- To keep Shamp safe: screening posts for fees, scams, links and spam; limiting how fast anyone can post; moderation.
- To answer you when you write to us, and to understand in aggregate how Shamp is used so we can improve it.
Who else handles it
We use a small number of services to run Shamp. They handle information only to provide their service to us:
- Our hosting provider, whose servers store Shamp and its data.
- Cloudflare, which delivers Shamp's pages and protects it from attacks, and so sees your internet address.
- Resend, which delivers the emails we send.
- Your browser's push service (from Google, Apple or Mozilla), if you turn on notifications. It delivers a signal with no content.
- Google Firebase Cloud Messaging, if you turn on notifications in the Shamp app for Android. It delivers the same signal with no content.
- The meeting service a Shamp Live host chose, when you join their session there.
When you post a link, Shamp's server fetches that page to make the link's card, and keeps its picture on our servers, so people reading the post do not contact that site. We share information with authorities only when the law requires it. These services and our servers may be outside the country where you live.
How long we keep it
- Your account and what you post, for as long as your account exists, or until you delete them.
- Notifications: the most recent two hundred.
- Circles: if you leave a Circle, or are removed from it, what you posted there stays for its members until you delete it, which you can still do from your profile. A record that you left or were banned is kept, so a ban cannot be undone by leaving and joining again. What a Circle's moderators did is kept as a record of who did what and why.
- Podium: a draft is kept until you publish it or delete it. Pictures you added to a draft and did not use are removed when it is published. If you delete your account, your drafts, your Podium's name and your subscriptions are removed; the pieces you published stay under your deleted username, like your posts, unless you delete them first.
- Link cards: a week, then fetched again if needed.
- When you delete your account, your email, password, profile, notifications, phone notification settings and endorsements are removed. Your username is kept, marked deleted, so no one else can take it and appear to have written your posts. Your posts stay up unless you choose to hide them, which also removes their files. Messages you sent stay in the other person's conversation.
- Backups are overwritten over time.
Your choices and rights
- See and change your profile at any time, and delete posts, replies and your whole account yourself.
- Hide who follows you and who you follow. Turn phone notifications off, or stop one person's posts buzzing your phone with the bell on their profile.
- Ask us for a copy of your information, to correct or delete it, or to stop using it for something, by contacting us. You can also complain to the data protection authority where you live.
Children
Shamp is not for anyone under 16. If we learn an account belongs to someone younger, we close it.
Security
Shamp is served only over HTTPS. Passwords are hashed, and changing or resetting yours signs every other device out. No system is perfectly secure; if something goes wrong that affects you, we will tell you.
Changes
If we change this policy, the date at the top changes, and for important changes we will tell you on Shamp first.
Contact
Questions or requests about your information: contact us.