The organisation directory lists collectives whose steward made a separate, versioned directory publication choice. Making a profile visible at /c/…is not enough. The directory is a projection of an organisation’s declared facts, not a social graph, membership index or recommendation system.
The versioned directory checkbox is the current receipt this surface has. Existing public profiles were not opted in retroactively. The checkbox names searchable HTML, public JSON, the exact steward-written fields, platform-record timestamps, and the risk of third-party copies. It does not select platform-derived member or steward fields, or grant rights over the steward’s words beyond showing them. Stewards must not put personal data about another person in directory fields.
The API separates values by authorship:
NOASSERTION; copyright remains with the applicable rightsholder. That label does not reduce Cambridge TCG’s responsibility for its processing or permit a steward to publish another person’s data.listPublicCollectives selects no collective record id, nosteward_user_id, no publication flag, and no member row. Its return type cannot hydrate the private Collectivemodel. A private collective is absent rather than represented by a redacted row, so this surface cannot confirm it exists. This is a structural claim: descriptions and house rules are steward-authored free text and could still contain personal data despite the structural exclusion. The notice therefore prohibits stewards from including personal data about another person and provides a correction/removal contact.
The directory is available as public HTML and a cross-origin public JSON API. Anyone can view it. Search engines, AI crawlers and other third parties may index, copy or redistribute the slug, display name, kind, region, languages, description, house rules and platform-record times. Names and descriptions are searchable; kind, region and language are filters. Withdrawing a listing stops Cambridge TCG’s future directory responses but cannot recall a copy already fetched by a third party.
To correct or remove a listing, the steward can turn it off in account management. Anyone can also email [email protected], including where a field contains personal data about them.
The JSON endpoint returns 400 INVALID_INPUT for an unknown kind, malformed or out-of-range limit/offset, or text beyond the documented maximum. It does not silently turn invalid explicit input into a different query, and repeated values are rejected as ambiguous. NUL and other Unicode general-category Cc characters are rejected before any database read. The HTML page is forgiving: unsupported or repeated URL filters are ignored with a visible notice, and a page beyond the end returns to the last available page (page one for an empty directory).
%, _ and backslash are escaped before anILIKE, so “substring” means literal substring rather than caller-supplied SQL wildcard syntax.Turning off the directory choice removes the collective from future HTML and JSON reads; making the profile private also clears the current directory receipt. A later listing needs a fresh choice. Withdrawal cannot recall a copy fetched earlier. Responses containing participant-authored entries are no-store. An empty result may use the directory’s ten-minute freshness class only when the consistent total is also zero and the caller supplied no free text. Count and page rows come from one materialized database statement, so a concurrent listing or withdrawal cannot split their snapshot.
apps/storefront/src/lib/collectives/db.tsapps/storefront/drizzle/0097_collectives.sql; directory receipt: apps/storefront/drizzle/0131_collective_directory_publication.sqlv2 — 2026-08-24.The publication notice now expressly names public HTML and JSON, search and filters, indexing, AI crawlers, third-party copying, the limit of withdrawal, Cambridge TCG’s correction/removal contact, and a categorical rule against entering another person’s data. Earlier v1 receipts are not current and do not list a collective.
v1 — 2026-08-24. Initial organisation-directory contract: separate versioned opt-in with no legacy backfill; steward/platform fields separated; no ids, membership, steward identity, ranking or inference; bounded literal search.