Privacy Policy
Owner-approved for publish — not counsel-reviewed. Numeric retention SLAs and counsel Privacy pack still pending. Soft launch collects minimal account data; USD PSP (Cashfree / PayPal) when checkout is enabled.
1. What we collect
- Account / waitlist: email address you submit.
- API usage: key id, timestamps, route/tool class, response status, plan counters — not request bodies by default.
- Payments (when PSP live): PSP customer / subscription ids; card data stays with the PSP.
- Product archives: public-source snapshots and derived series (third-party content cited as observations).
- Shape C inputs: decks/structures hashed; not retained by default unless an Archive vault product is explicitly opted in later.
2. What we do not do
We do not sell personal data. We do not operate a recruiting marketplace or applicant PII warehouse.
3. Retention (engineering posture)
See also common/legal/RETENTION.md in the monorepo. Until counsel sets numeric
SLAs: account email while the account is active + up to 24 months after closure for
abuse/billing disputes; usage logs ~90 days rolling unless needed for security; R2 raw
archives retained as product data per dataset methodology; keys deleted or rotated on
request via founder mail within a multi-day window (not a ticket SLA).
4. Subprocessors
Cloudflare (Workers, Pages, D1, R2, DNS, Email Sending); Migadu (founder human mail);
GitHub (source / CI); one card PSP when named. Details:
common/legal/SUBPROCESSORS.md.
5. Contact / requests
Privacy requests: [email protected]. There is no automated DSR portal in soft launch.
← Legal index · Terms · AUP