Draft for review. This wording is not final until Frank approves it for launch. Version 2026-07-20-draft.
What we collect
Account data: email, display name, handle, company name and role, timezone, and your onboarding answers. Content you post: posts, comments, reactions, reports, RSVPs, and course progress. Purchase records: what you bought, when, amounts, and Stripe identifiers. Never card numbers.
Operational analytics: page-view and funnel events (for example, that a checkout started or a lesson was completed). These events carry an internal account id only; they never contain message content or email addresses.
Why we collect it
To run your membership: sign-in, access control, course progress, community features, event logistics, receipts, and support. To improve the program: aggregate funnel and activation metrics. We do not sell personal data and we do not run third-party advertising trackers inside the member area.
Processors
Supabase (database, authentication, file storage), Stripe (payments, billing portal), Vercel (hosting), and a transactional email provider (Resend, once connected) process data on our behalf under their own security terms. This list will be kept current on this page.
Retention
Account and community data are kept while your account is active. Purchase and consent records are kept as long as required for tax and legal obligations. Analytics events are pruned or aggregated over time.
Your choices
You can update your profile at any time. You can request an export of your data or deletion of your account by contacting support; identity is verified before either request is fulfilled, and legally required records (for example purchase evidence) are retained even after deletion.
Security
Access to member data is role-restricted and audited. Payments never touch our servers. Staff accounts require two-factor authentication before production access.