Draft privacy policy · professional legal review required
Collect what is needed. Protect what is private. Explain what happens.
This draft describes the founding product’s intended data practices. It is not production legal advice and must be reviewed for the launch jurisdiction.
Information you provide
Account details, assessment responses, planning inputs, saved documents, purchase records, legal acceptances, and support messages. Financial inputs may be estimates. We do not request bank logins, card numbers, government-ID scans, passwords, private keys, or seed phrases.
Why it is used
To calculate requested educational outputs, save progress, create your Blueprint, manage access and purchases, provide support, maintain security, and meet legal obligations. Optional marketing requires a separate choice.
Service providers
The production service is designed to use Supabase for data and authentication, Stripe for payments, Resend for transactional email, and consent-aware analytics and monitoring providers. Final provider details, regions, and transfer terms require legal confirmation before launch.
Your choices
You can control optional analytics and marketing, request access or export, correct information, and request deletion subject to lawful retention. Requests are verified to protect the account.
Retention and security
Retention periods will be configured by data category before launch. Row-level access, server-side authorization, encryption in transit, audit records, secret isolation, and incident procedures reduce risk; no system can promise absolute security.
Find your starting point