Trust & policies
Privacy Policy
A behavior-matched policy explaining data handling, account controls and AI boundaries, approved and authorized by the Founder to operate. No attorney has reviewed this document.
This document is approved and authorized by the Founder to operate. It has not been reviewed or approved by outside legal counsel.
Current status
The product uses browser-local storage and implements authenticated durable persistence in Supabase. Live Stripe credentials have been configured for Founder Edition checkout; the application still checks several independent conditions (including database product/price activation) before accepting a real payment, and fails closed if any is not met. The confirmed vendor list is Vercel, Supabase and Resend as active processors; OpenAI and Stripe are each active only once their respective feature or commerce activation is actually complete, independent of this policy's own status. No analytics provider is implemented.
Information collected
- Account data if activated: email, managed identity identifier, verification/session information, optional display name, locale and time zone.
- Learning data: program progress, Practice attempts, reflections, Evidence Log entries, Coach and Mentor history, Professional Progress Summary, Vantage/Dashboard state and preferences.
- Support/security data after channels exist: messages, request context, timestamps and minimum incident evidence.
- Technical data necessarily processed by hosting and identity services, such as IP address, request headers and security logs, subject to actual vendor configuration.
Browser-local information
Progress, drafts, theme, privacy acknowledgements and other learning state may be stored in localStorage on the device. This storage is not an HTTP cookie and remains until the application or user clears it. It can be read by scripts running on the same origin.
Authentication and durable accounts
The implemented design uses Supabase Auth and PostgreSQL with row-level security. Password handling is delegated to the identity provider; this application does not receive password hashes. Account data should not be described as live until the environment and isolation tests pass.
Reflective Signal and Mentor
When Reflective Signal or Mentor is used with an external AI provider configured, OpenAI is disclosed as an external AI service provider. Reflective Signal transmits the learner's submitted Practice response and bounded scenario/rubric/Framework context needed for feedback; Mentor transmits the pasted document text plus its stated document type, audience, and objective. Only information reasonably necessary for the requested interaction is transmitted — the application does not intentionally send unrelated profile data, billing or payment information, security logs, unrelated practice history, secrets, or credentials to the AI provider. This is an educational AI capability, not a human coach, and users should not submit confidential, proprietary, client-identifying, personal, legal, medical, or otherwise sensitive information. A local/deterministic mode avoids any external model call. Questions about this processing can be directed to the configured privacy contact.
The configured code uses the OpenAI API. Provider retention and processing depend on the actual API account, endpoint and data-control configuration in effect at the time a request is made. This policy does not claim that user content is used to train OpenAI's models, or make any stronger privacy guarantee than the actual OpenAI account configuration and applicable OpenAI API terms support.
Billing and commerce
When checkout is activated, Stripe processes the hosted payment flow for customers in Mexico. The application stores a Stripe customer reference, checkout/payment references, purchase and entitlement status, amount and currency metadata, receipt or invoice references, refund records, and minimized webhook event summaries. It is not designed to receive or store raw card numbers. Tax behavior remains unapproved.
Purposes
- Provide requested learning and account functions.
- Maintain progress across devices after explicit account use.
- Generate requested Coach or Mentor feedback.
- Protect accounts, prevent abuse and diagnose failures.
- Respond to support, privacy, accessibility and security requests once channels are active.
- Meet legal obligations applicable to the approved operating entity and jurisdictions.
Cookies and similar technologies
Implemented account code uses required authentication cookies if Supabase is configured. A required session-choice cookie records remembered versus browser-session behavior. Theme and learning drafts use localStorage. No analytics or marketing cookies are implemented. See Cookie Notice.
Retention
No fixed retention period is implemented for any data category. Account deletion cascades through durable learner and user-linked commerce records; the user reference on audit-log entries is set to null rather than deleting the log entry. Provider records, payment-event summaries, service logs and backups follow separately verified schedules. Local browser data remains on each device until cleared. Whether accounting, fraud, tax, dispute, or legal-hold obligations require commerce or audit records to be retained beyond account deletion has not been determined.
Export, deletion and user choices
Implemented account code provides JSON export, individual/all evidence deletion, privacy preferences, global session revocation and account deletion. These controls require a configured provider and live acceptance before they can be promised as operational.
Sharing and processors
Data is processed by Vercel (hosting), Supabase (database and authentication), and Resend (transactional email) as active processors. OpenAI (AI features) and Stripe (payment processing) become active processors only once those respective features are activated. Squarespace administers the domain and DNS only and does not process product or customer data. The Academy does not currently implement sale of personal data or behavioral advertising.
Security
Implemented controls include server-side session checks, row-level ownership policies, same-origin mutation checks, request validation, limits, no-store responses and server-only secrets. These controls have not completed live provider or independent security testing. No absolute-security promise is made.
International availability and applicable privacy rights
ThinkToAction is operated from Mexico and internationally available, subject to applicable law. The operator baseline is Mexico's federal data-protection framework (LFPDPPP), under which Mexican residents may exercise ARCO rights (access, rectification, cancellation, and objection) through the configured privacy contact.
Customers residing outside Mexico may have additional mandatory privacy rights under the law of their own country. This policy does not state that any specific foreign privacy law applies automatically or that ThinkToAction has certified compliance with any of them — applicability depends on facts (such as the customer's residence and the nature of processing) that have not been determined here. Where applicable, this may include: EEA residents' rights under the General Data Protection Regulation (GDPR); UK residents' rights under the UK's data-protection framework; and US residents' rights under applicable state privacy laws, including California. Where a mandatory local right applies and is not otherwise addressed in this policy, the customer may exercise it through the configured privacy contact, and the Academy will address the request under the law that actually applies to it, without waiting for a future policy revision.
Service providers (see Sharing and processors) may process information in countries other than the customer's country of residence. This is disclosed as a fact of how the current hosting/processor architecture works. No adequacy decision, Standard Contractual Clauses, Data Protection Officer, EU representative, UK representative, or privacy certification is claimed here — none has been established, and none is asserted. If a legally required international-transfer mechanism is later determined to be necessary for a jurisdiction this product serves, that mechanism does not yet exist and is not represented as existing.
Children's privacy position and identity-verification process for rights requests remain to be finalized.
Contact and changes
A single monitored contact channel serves privacy requests, consistent with the channel published across the Trust Center. A policy-change notice process must be approved before this policy becomes effective.