Privacy Policy
Last updated: August 10, 2026
Paid portrait orders
The collection, delivery, and timing statements in this section apply to commissioned paid portrait orders and the existing 9-question intake. They do not apply to the private whole-person journey while its activation hold remains.
What we collect
When you commission a portrait, we collect: your name, email, LinkedIn URL (optional), the answers to 9 open-ended questions, and payment information (handled by Stripe - we never see your card).
What we don't do
- We don't sell your portrait or your data to anyone.
- We don't share your portrait without your written consent.
- We don't use your portrait to train any model.
- We don't send you marketing emails after delivery.
How we use it
We use your intake answers only to prepare, deliver, revise, and support your portrait. We may use order-level information such as purchase date, delivery status, and support history to operate the service and answer your questions.
How we store it
Your portrait responses are stored encrypted at rest. Access is limited to the people and systems needed to produce and support your portrait. Your portrait is delivered to you and to no one else unless you explicitly ask us to share it.
How long we keep it
We keep your portrait on file for 90 days after delivery so we can handle revisions, support, refunds, and accidental loss. After that window, we delete the portrait and intake responses from active storage. If you want them deleted sooner, write to [email protected] and we'll delete them within 24 hours unless we are legally required to keep transaction records.
Private whole-person journey
The private whole-person journey is locally verified, but it is not yet a live participant service.
Server storage and normal review
Answer text, deliberate-version text, and shared-snapshot text are application-encrypted before server storage; operational metadata is stored separately. When hosted under separate activation authority, transport uses HTTPS. The system operator can technically access material held on the server for operation and recovery.
John's normal portrait review and export show only the snapshot you deliberately share. The unshared working copy and unselected history are excluded from that normal review path. This is a consent-filtered product boundary, not cryptographic exclusion from the operator.
Pending changes on your device
When durable browser storage is available, pending answer text and state are application-encrypted before storage while the minimum routing and authenticated-context metadata remain separate. Saved on this device — sync pending means the encrypted local transaction completed; it does not mean the change reached the server. Private browsing, clearing site data, browser storage eviction, device loss, or abrupt browser or operating-system termination can still lose unsynced text.
If durable browser storage is unavailable, Saved in this open page — sync pending means the encrypted queue remains in memory. This change is saved only in this open page and is waiting to sync; closing or reloading the page can lose it.
Editing, versions, and sharing
Ordinary editing and autosave do not create application edit history or a covert deletion record. An encrypted backup made earlier may temporarily retain an older working copy within the disclosed retention boundary. Typing, autosave, blur, navigation, deletion, and Save and continue do not create a keystroke log or a respondent-visible version.
Preserve this version creates a deliberate, visible checkpoint. Explicit conflict-preserve and sharing actions may also create versions or immutable generations.
Sharing creates an immutable generation while your working copy stays editable. Later edits do not rewrite that generation; updating what was shared creates another immutable generation after review.
Stopping access and sharing
Stopping sharing removes the active generation from normal review and export, but it cannot recall a copy already viewed or exported. It leaves the editable working copy and does not promise immediate deletion from retained records or encrypted backups.
Invitation expiry or revocation ends access; it does not by itself delete retained records or backups.
Private-page analytics and retention
The private journey page has no analytics, session replay, third-party fonts, social embeds, or respondent-data logging. This route-specific promise does not describe the public marketing site as a whole.
Backup inclusion, bounded maintenance, and a disposable restore canary have local synthetic proof. The live backup lifecycle, production key recovery, production restore, live maintenance schedule, and retirement of the older plaintext exporter remain unverified and inactive. Retention periods are not active promises until the backup lifecycle is verified.
Payments and processors
Payments are handled by Stripe. We receive confirmation that a payment succeeded, but we do not receive or store your full card number. Stripe's own privacy terms apply to the payment step.
Your rights
You can ask us at any time what we have, ask us to correct it, ask us to delete it, or ask us to export it. We respond within 48 hours. If we cannot fulfill a request because of a legal or fraud-prevention requirement, we will explain the reason.
Children
Thumbprint is intended for adults. We do not knowingly collect information from children under 13.
Changes
If we materially change this policy, we will update the date at the top of the page and keep the current version available from the site footer.
Contact
Email [email protected] for any privacy question or data request.