Skip to main content

Privacy Policy

Factual summary of how this site handles personal data. This is not a substitute for a counsel-reviewed legal policy.

What we collect

  • Project intake — name, phone, email, project details, optional social links, and file uploads you submit on the start form.
  • Workspace identity — name, email, optional WhatsApp number, workspace membership, passkey credential IDs (not biometric images), recovery code hashes, and security audit events (including IP and user-agent when recorded).

Where data goes

  • Postgres (Supabase) — workspace users, memberships, enrollment tokens (hashed), devices, and audit logs.
  • Resend — intake submissions are emailed to our team (including attachments you upload).
  • WhatsApp — invite or device-approval messages are opened by you; we do not send WhatsApp messages from our servers.
  • Vercel Speed Insights — performance metrics only (not application form fields).

Cookies and passwords

Workspace auth uses platform passkeys (Face ID / Touch ID / Windows Hello). We do not collect account passwords. Session and workspace cookies are HttpOnly with Secure and SameSite settings appropriate to the deployment. Draft intake fields (excluding name, phone, and email) may be saved in browser storage to improve form UX; contact fields stay in memory until you submit.

Deleting your data

Signed-in workspace users can anonymize their account from Settings → Security → Delete my account data. That clears personal identifiers on your user record, removes passkeys and sessions, and nulls membership phone numbers. It does not delete entire workspaces or other members’ data. For intake or other requests, email talk@aioniqlabs.com.