Menu
EN

PRE-LAUNCH · PRIVACY

Privacy notice

This is a technical pre-launch notice. Controller identity and privacy contact must be configured, and the complete notice must be legally reviewed before public launch.

This page describes what the current guideguIA implementation actually stores or sends. It intentionally avoids claims that are not yet supported by the product or its legal setup.

Controller and privacy contact

Controller details are not configured in this pre-launch build.

Account and authentication data

If you create an account, authentication is handled through Supabase Auth. The application can store your email address, display name and preferred language. Social sign-in can involve the OAuth provider you choose.

AI Consultant data

The Consultant stores the answers needed to analyse a project and generate a result. Guest consultations use a temporary access token so the same consultation can be resumed safely. When you sign in, the active guest consultation can be securely associated with your account using that temporary token; after a successful association, the guest token is revoked.

Email preferences

Marketing email is optional. The current implementation records whether you opted in or withdrew consent. Creating an account does not automatically opt you in.

Browser storage

For guest continuity, the browser keeps a consultation identifier and temporary guest access token in local storage. Its local expiry mirrors the server's rolling guest-access window (currently renewed to at most 7 days after successful use) and never extends beyond the 30-day maximum retention from creation. The project summary used for the Consultant-to-Prompt-Builder handoff is kept only in session storage for the current browser tab. Prompt Builder round-trip drafts and recommendation handoffs also use one-time, tab-scoped session entries that are removed after they are consumed. Legacy locally stored project summaries are migrated out of persistent storage when detected. These values support the product flow and are not a substitute for account authentication.

Security and operational records

The service keeps limited request and operational records used for rate limiting, idempotency, monitoring, troubleshooting and security. When a guest starts a Consultant session, the production anti-abuse layer can process the request IP address at the edge and derive a keyed pseudonymous rate-limit identifier; the raw IP is not written to the guideguIA application tables by that flow. Internal monitoring systems are not exposed directly to public users.

Service providers

The current implementation uses Supabase for database, authentication and Edge Function infrastructure. Guest-start anti-abuse verification is designed to use Cloudflare Turnstile; the browser receives a public challenge and the server sends the Turnstile token and request IP to Cloudflare for verification. If you choose a social login provider, that provider also processes the authentication request under its own terms. Additional production providers must be documented here before launch.

Technical retention currently enforced

Guest consultations expire no later than 30 days after creation and are cleaned by a daily retention job. Consultant request logs older than 30 days are deleted by the same cleanup process. Data tied to a signed-in account remains associated with that account until the relevant consultation or the account is deleted under the current product controls.

Your choices and rights

You can change your optional email preference in your account, delete the current Consultant consultation from its result screen, and permanently delete your account from the account page after confirming the account email. Account deletion removes the Auth user and guideguIA data linked to that user through the current database relationships. Broader data-request flows, the controller contact and the applicable rights must still be completed before public launch.