Privacy Policy — AI Strategy Academy Community Platform
Version: 2026-08-17 · Effective: August 17, 2026 · Last updated: August 17, 2026
1. The short version
- We collect what we need to run the platform and not much else: who you are, what you bought, what you post, and how you use the product.
- We do not sell your personal information, and we do not share it with advertisers.
- We never see your full card number. Stripe handles payments.
- Our analytics are first-party. We do not run third-party advertising or tracking pixels inside the member platform.
- Your private messages are private. We do not read them as a routine practice. A reported message can be reviewed by an authorized moderator so we can act on the report.
- If you connect your own accounts to an AI agent, that data flows through systems you chose to connect. You control what you connect and can disconnect it.
- You can ask for a copy of your data or ask us to delete it by emailing support@hatch-capital.com.
The rest of this document is the detail.
2. Who we are
The AI Strategy Academy Community Platform (the “Platform”) is operated by Hatch Capital Consulting, LLC (“we,” “us,” “our”), a limited liability company organized under the laws of the State of Georgia, USA; business mailing address available on written request to support@hatch-capital.com.
We are the controller of the personal information described in this policy — meaning we decide what is collected and why.
This policy covers community.hatch-capital.com, portal.hatch-capital.com, and the relevant pages of hatch-capital.com, the member platform, our AI agents, and the emails we send you. It does not cover third-party services you connect yourself, or other websites we link to.
We are based in the United States and our systems are operated in the United States. Our database and file storage are hosted in the United States (AWS us-east-1, via Supabase). Our web infrastructure runs on Cloudflare’s global network, which serves content from locations near you.
3. What we collect
3.1 Information you give us
| Category | Examples | Why we have it |
|---|---|---|
| Account information | First name, last name, email address, password (stored only as a cryptographic hash — we never see it) | To create and secure your account |
| Profile information | Display name, handle, avatar, bio, and anything else you choose to add | To show you to the community |
| Onboarding information | What you told us about your business, goals, and role during onboarding | To personalize the program and route you to relevant content |
| Community content | Posts, comments, replies, reactions, uploads, and direct messages you send | To operate the community |
| Agent instructions | Prompts, questions, tasks, and configuration you give an AI agent | To run the agent for you |
| Support requests | Anything you send to support, including attachments | To help you |
| Payment information | Billing name, billing email, and the last four digits, brand, and expiry of your card — as reported back to us by Stripe. We never receive or store your full card number. | To manage your purchase and subscription |
3.2 Information we generate or collect automatically
| Category | Examples | Why we have it |
|---|---|---|
| Entitlement and billing state | Which programs you bought, subscription status, renewal dates, whether a payment succeeded, failed, was refunded, or was disputed | To know what you have access to |
| Progress data | Lessons viewed and modules completed | To show your progress and run the program |
| Product analytics | Which screens you opened, which features you used, timestamps, and the coarse context of an action | To understand what works and fix what does not |
| Technical and log data | IP address, browser and device type, referring page, request timestamps, error and security logs | To operate, secure, and debug the Platform |
| Email delivery data | Whether an email was delivered, bounced, or was marked as spam, and whether it was opened and its links clicked (our email provider records opens and link clicks) | To make sure our email reaches you |
| Attribution data | How you arrived — referral source and campaign parameters in the link you clicked | To understand which channels bring members |
Our analytics store rejects personal information at the database level. Event properties whose keys or values look like personal information — names, email addresses, physical addresses — are refused by database constraints before they can be stored. (Verified live in production, 2026-08-17.)
3.3 Information from third parties
- Stripe tells us the outcome of your payments, your subscription status, and limited card metadata.
- Contact records are synchronized with our customer-relationship system, and historical contact records from our prior marketing system may be matched to your account by email address.
3.4 What we do not collect
We do not knowingly collect: government identification numbers, financial account numbers, precise geolocation, biometric data, or special-category data (health, race, religion, sexual orientation, political opinion, union membership). Please do not post such information in the community or send it to an agent.
4. How we use your information
We use personal information to:
- Provide the Services — create your account, authenticate you, show you the community, unlock what you bought, deliver lessons and resources, and route your direct messages.
- Provision and run AI agents for members whose program includes one.
- Process payments and manage subscriptions, renewals, receipts, and failed payments.
- Communicate with you — verification and password emails, billing notices, program announcements, call reminders, digests, and support replies.
- Support you — investigate and resolve problems you report.
- Keep the Platform safe — detect and prevent fraud, abuse, spam, and unauthorized access, and enforce our Terms and community rules.
- Improve the product — understand which features are used and where members get stuck.
- Comply with law — tax, accounting, and legal obligations, and responding to lawful requests.
- Market to you — send you news and offers about our programs, where permitted. You can unsubscribe from marketing at any time; that does not stop transactional and account messages.
4.1 What we do not do
- We do not sell your personal information.
- We do not share your personal information with third parties for their own advertising or for cross-context behavioral advertising.
- We do not use your private messages or your business information to train third-party AI models. Our AI providers’ commercial API terms provide that API inputs and outputs are not used to train their models.
- We do not run third-party advertising or tracking pixels inside the member platform. Our public marketing landing page does carry a Meta (Facebook) pixel for ad measurement — that page is outside the member platform, and member content never appears on it.
5. AI agents and connected accounts
This section exists because we do something most course platforms do not: we run software on your behalf.
5.1 What happens when you use an agent
Your prompts, instructions, and the context an agent needs are sent to an AI model provider (see Section 8) to generate a response. Conversations with an agent are stored so the agent has memory and so you can see your own history.
5.2 Connected accounts
You choose which of your own accounts, tools, and data to connect to an agent. We do not require any particular connection, and you can disconnect at any time.
When you connect an account:
- the agent can read from and write to that account within the scope of the access you granted;
- data flows out of our Platform into the systems you connected, and that data is then governed by those providers’ own privacy policies; and
- where we hold a credential for a connected account, it is stored under the safeguards in Section 11.
Disconnecting stops future access. It does not retroactively remove data an agent already placed in a third-party system, and it does not delete anything from that provider. Revoke the credential on the provider’s side as well if you want to be certain.
5.3 Agent activity is logged
We keep records of significant agent actions so that behavior is auditable and problems can be investigated. These logs are treated like other operational logs (Sections 9 and 10).
6. Community content and who can see it
Assume that what you post in the community is visible to other members. Some spaces are open to every member; some are limited by what you bought. Your name, handle, avatar, and profile are visible to other members.
Direct messages are visible to you and the person you sent them to.
Moderation access is limited and purposeful. We do not read private messages as a routine practice. Where a message is reported, an authorized moderator may review the reported exchange in order to act on the report. Access is scoped and recorded.
Search engines. Community content sits behind authentication and is not publicly indexable. Our public marketing pages are indexable; your member content does not appear on them. If this ever changes, this section will change with it.
7. Cookies and similar technologies
We keep this minimal and first-party.
| What | Purpose | Can you refuse it? |
|---|---|---|
| Authentication / session storage | Keeps you signed in. Set by us and by our authentication provider. | No — without it you cannot sign in |
| Preference storage | Remembers small choices, like a dismissed banner | Yes, but the Platform will forget those choices |
| First-party analytics | Distinguishes one session from another so usage counts are meaningful | It is first-party only. There is no separate in-product toggle today; you can refuse it by blocking browser storage (the Platform still works) |
We do not use third-party advertising cookies, retargeting pixels, or cross-site trackers inside the member platform. Our public marketing landing page carries a Meta (Facebook) pixel for ad measurement; the member platform does not.
You can block or clear browser storage at any time through your browser settings; doing so will sign you out.
8. Who we share information with
We share personal information with service providers who process it on our behalf, under contract, and only to provide services to us. We do not sell it and we do not share it for others’ advertising.
| Provider | What it does for us | What it receives |
|---|---|---|
| Stripe | Payment processing, subscription billing | Your name, email, and payment details (card details go directly to Stripe — they do not pass through our systems) |
| Supabase | Database, authentication, and file storage | Account, profile, community content, progress, and entitlement data |
| Cloudflare | Website hosting, serverless functions, CDN, and security | Technical and request data, including IP address |
| Postmark | Transactional email delivery | Your email address and the contents of the emails we send you |
| Anthropic | Powers the in-community assistant and agents | Your prompts and the context needed to answer them |
| Orgo | Hosts managed agent environments | Data your agent processes in its environment |
| Attio | Contact and relationship management | Name, email, and membership/purchase status |
We also share information:
- With other members — the parts of your profile and content that the Platform is designed to show them (Section 6).
- For legal reasons — to comply with law, a subpoena, or a lawful request; to enforce our Terms; or to protect the rights, safety, or property of us, our members, or the public.
- In a business transfer — if we are involved in a merger, acquisition, financing, or sale of assets, information may transfer as part of that transaction. We will tell you if your information becomes subject to a materially different privacy policy.
- With your permission — for anything else.
9. How long we keep things
| Data | Retention |
|---|---|
| Account and profile | While your account exists, plus up to 60 days after closure |
| Community posts and comments | Kept for the continuity of the community with attribution anonymized on request; see Section 10 for full removal requests |
| Direct messages | While your account exists. Per-message deletion is not currently offered; contact support to request removal |
| Agent conversations | While your account exists |
| Payment and transaction records | As long as required by tax and accounting law — typically 7 years |
| Support requests | 3 years after the request closes |
| Technical and security logs | Up to 90 days |
| Product analytics | 24 months |
| Backups | Deleted data persists in backups for up to 35 days before it ages out |
We keep information longer where we must — to comply with law, resolve disputes, or enforce our agreements.
10. Your rights and choices
Whatever regime applies to you, we offer these to every member. Email support@hatch-capital.com and we will handle it.
- Access — get a copy of the personal information we hold about you.
- Correct — fix anything inaccurate. Most of it you can edit yourself in your account settings.
- Delete — ask us to delete your account and personal information. We will delete what we can and tell you plainly what we must keep and why (for example, payment records we are legally required to retain). Community content is handled per Section 6 and Section 9.
- Unsubscribe — opt out of marketing email using the link in any marketing message, or by asking us.
- Notification preferences — control which platform notifications reach you by email.
- Object or restrict — ask us to stop or limit a particular use.
- Portability — receive your information in a portable format where applicable.
- Complain — to us first, please. You may also complain to your local data protection authority if you are in a jurisdiction that provides one.
How we respond: we will verify your identity (usually by confirming control of the account email) and respond within 30 days (or any shorter period your local law requires). We do not charge for this and we will not discriminate against you for exercising a right.
Authorized agents. You may use an authorized agent to submit a request where the law allows; we will ask for proof of authorization.
11. How we protect information
We take security seriously, and the Platform is built with specific safeguards:
- Encryption in transit for all traffic, and encryption at rest for stored data.
- Least-privilege access. Each part of the system runs with its own narrowly-scoped credential rather than a shared master key, so a compromise in one place does not open everything.
- Row-level authorization in the database, so entitlement checks are enforced at the data layer rather than only in application code.
- Passwords are never stored in readable form.
- Access to member data by our team is limited to what a task requires, and administrative actions are logged.
- We never receive your full card number — Stripe handles it.
No system is perfectly secure. If a breach affecting your personal information occurs, we will notify you and any required authority as the law requires.
12. Legal bases for processing (if you are in the EEA or UK)
If GDPR/UK GDPR applies, we rely on: contract (providing the Services you bought), legitimate interests (securing the Platform, preventing fraud, understanding product usage), consent (marketing email, non-essential analytics), and legal obligation (tax and accounting records).
13. International users and transfers
We are based in the United States and our systems operate in the United States. If you use the Platform from outside the U.S., your information is transferred to and processed in the U.S., where privacy laws differ from those in your country.
14. Children
The Platform is for adults. You must be 18 or older to use it. We do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it and close the account. If you believe a minor has given us information, contact support@hatch-capital.com.
15. State-specific disclosures (United States)
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act (as amended) and comparable state privacy laws. If you live in a state with a comprehensive privacy law, you can exercise the rights described in Section 10 — access, correction, deletion, and portability — by emailing support@hatch-capital.com; we do not discriminate against you for doing so.
16. Changes to this policy
We may update this policy. The version string and effective date are at the top, and prior versions are available on request from support@hatch-capital.com.
If we make a material change — for example, collecting a new category of information, using it for a materially new purpose, or adding a processor that changes where your data goes — we will notify you by email to your account address, in the Platform, or both, before it takes effect.
Continuing to use the Platform after the effective date means you accept the updated policy.
17. Contact us
Hatch Capital Consulting, LLC Privacy and data requests: support@hatch-capital.com Mailing address available on written request.
End of Privacy Policy — version 2026-08-17.
