Privacy Policy

Effective: 2026-05-10 · Last Updated: 2026-05-10

Contents
  1. Information We Collect
  2. How We Use Your Information
  3. Sharing With Third Parties
  4. Data Security
  5. Your Rights
  6. Data Retention & Deletion
  7. Children's Privacy
  8. International Users & Geo-Blocking
  9. Changes to This Policy
  10. Contact

The Inner Circle ("we", "us", "our") operates joininnercircle.net (the "Service"). This Privacy Policy describes how we collect, use, share, and protect your personal information.

By accessing or using the Service, you agree to the collection and use of information in accordance with this policy.

1. Information We Collect

1.1 Information you provide directly

CategoryWhen collectedPurpose
Email addressSignup, magic-link auth, supportAccount identity, member communication, magic-link delivery
Full nameStripe CheckoutReceipt, member display, support
Payment information (card last 4, brand, country)Stripe CheckoutTokenized via Stripe — we never see or store full card numbers
Onboarding intake (7 questions)First-time loginPersonalize the GameBoy AI drafting tool. Stored only in your member profile, scoped to your user ID via Postgres Row-Level Security.
Community messagesWhen you postVisible to other paid members of your tier.
Quiz answers (per module)When you submit a quizTrack which modules you've passed. We do not analyze quiz answers for any purpose other than pass/fail unlocking.
GameBoy drafting inputPer drafting requestSent to our AI provider to generate reply drafts. Audit-logged for 30 days, then auto-purged. We do not use your inputs to train any AI model.

1.2 Information collected automatically

CategoryPurpose
IP address (truncated within 7 days)Abuse detection, rate limiting. Not associated with member identity beyond the 7-day window.
User-agent stringBrowser/device debugging.
Cloudflare bot management cookie (__cf_bm)Set by Cloudflare. Required for Service operation.
Supabase auth tokenHolds your session JWT (1h expiry, auto-refreshed). Cleared on sign-out.
UI preference cookiesSuppress repeat-prompt UI. Domain-scoped, expire automatically.

1.3 Information we do NOT collect

2. How We Use Your Information

3. Sharing With Third Parties

We share your data only with these processors, only for the purposes listed:

ProcessorData sharedPurpose
StripeEmail, name, billing address, card tokenPayment processing, refunds, chargeback defense
SupabaseAll Service dataDatabase, auth, Realtime chat
Cloudflare (Pages + Workers)Request metadata, JWT in transitApplication hosting, KV cache, edge cache
ResendEmail address, email bodyTransactional email delivery
OpenRouter / Anthropic / GoogleGameBoy drafting input, system promptAI reply generation. Our AI providers are contractually committed not to train on API inputs.
Cloudflare StreamVideo playback metadataTier-gated video streaming

We do not share your data with advertising networks, data brokers, or third-party analytics providers.

4. Data Security

If a breach affects your data, we will notify you within 72 hours of confirmation by email to your account email.

5. Your Rights

Depending on your residence, you may have the following rights:

RightHow to exercise
Access — request a copy of your dataEmail welcome@joininnercircle.net with subject "data access request"
Correction — fix inaccurate dataEdit profile via the Member Area, or email us
Deletion — request your data be erasedEmail with subject "deletion request". See §6 for what gets deleted vs. retained for legal compliance.
Portability — receive your data in a machine-readable formatEmail request; we deliver JSON within 30 days
Opt-out of marketing emailsClick unsubscribe in any non-transactional email. Transactional emails (receipts, expiry notices) cannot be opted out of while you are an active member.

We respond to verified requests within 30 days.

6. Data Retention & Deletion

7. Children's Privacy

The Service is not directed to and may not be used by anyone under 18. We do not knowingly collect personal information from anyone under 18. If we learn we have collected data from a person under 18, we will delete it promptly. The Service requires you to confirm you are 18+ during onboarding.

8. International Users & Geo-Blocking

The Service is currently not available to residents of the European Union, United Kingdom, Switzerland, or other countries with comparable data-protection regimes (GDPR, UK GDPR, Swiss FADP).

If you are outside the US, your data is stored on infrastructure with US data centers as primary. By using the Service, you consent to the transfer of your data to the US.

9. Changes to This Policy

We will notify you by email at least 30 days before any material change to this Privacy Policy takes effect. Continued use of the Service after the effective date constitutes acceptance.

10. Contact

The Inner Circle
welcome@joininnercircle.net

This Privacy Policy is current as of the date above. We are continuing to refine it with legal counsel; substantive changes will be emailed to active members at least 30 days before they take effect. Questions about this policy can be sent to the email address above.