Skip to content

Draft — under legal review

This document is published in draft so that our actual data practices are on the record and can be checked. It has not yet been reviewed by counsel and is not a contract. Where it is silent or unclear, ask us and we will answer plainly.

Privacy Policy

Last updated 2 September 2026

Who is responsible for your data

The data controller is dotPerson PBC (a working name; the entity is in formation). Mind Hack, Inc., a Delaware corporation, acts as our agent and as reseller-of-record for payments, which means it is the merchant on your card statement and the counterparty for the payment transaction itself.

What we collect

Three things, and nothing beyond them:

  • Account data. Your email address and the GitHub account you sign in with, plus the identifiers Firebase Authentication needs to keep you signed in. If you join the waitlist, we hold the email address you gave us and where on the site you gave it.
  • Captures you enable. The browser extension captures conversations only on the surfaces you switch on in its popup, and sends them to our relay. The IDE observers do the same for the editors you have wired up, once you have signed in. Every surface starts off.
  • Corpus events you mirror. Your corpus lives in a SQLite database on your own machine. Only events flagged as mirrorable by the harvester that wrote them are pushed to us — git activity, plans, sessions and your reading list. Config snapshots, screenshots and anything imported from a ChatGPT archive are never pushed.

Your persona file lives in a GitHub repository under your own account. Your Ed25519 signing key is generated on your machine and never transmitted to us.

Who processes it

Processor What it does Where
Google Cloud Cloud Run (the relay), Cloud SQL (Postgres), Firebase Authentication United States
Google Vertex AI Persona synthesis — inference over captured observations to propose persona updates. Not model training. United States
GitHub Hosting of your persona repository, and the GitHub App that brokers access to it United States
WooCommerce / WooPayments, via Groundcraft Payment processing and subscription billing United States

We do not train models on your conversations, and we do not sell your data to anyone.

Security

Being precise rather than reassuring: data in transit is protected by TLS, and the relay's database sits behind authenticated access controls. Your persona is cryptographically signed with your own Ed25519 key, which proves it has not been tampered with — signing is not encryption, and we do not claim your persona is encrypted at rest. On your own machine, your corpus and keys are protected by ordinary file permissions, so the security of your user account is what protects them.

How long we keep it

Account data is kept while your account exists. Captures and mirrored corpus events are kept until you delete them or close your account — they are the product's memory, so we do not expire them on a timer. Waitlist emails are kept until the founding-member programme closes or you ask us to remove you, whichever comes first. Backups may hold copies for a short period after deletion before they age out.

Your rights

  • Access. Ask us what we hold about you and we will tell you.
  • Export. Run personkit export to take your whole corpus as Obsidian-ready markdown, any time, without asking us. Your persona is already a file in your own repository.
  • Deletion. On request, by email. We are building a self-service deletion endpoint; until it ships, deletion is a request we action by hand, and we would rather say so than imply a button exists.
  • Withdrawal. Turn off any capture surface in the extension popup, or stop the daemon, and we stop receiving new data immediately.

International transfers

Our infrastructure is hosted in the United States. If you use aiperson from outside the US, your data is transferred there. We have not yet appointed EU or UK representatives, and we will appoint them before we market to the EEA — we would rather state that plainly than imply a compliance posture we have not established.

Contact

Questions, requests, or a correction to this draft: ht@humphreytheodore.com .

For the engineering-level detail of what stays local and what is mirrored, see the privacy documentation.