Last updated: June 16, 2026 · Effective: June 16, 2026
AI Passport is operated by Nextera Consulting ("we," "us," or "our"), based in Chicago, Illinois, USA. We provide a structured context vault service for LLM workflows at ai-passport.nexteraconsult.com.
Data controller contact: consulting.nextera@gmail.com
Email address and hashed password, stored by Supabase. Optional display name in your user profile metadata.
Categories, items, and context you create. Stored encrypted at rest in Supabase (AES-256). You own this data entirely.
Anonymized page views and feature events via PostHog. No personal identifiers are associated. Only collected if you accept cookies.
Processed entirely by Stripe. We store only your Stripe customer ID and subscription status — never card numbers or full payment details.
Server-side logs may include IP address, browser type, and request timestamps for security and debugging purposes. Logs are retained for 30 days. When an application error occurs, diagnostic data (error message, stack trace, and the page you were on) is sent to Sentry for monitoring; we configure Sentry to mask text and media in any captured session replays.
Your vault content is never used to train AI models — ours or any third party's. It is used solely to provide you the service as directed by you.
For users in the EU/EEA, we process your personal data under the following legal bases:
Depending on your location, you may have the following rights:
To exercise any right, email consulting.nextera@gmail.com. We respond within 30 days.
We do not sell your data. Sharing is limited to infrastructure providers necessary to operate the service:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database & authentication | US (us-east-2) |
| Stripe | Payment processing | US |
| Vercel | Hosting & CDN | US/Global edge |
| PostHog | Product analytics (optional) | US |
| Sentry | Error monitoring & diagnostics | US |
| Resend | Transactional email delivery | US |
All providers are bound by data processing agreements. EU-to-US transfers rely on Standard Contractual Clauses (SCCs) where applicable.
We use essential authentication cookies and optional analytics cookies. See our Cookie Policy for details.
AI Passport is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has provided data, contact us and we will delete it.
We implement industry-standard security measures including encryption at rest and in transit (TLS), row-level security on all database tables, and service-role key segregation. No system is 100% secure — please use a strong, unique password.
We will notify registered users of material changes via email at least 14 days before they take effect. Continued use after notice constitutes acceptance.
Nextera Consulting · Chicago, Illinois, USA · consulting.nextera@gmail.com
EU users may also lodge a complaint with their local data protection authority (DPA).