← AI Passport

Privacy Policy

Last updated: June 16, 2026 · Effective: June 16, 2026

1. Who We Are

AI Passport is operated by Nextera Consulting ("we," "us," or "our"), based in Chicago, Illinois, USA. We provide a structured context vault service for LLM workflows at ai-passport.nexteraconsult.com.

Data controller contact: consulting.nextera@gmail.com

2. Data We Collect

Account Data

Email address and hashed password, stored by Supabase. Optional display name in your user profile metadata.

Vault Content

Categories, items, and context you create. Stored encrypted at rest in Supabase (AES-256). You own this data entirely.

Usage Analytics (Optional)

Anonymized page views and feature events via PostHog. No personal identifiers are associated. Only collected if you accept cookies.

Billing Data

Processed entirely by Stripe. We store only your Stripe customer ID and subscription status — never card numbers or full payment details.

Technical Data

Server-side logs may include IP address, browser type, and request timestamps for security and debugging purposes. Logs are retained for 30 days. When an application error occurs, diagnostic data (error message, stack trace, and the page you were on) is sent to Sentry for monitoring; we configure Sentry to mask text and media in any captured session replays.

3. Zero-Training Guarantee

Your vault content is never used to train AI models — ours or any third party's. It is used solely to provide you the service as directed by you.

4. Legal Basis for Processing (GDPR)

For users in the EU/EEA, we process your personal data under the following legal bases:

  • Contract performance (Art. 6(1)(b)): Processing your account data and vault content to provide the service you signed up for.
  • Legitimate interests (Art. 6(1)(f)): Security logging, fraud prevention, and service improvement using anonymized analytics.
  • Consent (Art. 6(1)(a)): Analytics cookies — only if you explicitly accept via the cookie banner.
  • Legal obligation (Art. 6(1)(c)): Retaining billing records as required by applicable law.

5. Your Rights (GDPR / CCPA)

Depending on your location, you may have the following rights:

AccessRequest a copy of your personal data.
RectificationCorrect inaccurate data. Update your display name in Settings.
ErasureDelete your account and all data via Settings → Security → Terminate Account, or email us.
PortabilityExport your vault as JSON via Settings → Security → Export Vault.
ObjectionObject to processing based on legitimate interests.
RestrictionRequest we restrict processing while a complaint is resolved.
Opt-out (CCPA)We do not sell personal information. No opt-out is required.

To exercise any right, email consulting.nextera@gmail.com. We respond within 30 days.

6. Data Sharing

We do not sell your data. Sharing is limited to infrastructure providers necessary to operate the service:

ProviderPurposeLocation
SupabaseDatabase & authenticationUS (us-east-2)
StripePayment processingUS
VercelHosting & CDNUS/Global edge
PostHogProduct analytics (optional)US
SentryError monitoring & diagnosticsUS
ResendTransactional email deliveryUS

All providers are bound by data processing agreements. EU-to-US transfers rely on Standard Contractual Clauses (SCCs) where applicable.

7. Data Retention

  • Account and vault data: retained while your account is active.
  • Upon account deletion: all vault content, categories, items, and profile data are permanently deleted within 30 days.
  • Billing records: Stripe retains these per their legal and regulatory obligations (typically 7 years).
  • Server logs: deleted after 30 days.
  • Error monitoring data (Sentry): retained up to 90 days.
  • Analytics data: anonymized, retained indefinitely in aggregated form.

8. Cookies

We use essential authentication cookies and optional analytics cookies. See our Cookie Policy for details.

9. Children's Privacy

AI Passport is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has provided data, contact us and we will delete it.

10. Security

We implement industry-standard security measures including encryption at rest and in transit (TLS), row-level security on all database tables, and service-role key segregation. No system is 100% secure — please use a strong, unique password.

11. Changes to This Policy

We will notify registered users of material changes via email at least 14 days before they take effect. Continued use after notice constitutes acceptance.

12. Contact & Complaints

Nextera Consulting · Chicago, Illinois, USA · consulting.nextera@gmail.com

EU users may also lodge a complaint with their local data protection authority (DPA).