Privacy Policy

DRAFT - pending legal review. Not yet final.

AI Mindset Applied Studio · Effective date: [EFFECTIVE DATE] · Operated by [LEGAL ENTITY NAME] ("AI Mindset", "we", "us")

1. Our privacy approach

The Applied Studio is engineered so that we hold as little as possible. There are no individual user accounts, no login identities, and no server-side database of anything you type. Your organization profiles, tool inputs, and generated outputs belong to you and live on your device. Because we do not collect or control this content, you retain ownership and control of your inputs and outputs at all times.

This policy explains precisely what stays on your device, what transits our systems when you use an AI feature, and the one small record we keep to operate company-level access.

2. Where your work is stored

Everything you enter into the Studio - your organization profile, tool inputs (for example in the Disruption Compass, Task Force Charter, or Role Blueprint), and the outputs the Studio generates - is stored exclusively in your browser's local storage (localStorage) on your device.

Practical consequence: because we hold no copy, we cannot recover work lost to a cleared cache, a reset browser, or a changed device. The Studio's export features (such as the Markdown report download) are your backup mechanism.

3. The one thing we do hold

Access to the Studio is granted per client organization through a shared access code. To operate this, we keep one small record per client in our infrastructure (Cloudflare Workers KV):

This record contains no personal information about any individual, and nothing any user types into the Studio. When you enter an access code, it is transmitted to our verification endpoint, hashed, and checked; your browser then keeps only the hash locally so you are not asked again on that device.

4. AI processing

The Studio's generative features (including the Navigator) are powered by third-party large language models via Anthropic's Claude API, accessed through our own server-side relay.

5. Hosting and infrastructure

The Studio is served by Cloudflare, Inc. As with any website host, Cloudflare maintains standard operational logs (such as IP addresses, timestamps, and URLs requested) as part of running and protecting the service. This is infrastructure-level metadata handled under Cloudflare's privacy policy; it is not content retention by AI Mindset.

6. Cookies, analytics, and trackers

7. Guidance for regulated industries

Many Studio clients operate in regulated sectors. Because your work is stored locally and we retain no server-side copy, the Studio can generally be used within regulated departments - but what you choose to type is governed by your own organization's data-handling policies.

Please do not input Protected Health Information (PHI), Nonpublic Personal Information (NPPI), personally identifiable financial information subject to GLBA, or equivalent regulated data, unless your organization's internal policies explicitly permit submitting such data to third-party AI services. Text you enter into AI features is transmitted (transiently) to our relay and to Anthropic to generate your response, as described in Section 4.

8. Deleting your data

9. Changes and contact

If we change how the Studio handles data, we will update this policy and revise the effective date above. Material changes will be flagged to client organizations directly.

Questions or requests: studio@ai-mindset.ai