Privacy Policy
DRAFT - pending legal review. Not yet final.1. Our privacy approach
The Applied Studio is engineered so that we hold as little as possible. There are no individual user accounts, no login identities, and no server-side database of anything you type. Your organization profiles, tool inputs, and generated outputs belong to you and live on your device. Because we do not collect or control this content, you retain ownership and control of your inputs and outputs at all times.
This policy explains precisely what stays on your device, what transits our systems when you use an AI feature, and the one small record we keep to operate company-level access.
2. Where your work is stored
Everything you enter into the Studio - your organization profile, tool inputs (for example in the Disruption Compass, Task Force Charter, or Role Blueprint), and the outputs the Studio generates - is stored exclusively in your browser's local storage (localStorage) on your device.
- No central database. We do not operate a backend database of user session content. AI Mindset employees cannot view, access, or restore your inputs or outputs.
- Device- and browser-specific. Your work does not follow you to another browser or device unless you export it yourself.
- You control deletion. Clearing your browser data erases your Studio work entirely (see Section 8). Private/incognito windows discard it when the window closes.
3. The one thing we do hold
Access to the Studio is granted per client organization through a shared access code. To operate this, we keep one small record per client in our infrastructure (Cloudflare Workers KV):
- a one-way cryptographic hash (SHA-256) of the organization's access code, used to verify unlock attempts;
- an encrypted copy of the access code, so we can re-issue it to the client organization's administrator if it is mislaid;
- the organization's name; and
- an active/inactive flag, so a code can be switched off without affecting other clients.
This record contains no personal information about any individual, and nothing any user types into the Studio. When you enter an access code, it is transmitted to our verification endpoint, hashed, and checked; your browser then keeps only the hash locally so you are not asked again on that device.
4. AI processing
The Studio's generative features (including the Navigator) are powered by third-party large language models via Anthropic's Claude API, accessed through our own server-side relay.
- The path your text takes: when you use an AI feature, the relevant input is sent from your browser to our relay endpoint (on the same domain), which attaches our API credentials and forwards it to Anthropic's API. The response returns the same way.
- Transient processing: our relay does not log, store, or archive prompts or responses. The content is used solely to generate the immediate response.
- No model training: under Anthropic's commercial API terms, API inputs and outputs are not used to train Anthropic's models.
- Anthropic's retention: Anthropic retains API data for a limited period for trust-and-safety monitoring and then deletes it, as governed by its commercial terms and data policies: anthropic.com/legal/commercial-terms.
- Usage attribution: AI requests carry your organization's access-code hash so that aggregate usage (request counts and token volume) can be attributed per client organization for capacity and billing purposes. This attribution is at the organization level, never the individual level.
5. Hosting and infrastructure
The Studio is served by Cloudflare, Inc. As with any website host, Cloudflare maintains standard operational logs (such as IP addresses, timestamps, and URLs requested) as part of running and protecting the service. This is infrastructure-level metadata handled under Cloudflare's privacy policy; it is not content retention by AI Mindset.
6. Cookies, analytics, and trackers
- No analytics or telemetry scripts.
- No third-party trackers and no advertising technology.
- No tracking cookies. The Studio uses browser local storage only, for your own work and your device's access state.
- No third-party content on the page: fonts and scripts are self-hosted, so pages load only from our domain.
7. Guidance for regulated industries
Many Studio clients operate in regulated sectors. Because your work is stored locally and we retain no server-side copy, the Studio can generally be used within regulated departments - but what you choose to type is governed by your own organization's data-handling policies.
8. Deleting your data
- Your work: clear this site's data in your browser settings (or clear browsing data generally). This permanently deletes your Studio content from the device. We hold no copy to delete on our side.
- Your organization's access record: when a client relationship ends, the access record described in Section 3 is deactivated and deleted. You may request deletion at any time via the contact below.
9. Changes and contact
If we change how the Studio handles data, we will update this policy and revise the effective date above. Material changes will be flagged to client organizations directly.
Questions or requests: studio@ai-mindset.ai