Privacy Policy
- Version
- 1.1
- Effective
- Cited as
- legal:privacy-policy@1.1
mAInCharacter Advisory LLC ("we") runs this site, the booking flow, the client portal, and the desktop application a consultant uses during a session. This policy says what personal data each of those holds, why, who else sees it, and how long it stays.
Two companion documents carry the detail this one summarises: the subprocessor list names every third party and what it receives, and the data-handling statement describes what the architecture actually enforces. Where they are more specific than this page, they are the ones to read.
Who is responsible
mAInCharacter Advisory LLC is the controller of the personal data described here. Questions, and requests to see or delete what we hold, go to hello@main-character.me.
Reading the public site
The public pages set no cookies. They store a small number of display preferences — whether you muted a sound, which panel you last opened — in your own browser's local storage, where they stay on your machine and are never sent to us.
No analytics is running. The pages carry a Google Analytics loader that activates only when a measurement ID is configured, and none is; if that ever changes, this policy changes first and the subprocessor list says so.
Because the site is hosted on Vercel, ordinary web-server information — your IP address, the page you requested, your user agent — passes through their infrastructure in the course of serving the request.
Booking a call
The booking form asks for your name, your email address, your time zone, and optionally a phone number, guest email addresses, and a short note about what you would like to discuss.
Please keep the note to context, not to detail. It is a note about a meeting, not a medical or financial record, and we ask you not to put health, financial, or otherwise sensitive information into it. Nothing else on the public site asks for such information, and no public form is capable of collecting it.
- Why: to hold the slot, send you a confirmation and a calendar invitation, and let you reschedule or cancel through a link only you have.
- Basis: taking steps at your request before entering into a contract.
- Who sees it: our mail provider, in order to send the confirmation.
- How long: the booking record persists as the start of your case file. If nothing comes of it, ask and we will delete it.
The booking form carries an abuse challenge, which sends a token and your IP address to Cloudflare and nothing else. Bookings are also rate-limited, which means we keep a short-lived record of request activity in order to enforce the limit.
Signing in
Your account exists so that only you can read your own material. We hold your
email address, your role, and the session cookie that keeps you signed in.
Signed-in pages are marked not to be indexed and are disallowed in
robots.txt.
Working with you
This is the substantial part, and the data-handling statement covers it in full. In summary:
Recordings. Sessions are recorded and transcribed on your consultant's own machine. Audio never reaches this platform — the platform's device interface will not accept it — and the recording is deleted from that machine and the deletion verified. What the platform receives is text.
Transcripts and notes. Identifying details are replaced with consistent stand-ins before session material becomes durable case data. The map back to the real details is held on our servers, encrypted per case, and is never sent to a device. You can read your own transcripts in your portal.
Documents you upload. Stored in a private bucket, reachable only through short-lived signed links, never served from the public web. Word, Markdown and plain-text files are read on our own server. A PDF must be read by an outside model to become text at all, which is a crossing we do not paper over: it requires a named consultant to grant permission on that one document with a stated reason, the permission is audited, and the result stays consultant-visible until it has been de-identified.
Basis. Performing our contract with you for the engagement itself; your consent for recording and AI processing, and separately for any use of anonymised material; and our legitimate interest in keeping a working record of work we did together, for the limited retention period described below.
Consent, and withdrawing it
Consent for recording and AI processing is captured in your portal against a specific, versioned document, and you can withdraw it there at any time without giving a reason.
Withdrawal is per category and takes effect immediately: your material closes, nothing further is taken in or lent into another engagement's preparation, and the platform stops drawing on what it already holds. Withdrawal is not retroactive — work already done while your consent stood is not unmade.
The data-handling statement reproduces the consent wording in full.
How long we keep things
| What | How long |
|---|---|
| Audio | Never kept. Deleted on the consultant's machine; never reaches the platform. |
| Transcripts and notes | For the life of your engagement. After withdrawal of consent, use stops immediately and the stored copy is kept for twelve months from the date it entered durable storage, then permanently deleted. |
| Your consent history | Permanently, including through a deletion request. It is the record of what was agreed and withdrawn, and when, and it holds the email address that agreed along with the IP address and browser it came from. |
| Our administrative audit trail | Permanently, including through a deletion request. It records who did what and when, and it holds the staff email address that acted along with before-and-after copies of the rows they changed. |
| The record that a deletion happened | Permanently. The case reference, the name it was filed under, who deleted it, when, why, and how many rows went — counts, never content. |
| Uploaded documents | For the life of your engagement, or until you ask for them to go. |
| Booking records | As the start of your case file; deleted on request if no engagement follows. |
| Quarantined session material not yet promoted | Until its expiry, after which a scheduled sweep removes it and verifies the removal. |
If you want stored material deleted sooner than the periods above, ask and we will handle it.
Who else sees your data
Only the parties named in the subprocessor list, which is complete and states what each one receives. We do not sell personal data, we do not share it with advertisers, and we do not use client material to train anyone's models.
Our providers operate internationally, so data may be processed outside your own country. Ask and we will tell you where your material is stored.
How it is protected
- Session material waiting on a consultant's machine is encrypted with AES-256-GCM under a key held in the operating system's credential store, and the application refuses to write client material at all if that key is unavailable.
- Every table is governed by row-level security, so a mistake in one page cannot expose another person's case.
- The public surface and the signed-in application are separated by route group and by data access: no public page reads any table holding client or session data, and none holds a privileged credential.
- Uploaded files are type-checked, size-capped, and stored privately.
- Deletions are verified rather than assumed.
The data-handling statement also names the places where these protections deliberately do not apply — an Obsidian export to a folder you chose, a short audio export window — because a security summary with unnamed exceptions is not worth reading.
Your rights
You can ask us to give you a copy of what we hold about you, correct it, delete it, restrict what we do with it, or object to processing based on legitimate interest. You can withdraw consent at any time. Depending on where you live, you may also have the right to complain to a data protection authority.
Write to hello@main-character.me. We will not ask you for a reason.
What a deletion reaches, and what it keeps
Deleting your case removes your case material: the transcripts and the notes drawn from them, the evidence and cues built out of them, the documents you uploaded and the text extracted from them, the map that could turn a stand-in back into your name, and the bookings attached to the engagement. It is proved rather than assumed — the database re-reads itself afterwards looking for anything left belonging to that case, and if a single row is still standing the whole deletion is undone rather than reported as a success. Your files are removed in a second step, and the deletion is not marked finished until something has re-read the storage bucket and found nothing there.
Three records are deliberately kept, and we would rather state that here than let you discover it:
- Your consent history. It is the record of what you agreed to, against which version of which document, and when — including the agreement that made it lawful for us to hold the material just deleted. Destroying it alongside the material would remove the evidence that we were entitled to hold it.
- Our administrative audit trail. It is what makes it possible to show who did what to your case, and the deletion is the entry in it we would least want to be missing.
- The record that the deletion happened. A deletion that leaves no trace cannot be shown to have taken place.
All three refuse to be edited or deleted at the database level, by a rule the application has no way to switch off. That refusal is not a side effect of the retention; it is the reason for it. A ledger that can be rewritten one entry at a time is not evidence of anything. The same rule means a correction cannot be applied inside them either — a correction is recorded as a new entry rather than by altering an old one.
The counterweight is disclosure. If you ask for a copy of what we hold, all three are included in full, so what is retained is at least something you can read. And one thing a per-case deletion does not sweep up by itself: a booking that never became an engagement belongs to no case, so deleting a case does not find it. Those are located by your email address instead — they are listed before a deletion runs so they are not missed, and they appear in your export.
If you think your circumstances mean one of the retained records should go anyway, say so and we will give you an answer rather than point at this page.
Children
The platform is for working professionals. It is not directed at children and we do not knowingly collect their data.
Changes
Changing this policy means editing a file in a repository, which means a commit, a review, and a new version number at the top of this page. There is no administrative screen that can quietly change it. Where a change materially affects what you agreed to, the consent flow will ask you again rather than assume.