Privacy Policy
What we collect, why we collect it, who else touches it, and how to make us delete it.
Effective 3 August 2026. Last updated 3 August 2026.
The short version
- We collect your email address, and the tools you ask us to watch.
- Your address is stored encrypted, and your record is filed under a fingerprint of it rather than the address itself — a stolen copy of our database does not say who you are.
- We never see your card. Our payment provider handles that.
- We do not sell or share your personal information. Ever.
- Site analytics are cookieless and anonymous — no session recording, no advertising network, no cross-site tracking, no consent banner needed.
- Email [email protected] and we will delete everything we hold about you.
Who is responsible
Jon Schipp, a sole proprietor in Florida, United States, doing business as The AI Toolchain, is the data controller. Contact: [email protected].
What we collect
If you subscribe
- Your email address — so we can send you the thing you asked for.
- Which newsletters you want, and which tools or categories you filter to — this is the product; without it Grep cannot work.
- Delivery records — which issue went to you and when, so a retried job cannot send you the same issue twice.
- Sign-in tokens — a short-lived, single-use hash, deleted automatically after fifteen minutes.
If you pay
Payment is handled by Paddle, which acts as the Merchant of Record. Your card details never reach our systems. We receive from Paddle only what we need to know you are entitled to what you bought: a customer reference, which plan, its status, and when the period ends.
If you just visit the site
We use PostHog for basic traffic analytics, configured deliberately narrowly: page views only, no autocapture of clicks or form contents, no session recording, and state kept in your browser’s local storage rather than in a cookie. It records a random identifier, the page, referrer, approximate location derived from IP, and browser type. We do not use advertising or cross-site tracking of any kind, which is why this site has no consent banner.
The site is hosted on GitHub Pages, which keeps its own server logs including IP addresses, under GitHub’s privacy policy rather than ours.
Why we are allowed to (legal bases)
- Consent — sending you a newsletter you signed up for. Withdraw it by unsubscribing; every email has a one-click link.
- Contract — delivering and billing a paid subscription.
- Legitimate interests — anonymous traffic analytics, preventing abuse, and keeping the service secure and working.
- Legal obligation — tax and accounting records for a sale.
Who else processes your data
- Paddle — payments, invoicing and tax, as Merchant of Record.
- Resend — sends the email, and records deliveries, bounces and complaints.
- Amazon Web Services (US East, Ohio) — stores subscriber records and preferences.
- PostHog (United States) — anonymous site analytics.
- GitHub Pages — hosts the website.
- Anthropic — summarises public release notes. Your personal data is never sent to it; it only ever sees vendors’ published material.
Each is a processor acting on our instructions. We do not sell personal information, and we do not share it for cross-context behavioural advertising — under the CCPA or any other law.
Where it lives
Our systems run in the United States. If you are in the EU, the UK, or elsewhere outside the US, your data is transferred there, protected by the standard contractual clauses our processors operate under.
How long we keep it
- Subscriber record and preferences — until you unsubscribe or ask for deletion.
- Sign-in tokens — fifteen minutes, then deleted automatically.
- Delivery records — 24 months, so we can answer “did that issue reach me?”
- Suppression list — an unsubscribed address is kept indefinitely, in hashed form, for the sole purpose of never emailing you again.
- Billing records — as long as tax law requires, typically seven years, held by Paddle.
Your rights
Wherever you live, you can ask us to show you what we hold, correct it, delete it, hand it over in a portable form, or stop a particular use. If you are in the EU or UK this is the GDPR; in California, the CCPA; in several other places, something equivalent. We apply the same answer to everyone rather than sorting people by jurisdiction.
Email [email protected]. We will respond within 30 days, and we will not charge you or make you create an account to ask. If you are unhappy with the outcome, EU and UK readers may complain to their national data protection authority.
Children
The service is not for anyone under 16, and we do not knowingly collect their data. If you believe we have, email us and it will be deleted.
Security
Traffic is encrypted in transit. Your email address is also encrypted where we store it, and your subscriber record is filed under a one-way keyed fingerprint of your address rather than the address itself. A copy of our database, taken on its own, is a set of tool preferences that cannot be tied back to a person without keys held separately from it.
We are not claiming we cannot read your data, because we can: the job that sends your newsletter decrypts your address to address the envelope, and Resend necessarily sees it in order to deliver. What this protects against is a leaked, exported or stolen copy of the database — which is the realistic risk, and the one where your filter list would otherwise name you.
Sign-in tokens are stored hashed, expire in fifteen minutes and work once. Changing your delivery address or opening billing requires a fresh link emailed to you, so a stolen browser session can do neither. Credentials live in a secrets manager, never in our source code, and the subscriber list is never handed to any system outside our own — including our own build and publishing automation. No system is perfectly secure, and if a breach affects you we will tell you and the relevant authority within the time the law requires.
Changes
If we change this policy in a way that materially affects you, we will email subscribers before it takes effect rather than quietly editing the page.
Related
Questions about anything on this page go to [email protected] and reach a person, not a queue.