Privacy Policy

Last updated: June 12, 2026

This policy explains what AILE collects, why, who we share it with, and the choices you have. We keep it short and plain on purpose.

1. Who we are

AILE is operated by Ellment Creative LLC, located at 9251 West 22nd Street, Minneapolis, MN 55426. For any privacy question or request, email us at ellmentcreative@gmail.com. Ellment Creative is the data controller for the personal information described here.

2. Information we collect

  • Waitlist details: your email address or US mobile phone number (whichever you choose), the page or source you signed up from, and a timestamp. We also store a one-way hashed version of your IP address to prevent spam and abuse (we do not keep your raw IP for the waitlist), and a record of the exact consent language you saw when you joined.
  • Account and authentication data (for the future app and internal admin): email, a securely stored password, and session tokens.
  • Product usage (when the app launches): lessons completed, progress, streaks, and similar learning activity.
  • Technical and log data: standard server logs (such as request times and error information) used to operate and secure the service.

We do not knowingly collect special-category data and we ask you not to send us sensitive information through the waitlist.

3. Why we use it, and our legal bases

Under the GDPR and UK GDPR, we rely on the following legal bases:

  • Consent: to send you waitlist and launch emails, or, if you join by phone, a single launch text message. You can withdraw consent at any time by unsubscribing (email) or replying STOP (text). Message and data rates may apply to texts. We record the time of your consent, a hashed IP, and the version of the consent language you saw; we will not send recurring marketing texts, and we send nothing at all until launch.
  • Contract: to provide an account and the service you sign up for.
  • Legitimate interests: to keep the service secure, prevent abuse, and understand and improve how it works, balanced against your rights.
  • Legal obligation: to comply with applicable law.

4. Cookies, local storage, and analytics

The public website sets no advertising or analytics cookies and stores nothing persistent on your device. We use two privacy-respecting, cookieless analytics tools: Vercel Analytics (aggregate page statistics, no cookies or device identifiers) and PostHog in memory-only mode (no cookies, no local storage, a fresh anonymous identifier on every page load). Analytics events describe interactions, for example "waitlist form submitted", and never contain your email address or phone number. We use no advertising trackers and no cross-context behavioral advertising.

On-device storage is limited to session-only flags (whether the intro animation has played, and which feedback posts you have upvoted) plus strictly necessary login cookies in the signed-in admin area. Because nothing non-essential is stored on your device, we do not show a cookie consent banner. We honor Global Privacy Control signals. If we ever add advertising or tracking that stores data on your device, we will update this policy and present a consent choice first.

5. How we share information

We do not sell or share your personal information, and we do not use it for cross-context behavioral advertising (as those terms are defined under the CCPA/CPRA). We share data only with the service providers (subprocessors) that help us run AILE:

  • Supabase: Database, authentication, and hosting of application data (United States). Data terms.
  • Vercel: Website hosting, content delivery, and cookieless aggregate site analytics (United States). Data terms.
  • PostHog: Privacy-respecting product analytics, configured cookieless (nothing stored on your device) (United States). Data terms.
  • Anthropic: AI model processing for learning features (does not train on API data) (United States). Data terms.
  • Resend: Transactional and waitlist email (when enabled) (United States). Data terms.

The current list is also on our subprocessors page. We may also disclose information if required by law or to protect rights, safety, and the integrity of the service.

6. International data transfers

We are based in the United States and our providers process data in the United States. If you are in the EEA, the UK, or Switzerland, your data is transferred to the US under appropriate safeguards, including the European Commission's Standard Contractual Clauses with our subprocessors.

7. How long we keep it

We keep waitlist information until the product launches plus a reasonable window, and then delete it if you have not become a user. We delete or anonymize personal data when it is no longer needed, and sooner on a valid deletion request, unless we must retain it to meet a legal obligation.

8. Your rights and choices

Depending on where you live, you may have the right to access, correct, delete, restrict, or object to our use of your data, to data portability, and to withdraw consent (GDPR/UK GDPR). California residents have the rights to know, delete, and correct personal information, to opt out of sale/sharing (we do neither), and to not be discriminated against for exercising these rights (CCPA/CPRA).

To exercise any right, email ellmentcreative@gmail.com. We will verify your request and respond within the timelines required by law. You may also unsubscribe from any email using the link in its footer. EEA/UK users may lodge a complaint with their local data protection authority.

9. AI processing

Some AILE features use AI models provided by Anthropic to generate and review learning content. Anthropic processes the inputs needed to return a result and, per its commercial terms, does not use API data to train its models. AI output can be wrong; our assessment content is reviewed by a person before it goes live.

10. Children

AILE is intended for people aged 13 and older. We do not knowingly collect personal information from children under 13. In the EEA, where a higher age of consent applies (up to 16), a parent or guardian must consent on the child's behalf. If you believe a child has provided us data, contact us and we will delete it.

11. How we protect your data

We use industry-standard safeguards including encryption in transit (HTTPS/TLS), database row-level security, least-privilege access, multi-factor authentication on administrative accounts, and regular security review. No system is perfectly secure, but if a breach affects your personal data we will notify you and the relevant authorities as required by law.

12. Changes and contact

We may update this policy as AILE evolves; we will revise the “Last updated” date and, for material changes, give prominent notice. Questions or requests: ellmentcreative@gmail.com or Ellment Creative, 9251 West 22nd Street, Minneapolis, MN 55426.

Effective date: June 8, 2026.