LEGAL
Privacy Policy
Version: 2026-08-11 Β· Last updated: August 11, 2026
This Privacy Policy explains how AI Leverage Academy ("we," "us") collects, uses, shares, and protects your personal information when you use The Compass Pro (the "Service"). We take privacy seriously and only collect what we need to run the Service.
1. Who we are and how to reach us
Data controller: AI Leverage Academy
Contact for privacy inquiries: hello@aileverageacademy.org
Postal address: Available on request via the email above
2. Information we collect
2.1 Information you give us directly
- Account: email address, first name (optional), password (stored as a one-way cryptographic hash β we cannot see it), age confirmation (18+)
- Consent records: timestamps and version numbers of the Terms and Privacy Policy you accepted, marketing email opt-in status
- Profile: business name, niche, target audience, voice description, phone number (optional, for reminders)
- Your Content: quiz answers, weekly check-ins, chat messages, voice samples, uploaded files, URLs, pipeline contacts, notes
- Payment: Stripe collects and stores your card. We only see billing metadata (last 4 digits, expiry, country) β never the full card number
- Communications: support emails, feedback you send us
2.2 Information we collect automatically
- Usage data: pages visited, features used, timestamps, actions taken (e.g., roadmap generated, chat sent)
- Technical data: IP address, browser type, operating system, device type, referral source
- Cookies: essential cookies for login sessions; optional analytics cookies only if you consent (see Section 8)
- Error data: if the Service crashes, we log the error (which may include your user ID and the URL you were on) via Sentry to fix bugs
2.3 Information from third parties
- Stripe: subscription status, billing events, and card metadata
- Email providers: delivery/bounce/complaint signals
3. How we use your information
We use your information for the following purposes:
- Providing the Service β running your account, generating AI outputs from your inputs, sending the emails you signed up for (roadmap delivery, Monday briefs, check-in reminders)
- Legal & security β preventing fraud and abuse, enforcing our Terms, complying with legal obligations, protecting our rights
- Improving the Service β analyzing aggregate usage patterns to fix bugs and prioritize features (we do NOT use your Content to train any AI model)
- Marketing (only if you opt in) β occasional product updates, new features, promotional offers. You can unsubscribe at any time using the link in every marketing email
- Support β responding to your emails and requests
4. Legal basis for processing (GDPR)
If you are in the European Economic Area, United Kingdom, or Switzerland, we rely on these legal bases:
- Contract β to deliver the Service you signed up for
- Legitimate interests β to secure the Service, prevent fraud, and improve the product (only where our interests are not overridden by your rights)
- Consent β for marketing emails and optional analytics cookies (you can withdraw consent at any time)
- Legal obligation β to comply with tax, accounting, and other laws
5. Who we share information with
We do NOT sell your personal information. We share it only with the following categories of service providers, and only for the purposes listed:
| Provider | Purpose | Data shared |
|---|---|---|
| Anthropic (Claude) | AI processing for roadmap, coach, Studio, Foundry | Your prompts + inputs; not used to train Anthropic models by default |
| OpenAI (if enabled) | Audio transcription (Whisper) for uploaded voice notes | Audio files you upload |
| Stripe | Payment processing, subscription management | Name, email, billing address, card details (Stripe holds card; we don't) |
| Render | Application hosting + database storage | All account and Content data (stored encrypted at rest) |
| Google (Gmail SMTP) | Sending transactional and product emails | Recipient email and email content |
| Sentry (if enabled) | Error monitoring | Error stack traces, URL, user ID |
We may also disclose information if legally required (subpoena, court order), to protect our rights, or in connection with a business transaction (merger, acquisition β with prior notice to you).
6. International data transfers
The Service is hosted in the United States. If you access it from outside the US, your data will be transferred to the US. Where required by law (e.g., EU users), we rely on Standard Contractual Clauses or equivalent safeguards with our processors.
7. How long we keep your data
- Active accounts: as long as you have an account with us
- Deleted accounts: we hard-delete within 30 days of your deletion request (grace period for accidental deletion)
- Financial records: retained up to 7 years to comply with tax and accounting laws
- Anonymized analytics: may be kept indefinitely (no longer identifies you)
- Backups: may persist for up to 90 days after deletion in encrypted backups, then overwritten
8. Cookies and similar technologies
We use the following types of cookies:
- Essential cookies: required for login and security (cannot be disabled β you cannot use the Service without them)
- Preference cookies: remember your settings (e.g., dev tier switcher in local development)
- Analytics cookies (optional): anonymous usage tracking to improve the product; only set if you accept via our cookie banner
You can manage cookie preferences via your browser settings and via the cookie banner shown to first-time visitors.
9. Your rights
9.1 Rights available to all users
- Access β download a copy of your personal data at any time from your account settings
- Correction β update your name, email, or other profile fields at any time in account settings
- Deletion β delete your account and all associated data from account settings (2-step confirm; hard-deleted within 30 days)
- Cancellation β cancel your subscription at any time via the billing portal in your dashboard
- Marketing opt-out β unsubscribe from marketing emails using the link in every marketing message
9.2 Additional rights for EU/UK/Swiss users (GDPR)
- Portability β receive your data in a structured, machine-readable format (JSON, provided in your data export)
- Restriction β request we limit how we use your data
- Objection β object to processing based on legitimate interests
- Withdraw consent β for any processing based on your consent
- Complaint β lodge a complaint with your local data protection authority. Please contact us first β we'll try to resolve it directly.
9.3 Additional rights for California users (CCPA/CPRA)
- Right to know β what personal information we've collected in the last 12 months (see Section 2)
- Right to delete β delete personal information (some exceptions for legal / fraud prevention)
- Right to correct β inaccurate personal information
- Right to opt out of sale/sharing β we do NOT sell or share personal information for cross-context behavioral advertising
- Right to non-discrimination β we will not deny service or charge more for exercising your rights
To exercise any right, use the self-service tools in your account settings or email hello@aileverageacademy.org. We respond within 30 days.
10. Data security
We use industry-standard measures to protect your data:
- HTTPS/TLS encryption for all data in transit
- Passwords stored as one-way cryptographic hashes (bcrypt-family)
- Encrypted database backups
- Access controls limiting who at AILA can view user data
- Rate limiting to prevent abuse
- Error monitoring to detect anomalies
No system is perfectly secure. If we experience a data breach affecting your personal information, we will notify you and (where required) regulators within the timeframes required by law.
11. Children's privacy
The Service is not intended for anyone under 18. We do not knowingly collect information from minors. If we discover we have collected data from a minor, we will delete it promptly. Parents/guardians who believe their child has provided us with data should contact us immediately.
12. AI-specific privacy notes
Because the Service uses AI, please understand:
- Your prompts and inputs are sent to Anthropic's Claude API to generate outputs. Anthropic states they do not train on API data by default. We further do not use Your Content for training any AI model, ours or anyone else's.
- If you upload audio for transcription, the audio file is sent to a transcription service (currently OpenAI Whisper if enabled) and then deleted from that service per its retention policy.
- AI outputs may reflect biases in the underlying models. We do not guarantee outputs are free from bias or error. You are responsible for reviewing outputs.
13. Do Not Track
Some browsers send a "Do Not Track" signal. There is currently no industry standard for how to respond, so we do not act on it. Our cookie banner gives you direct control over analytics tracking.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email at least 14 days before the effective date. The version number and date at the top of this policy always reflect the current version.
15. Contact
Privacy questions, requests, or complaints: hello@aileverageacademy.org
The Compass Pro is a product of AI Leverage Academy. This Privacy Policy is a working framework aligned with GDPR, UK GDPR, CCPA/CPRA, and other applicable laws. For jurisdiction-specific advice, consult a qualified attorney.