Privacy Policy

Last updated July 17, 2026

Overview

This Privacy Policy explains how SystemSculpt collects, uses, and shares information when you visit the website, purchase licenses, or interact with the Obsidian plugin.

Information I Collect

I collect account details provided through Clerk, payment information handled by Stripe, and communication metadata submitted through the contact form. When you use a hosted AI feature, I process the prompts, notes, files, audio, YouTube URLs, transcripts, and other context you choose to submit. I also store limited telemetry required to operate your dashboard, meter hosted work, understand product usage, attribute purchases, and diagnose checkout or plugin issues.

How I Use Information

Collected data enables account provisioning, payment processing, license delivery, customer support, fraud prevention, analytics, advertising measurement, and product improvement. I do not sell personal information to third parties.

Advertising and Conversion Measurement

When you arrive from an ad or campaign link, I may store campaign parameters and click identifiers such as UTM values, gclid, gbraid, or wbraid so I can understand which ads led to signups or purchases. If advertising conversion measurement is enabled, limited purchase event data may be sent to platforms such as Google Ads. When enhanced conversion data is used, customer data is normalized and hashed before it is sent, subject to consent and applicable platform terms.

Third-Party Services

I rely on trusted vendors including Stripe, Clerk, Cloudflare R2, Resend, OpenRouter, AssemblyAI, Supadata, Google Analytics, and Google Ads. For uploaded audio, Audio Processor sends a temporary signed audio URL to AssemblyAI for speaker-labeled transcription. After SystemSculpt durably stores the transcript, it requests deletion of the AssemblyAI transcript and retries if that request temporarily fails. For YouTube, Audio Processor sends the submitted URL to Supadata to use existing captions first and generate a transcript only when captions are unavailable. Transcript-derived chunks go to OpenRouter for structured summarization, with provider data collection disabled. SystemSculpt may reuse a retained result for an identical source instead of repeating provider work; uploaded-audio reuse stays within the same account, while public YouTube results may be reused for the same video. Each vendor processes data under its own privacy policy and contractual safeguards.

Security

I design the platform with security controls including CSRF protection, rate limiting, and secure credential storage. Access to customer data is limited to authorized personnel acting on my behalf.

Retention

I retain data for as long as needed to deliver services and meet legal obligations. Audio Processor keeps an uploaded source for no more than 24 hours. Completed notes, summaries, transcripts, and processing checkpoints may be retained for up to 30 days while waiting for delivery. After the plugin confirms that the result was written to your vault, that job's retention window is normally shortened to 7 days. Provider-side deletion and short-lived caches follow the process described above and the applicable vendor terms. You may request deletion of support conversations or dashboard exports by contacting me.

Your Rights

Depending on your jurisdiction you may have rights to access, correct, or delete personal data. Submit requests through the contact form or email privacy@systemsculpt.com.

Policy Updates

I may update this Privacy Policy for operational or legal reasons. I will post revisions with an updated date and, when appropriate, provide additional notice.