Supplemental privacy notice · Release readiness
What leaves your browser—and when.
Building or exporting the release packet keeps it on your device. If you separately join Wave 2, the current AI-use category is copied into that submission; the confirmed record is created only after you prove control of your mailbox.
Notice scope
This notice covers the Distro release-readiness packet and its Wave 2 confirmation and opening-update flow. Read it with the general Suede privacy policy linked below.
Last updated
Data signal path
Local. Pending. Confirmed.
Building or exporting the packet does not upload it. If you separately ask for Wave 2 updates, the current AI-use category is copied into that submission with the other disclosed form fields; hosting, security, rate-limit, and email providers also process the limited operational data described below.
- 01Local
Your packet stays yours
AI roles, permissions, split totals, and royalty-path answers remain in your browser. Building or exporting does not upload the packet. The current AI-use category is copied only if you separately submit the Wave 2 form.
- 02Pending · 24 hours
One confirmation email
The form sends your email, selected AI-use category, first royalty path, and consent record. Before confirmation, Suede does not add that request to the confirmed-interest table. Vercel/BotID, Upstash, and Resend process limited request, abuse-prevention, and email-delivery data under their configured retention. The opaque token is placed in the email link fragment and stops being accepted after 24 hours.
- 03Confirmed
A bounded interest record
Only after mailbox confirmation does Supabase store the normalized email, selected AI-use category, first royalty path, consent version and source, a one-way digest of the confirmation-link identifier, a keyed one-way digest of the normalized email for withdrawal replay protection, and lifecycle timestamps.
Confirmed record
The fields we keep
- Normalized email address (trimmed and lowercased)
- Selected AI-use category
- First royalty path
- Consent version and source
- Keyed one-way digest of the normalized email for withdrawal replay protection
- One-way digest of the confirmation-link identifier (not the token)
- Confirmation, creation, update, and retention-deadline timestamps
Purpose boundary
What we use it for
We use confirmed interest only to complete the requested Wave 2 confirmation, send the specifically requested Wave 2 opening updates, and plan the product in aggregate.
Consent is the basis for the requested confirmation and updates. Limited security processing is used to protect the service and sender from automated or repeated abuse.
We do not sell the data described in this notice.
Security processing
Abuse checks stay separate
Salted or keyed request and recipient identifiers are processed through our security infrastructure to deter automated or repeated abuse. The confirmed Distro interest record does not include a raw IP address or those rate-limit keys.
Service providers / processors
- Vercel
- Hosts the Distro site and processes web requests and platform telemetry.
- BotID
- Processes automation signals used to block abusive submissions.
- Supabase
- Stores the mailbox-confirmed Wave 2 interest record.
- Resend
- Receives the recipient, message content, and delivery metadata needed to send the confirmation and requested updates.
- Upstash
- Stores time-limited rate-limit keys derived from request and recipient identifiers for abuse prevention.
Retention and choice
A live-record expiry, with an earlier withdrawal path.
- Confirmation token
- Stops being accepted after 24 hours. An unconfirmed request is not added to the confirmed-interest table. Email-delivery and abuse-prevention providers apply their own configured retention to operational records.
- Confirmed interest
- The record is scheduled for deletion by a daily retention job within 24 hours after the 13-month mark following the most recent confirmation, or earlier after a verified withdrawal. Routine hosting backups follow the provider's rotation; any restored live record remains subject to the same retention control.
Withdraw or request deletion
Email us from the address you confirmed. We may ask you to verify control of that mailbox. An authorized operator then removes the live confirmed-interest record; there is not yet a public self-service deletion endpoint. To keep an unexpired pre-withdrawal link from recreating that record, a keyed one-way digest of the normalized email and the withdrawal cutoff remain active for 25 hours. This is pseudonymous security data, not anonymous data; the guard contains no raw email. The daily lifecycle job schedules it for deletion within 24 hours after that active window ends. A fresh link requested after withdrawal can create a new consent record.
Wider Suede policy
This notice is supplemental.
The general Suede privacy policy explains practices outside this focused Distro flow. This notice is an operational explanation, not legal advice, a compliance certificate, or a legal or compliance guarantee. The release packet does not guarantee rights clearance, regulatory compliance, or store acceptance.