Privacy Policy
Effective July 30, 2026 · Righthand, operated by Stevesaiguide.
Plain-language summary; not a substitute for legal review.
The short version
Until you sign in, your work — progress, saved prompts, voice profile — lives in your own browser, not on our servers. What you type into the AI features is sent to Anthropic’s Claude API to generate your draft, and to nothing else. Our analytics and error monitoring are built so they never carry the text of your prompts or drafts. We don’t sell your data, run ad trackers, or record your sessions. See exactly where each flow goes on Where your data goes.
What we collect
- On your device (default): lesson progress, streaks, saved playbook prompts, your voice profile, interview answers, and personalized scenarios are stored in your browser’s local storage. Anonymous use puts none of this in a server database.
- Account data (only if you sign in): your email address (magic-link sign-in — no passwords), which door you signed up on, your plan, and a sync snapshot of the on-device work above so you can resume on another device.
- AI inputs and outputs: the prompts, facts, documents, and photos you submit to the AI features, and the drafts generated from them. Processed to serve your request (see “AI processing” below); not written to a database unless you sign in and sync.
- Usage data: if product analytics are enabled, we record event names, lesson/skill ids, scores, and counts — never the text you type. Your device gets a random id, not a fingerprint.
- Diagnostics: error reports (stack traces and request metadata) so we can fix what breaks. Session replay is off.
- Feedback: whatever you type into the feedback widget, with an optional email if you want a reply.
How we use it
To run the product (build your path, score your practice, generate drafts, sync your work when signed in), to send you the sign-in link and essential service messages, to meter free and paid usage, to fix errors, and to improve the product. We do not sell your personal information, and we don’t use advertising trackers.
AI processing
Your AI inputs are sent to Anthropic’s Claude API — the only model provider this product uses — to generate output. Under Anthropic’s Commercial Terms of Service, Anthropic may not train its models on this content. Don’t paste information you aren’t authorized to share; the free lesson What client data is safe to paste teaches how to redact before you upload.
Service providers (processors)
- Anthropic — AI model provider (your AI inputs and outputs).
- Railway — cloud hosting and the PostgreSQL database (account + sync data).
- Cloudflare — DNS, TLS, and proxying (traffic metadata).
- Sentry — error monitoring (error events; problem reports you submit).
- Resend — transactional email (your sign-in link; feedback delivery).
- PostHog — product analytics, when enabled (event names and counts only).
- Stripe — payments, when paid checkout is live. Checkout is Stripe-hosted; your card number never touches our servers.
Cookies and local storage
We use a signed session cookie for sign-in, a door-preference cookie, and signed usage counters for free-tier metering (a count and a timestamp — no content). Your work stays in local storage on your device. There are no third-party advertising cookies.
Retention and deletion
Account and sync data are kept while your account is active. Server-side caches for scoring and address lookup are short-lived, in memory only, and are cleared automatically. Email us at [email protected] to access, correct, or delete your data — we’ll delete within 30 days, except limited records we must keep for legal, tax, or security reasons. On-device data you can clear yourself at any time by clearing your browser storage.
Security
Sign-in is passwordless (one-time links), sessions are server-revocable and signed, and all traffic runs over HTTPS. No system is perfectly secure — which is also why the safe-to-paste lesson exists.
Children
Righthand is a business tool for adults. It is not directed to anyone under 18.
Changes and contact
We’ll post updates here and change the effective date above. Questions: [email protected].