Legal — Draft
Privacy Policy
Private Beta draft. This page is not final legal advice and requires qualified legal review before commercial publication.
2026-07-24-draft-1.PhoenixOPS is a private-beta project operated independently by its founder. This Privacy Policy explains how information submitted through the PhoenixOPS website and request-intake service (the "Service") is collected, used, stored, and protected.
1. Information we collect
When you submit a request through the Service, we collect:
- Identity and contact details you provide: first name, last name, work email, company, role, and optional phone number and country.
- The content of your message and any estimated timeline you provide.
- Consent records: whether you accepted this Privacy Policy and our Terms, the version accepted, and whether you opted in to marketing communications, together with the date and time of consent.
- Files you choose to upload, only after we have invited you to do so through a private, single-use upload link.
- Limited technical information used solely for abuse prevention: a one-way cryptographic hash of your IP address and a rate-limiting counter. We do not store your raw IP address.
2. How we use this information
- To review your request and respond to you by email.
- To invite you to a private upload flow if we accept your request for further review.
- To prepare a manual quotation and, where applicable, a payment link.
- To protect the Service against abuse, spam, and unauthorized access.
- To send you optional marketing communications, only if you have opted in.
3. Service providers
We use the following categories of service providers to operate the Service. Each processes data only as necessary to provide its function to us:
- Hosting and infrastructure (Vercel).
- Database and private file storage (Supabase).
- Transactional email delivery (Resend).
- Bot and abuse protection (Cloudflare Turnstile).
- Error monitoring (Sentry).
4. Storage and retention
During the Private Beta, our default retention practice is:
- Files uploaded but not finalized: deleted after 48 hours.
- Expired upload session metadata: retained for 30 days, then deleted.
- Rejected or unqualified requests and any associated files: deleted after 30 days.
- Data relating to an accepted client engagement: retained under the terms of a signed client agreement and our project retention policy.
- Operational security logs: retained for up to 90 days where our tooling permits.
5. Security controls and limitations
Uploaded files are stored in a private storage bucket that is never exposed through a public URL and are not automatically parsed, rendered, or processed by any automated system, including AI systems, during Private Beta. Files remain in a pending-review state until a member of our team has manually reviewed them, including endpoint/antivirus scanning before any file is opened. No security control is perfect, and we cannot guarantee absolute security of any information transmitted to us.
6. Cross-border processing
Service providers may process or store information in multiple jurisdictions. Appropriate technical, organizational, and contractual safeguards will be applied where relevant.
7. Your rights
You may request access to, correction of, or deletion of your personal data, or withdraw marketing consent at any time, by contacting us at the address below. Because this is a Private Beta, some requests may take additional time to fulfill manually.
8. Private Beta limitations
The Service is an early-stage Private Beta. Workflows, retention practices, and this Policy may change as the Service develops. We will note material changes to this Policy by updating the version number above.
9. Governing law
This private-beta draft does not specify a governing law or dispute-resolution forum. Those provisions will be completed and legally reviewed before any commercial launch.
10. Contact
For questions about this Privacy Policy, or to exercise your rights, contact us at hello@phoenixops.ai.