Project Hindsight

Privacy Policy

Effective July 21, 2026

Project Hindsight is operated by Surefoot, a solo-run company in the United States. This page explains what we collect, why, and how you can get it back or have it deleted. We’d rather write this in plain English than bury it in boilerplate.

What we collect

  • Account info. Your email address and, if you provide it, your name and timezone. Authentication is handled by Supabase Auth; we don’t see or store your password.
  • Decision journal content. The decisions, reviews, and principles you write are stored in our Postgres database, hosted by Supabase in a US region.
  • Voice recordings (Pro). If you’re on a Pro plan and choose to record audio, it’s stored in private object storage that only you (and our backend, to process it) can access, and transcribed to text using OpenAI’s API. You control how long recordings are kept (forever, 30 days, or 1 year) in Settings.
  • AI-generated insights (Pro). For Pro users, we send relevant decision and review content to Anthropic’s API to generate pattern insights and prompts (e.g. calibration feedback, surfaced principles).
  • Email delivery data. We use Resend to send transactional email (magic links, review reminders, welcome emails) and keep a record of what was sent and whether it was opened or clicked, so reminders work reliably.

How we use it

We use your data to run the product: storing and displaying your journal, sending you review reminders, authenticating you, and, for Pro users, transcribing voice notes and generating insights about your own decisions. That’s it. We don’t run ads, and we don’t sell, rent, or share your data with third parties for marketing purposes.

AI and your content

Your decisions, reviews, and voice recordings are never used to train AI models, ours or anyone else’s. Content sent to OpenAI (for transcription) or Anthropic (for insights) is sent solely to generate a response for you, under each provider’s API terms, which contractually prohibit using API inputs for model training.

Sub-processors

We rely on a small number of infrastructure providers to run the service: Supabase (database, authentication, file storage), Resend (transactional email), OpenAI (voice transcription for Pro users), Anthropic (AI insights for Pro users), and Stripe (payment processing, if and when you subscribe to a paid plan). Each only receives the data it needs to do its job.

Data retention

We keep your account and journal data for as long as your account is active. Voice recordings follow the retention preference you set in Settings (never auto-delete, 30 days, or 1 year). If you delete your account, we delete your data within a reasonable period, except where we’re required to retain records (e.g. payment records for tax purposes).

Your rights

You can export everything you’ve logged (decisions, reviews, principles, and preferences) as a JSON file at any time from Settings. To request deletion of your account and data, or to ask any question about what we hold on you, email hello@projecthindsight.ai and we’ll handle it directly. There’s no support queue to get lost in.

Security

Your journal data is protected by row-level security in our database, meaning it’s scoped to your account and inaccessible to other users by design. Voice recordings are stored in private storage, not publicly accessible. No system is perfectly secure, but we take reasonable, industry-standard measures to protect your data.

Changes to this policy

If we make material changes, we’ll update the effective date above and, where practical, let you know directly.

Contact

Project Hindsight is built and run by Brian at Surefoot, based in the United States. Reach out any time at hello@projecthindsight.ai.

Terms of service · Back home