Skip to main content
AI Policy File

Privacy Policy

Last updated: August 29, 2026

Controller and contact

Jason Ramirez, the site owner and maintainer, determines why and how this website processes the data described below and is the controller for that processing. Contact: hello@aipolicyfile.com. No separate data protection officer or European Union representative contact has been verified for this site. This public contact does not replace any appointment that applicable law may require.

The checker

Checker answers and results are calculated in your browser. The checker does not send those answers or results to our waitlist endpoint. Closing or refreshing the checker clears its in-memory state.

The founding list

If you choose to join, we collect your email address, your optional role selection, your optional product-value selection, and whether you submitted from the home page or checker. The server requires affirmative consent before accepting a submission. It adds the server-side submission time, the version of the consent notice, a manual retention target, and the retention rule to the Telegram message. These metadata are generated by the server, not accepted from the browser. Do not include legal or other sensitive personal information; the form has no free-text field.

The server sends those fields through the Telegram Bot API to a private Telegram chat controlled by the site owner. New messages use Telegram's content-protection option, which limits ordinary forwarding and saving in supported Telegram clients; it is not encryption and does not enforce deletion. Telegram is a service provider and stores the resulting message under its own systems and policies. Authorized access is limited to the site owner and Telegram personnel or systems as needed to provide the service.

We use the submission for one launch announcement and related administration. We do not sell it or share it for advertising. There is no separate waitlist database, but the Telegram message remains available until it is manually deleted or its chat timer expires. The destination chat's 365-day auto-delete setting for new messages was verified on August 29, 2026 with a synthetic production submission; the synthetic record was then deleted. Each new message carries this administrative rule: delete on verified withdrawal; otherwise within 30 days after the one launch email; the 365-day timer is a backstop. Telegram's timer is not retroactive, so messages received before it was enabled remain subject to manual review and deletion. To request deletion, email hello@aipolicyfile.com from the address you submitted. We will delete the accessible message when we can verify the request. Telegram or hosting providers may retain limited backup, security, or legal records, so we do not promise immediate deletion from every system.

Contact email

Messages sent to hello@aipolicyfile.com are routed through Namecheap's email-forwarding service to the owner's receiving mailbox. The final mailbox provider, its account-side retention setting, and its security configuration must be verified in the owner account; the website cannot establish those settings from DNS alone. Do not email confidential, privileged, or highly sensitive information.

Hosting and logs

Vercel hosts the site and may process standard request data such as IP address, request time, route, browser or network information, and operational logs. Our waitlist code does not intentionally write submission fields, Telegram messages, or Telegram credentials to application logs. Hosting and security records follow Vercel's configured and contractual retention behavior; we do not promise zero retention.

Analytics and advertising

Google Analytics remains blocked unless you select "Allow analytics." If allowed, the site manually sends a page-view event containing the page title, origin, path, and referrer with query strings and fragments removed. The dedicated AI Policy File property has Enhanced Measurement disabled, so it is not configured to automatically collect scrolls, outbound-link clicks, file downloads, site searches, video engagement, form starts or submissions, or browser-history page views. Do not put sensitive data in a URL because hosting logs, third-party links, or a future configuration change may still expose it.

Google Analytics also processes standard analytics data such as session information, referrer, browser and operating-system name, broad device category, language, and country or region. Google says IP addresses are used to derive location before being discarded. Granular location and device collection is blocked in all 307 regions available in the property, so the property is not configured to collect city-level location, city latitude or longitude, detailed device models, User-Agent strings, browser or operating-system minor versions, or screen resolution. Site code does not send checker answers, checker results, email addresses, role or product-value selections, or other founding-list form-field values to Google Analytics. After consent, Google may still generate standard events such as first visit, session start, and user engagement; those are distinct from Enhanced Measurement events.

The dedicated property's event and user data retention are both set to two months, and reset on new user activity is disabled. Google Signals and user-provided data collection are off. Ads personalization is disallowed in all 307 regions, while site code also denies advertising storage, advertising user data, and advertising personalization. These provider-account settings were verified on August 29, 2026 and must be rechecked after any Analytics account or stream change. The regional restrictions apply to future collection and use; they do not retroactively rewrite provider records. Google states that the two-month controls do not affect most standard reports, which use aggregated data, so the setting is not a promise that every aggregate disappears after two months.

See Google's current documentation for its data collection details and regional processing explanation, its page-view collection guidance, and its Enhanced Measurement event list, its retention controls, its granular location and device controls, and its ads-personalization controls.

Your choice is stored in your browser so it can be honored on later visits. You can change it through the persistent Privacy choices button. If you continue without analytics, the Google Analytics script is not downloaded.

Purposes and legal bases

Where the EU General Data Protection Regulation applies, founding-list processing and optional Google Analytics processing rely on your consent. You may withdraw either choice at any time without affecting processing that was lawful before withdrawal. Hosting, security, abuse prevention, service diagnostics, and handling privacy or correction requests rely on the legitimate interests of keeping the site available, secure, accurate, and able to establish or defend legal claims. Data may also be processed when necessary to comply with a legal obligation.

Recipients and international processing

Recipient categories are Vercel for hosting and request logs, Telegram for founding-list delivery, Google for consented analytics, Namecheap and the receiving mailbox provider for contact email, and public authorities when disclosure is legally required. These providers may process data in the United States and other countries. The applicable provider account, contract, and data-processing terms determine whether an adequacy decision, standard contractual clauses, or another transfer mechanism applies. Email hello@aipolicyfile.com to request the current provider and safeguard information available for your processing.

Your privacy rights

Where applicable, you may request access, correction, deletion, restriction, or portability of your personal data, or object to processing based on legitimate interests. You may withdraw analytics consent through Privacy choices and may withdraw founding-list consent by emailing hello@aipolicyfile.com. You may also lodge a complaint with the data-protection supervisory authority where you live or work. We may need information reasonably necessary to verify identity and may retain or deny a request where law permits or requires it.

Providing founding-list data is optional. If you do not provide an email address and consent, you will not receive the launch announcement; the checker remains available. Declining analytics does not limit the site. The site does not use the described data for automated decisions that produce legal or similarly significant effects.

See the official GDPR text, including Article 13.

Contact

Privacy questions or deletion requests: hello@aipolicyfile.com. We may need to verify that you control the submitted email address before acting on a request.