Privacy
What we collect, what we don't, and why.
Aperture-as-company doesn't collect or retain participant data for our own use. Facilitators may optionally collect participant names for their own session use, with informed consent. This page details both layers. If you took part in Aperture's image-research program, a separate research-participant notice covers that data.
01What we collect.
-
Account information.
Your email and auth method (Google SSO, magic-link email, or username and password), and an optional display name. We never require a real legal name.
-
Google sign-in.
When you sign in with Google, Google shares your name, email address, and Google account identifier with us. We use this only to create and secure your facilitator account and to associate your saved decks and sessions with you. We request only basic sign-in access (name, email, profile). We do not access your Gmail, Google Drive, contacts, or any other Google data.
-
Billing information.
Paddle, our Merchant of Record, processes payment as the legal seller of record. We receive limited order information (which plan, when, currency, country of purchase, billing status). Paddle holds your card details; we never do. Section 06 details Paddle's role.
-
Session information you create.
Session names, configurations, saved Selections, and the decks you build. This is your facilitation work; it lives in your account.
-
Operational logs.
When sessions are created and started (for refund eligibility), and consent and renewal events (for California ARL compliance). To make these records legally reliable and to protect against abuse, a consent record and a join attempt include the IP address and browser user-agent at that moment. We use this only to evidence the action and to guard against fraud and automated abuse; not to build a profile of you. Retained as required by law; not used for any other purpose.
02What we don't collect.
-
Participant data, for Aperture's own use.
No AI training on the choices participants make. No aggregation of picks across facilitators or sessions. No analytics for our own commercial purposes. Aperture-as-company never reads what an individual participant picked, said, or shared in your sessions.
-
Picks are your facilitation data, for your debrief.
When you turn on "Save picks for debrief," the images participants choose are recorded so that you, the facilitator, can see the aggregate for your own session in debrief mode. This is your data, visible only to you. Within that aggregate, picks are tied to a pseudonymous per-session token, not to a name, so the debrief view shows what the group chose without revealing who chose what, unless you separately turn on "Collect names." We never use these picks for our own purposes, and we never reveal who picked what to anyone.
-
Names of your participants, unless you choose to.
If you turn on "Collect names" in a session, participants enter their names when they join, and only then can a pick be attributed to a named person, for your eyes alone. That data is yours, visible only to you, never touched by Aperture for any other purpose, and deleted when the session is deleted.
-
Participants see how their session is set up.
When a session asks participants to submit picks, the join screen tells them how many to choose; when "Collect names" is on, it asks for a name and discloses that the name is shared only with the facilitator. When a session is browse-only, participants are told that nothing is submitted, and they leave no record of what they looked at.
-
Real legal identities.
We accept display names and SSO emails. We don't require ID verification, government documentation, or anything that maps you to a legal identity beyond what Paddle requires at checkout for paid accounts.
-
Behavioral profiles.
No cross-context tracking. No ad-targeting profiles. No data sold or shared with brokers.
03Cookies and similar.
-
Essential authentication cookies.
Set by Supabase for sign-in sessions. Required to use the platform.
-
Paddle checkout cookies.
Set by Paddle during checkout. Required to process payment.
-
Privacy-respecting analytics.
We use Cloudflare's first-party Web Analytics, which our host Cloudflare provides without cookies and without per-user tracking. It helps us understand traffic patterns without identifying anyone. Cloudflare's role is detailed in the subprocessor list.
-
Error monitoring.
We use Sentry to catch and diagnose technical errors in the Studio app. It records diagnostic events with technical metadata (such as stack traces, page URLs, and browser and runtime information). We configure Sentry not to send default personal information, and it does not collect participant data. See the subprocessor list.
-
Participant session cookie (functional).
When a participant joins a session, a session-scoped device cookie holds a pseudonymous participant token (a random identifier, not a name) so they can return and edit their own submissions. The token is tied to that one session, auto-deleted at session expiration (around 7 days), and is never used to track anyone across sessions or sites.
04How long we keep things.
-
Retained while your account is active.
Your account, sessions, and saved Selections are kept for as long as your account is open, so your work is there when you come back. We don't put your facilitation work on a deletion timer.
-
Delete anytime, and it's total.
You can delete your account, with all sessions and Selections, at any time from Account → Account Deletion. When you do, deletion is total and permanent; we don't keep zombie data. A 30-day grace window lets you cancel the deletion or export your work first.
-
After you cancel a subscription.
If you cancel a subscription but leave your account open, your account and saved work stay in place; you keep access to your data and can export it or delete the account whenever you choose. Cancelling billing is not the same as deleting your account.
-
Export window.
Before final deletion, you can download a copy of your saved decks and session notes yourself, anytime, from your account: Account → Data Export. We don't lock you in.
-
Operational logs.
California ARL consent and renewal events: 3 years (legal requirement). Refund eligibility logs: 1 year. Transaction and billing records: held by Paddle, as Merchant of Record, per its own retention obligations.
05Who else sees data.
-
Our subprocessors.
Cloudflare, Supabase, and others we name publicly. Each processor has a Data Processing Agreement in place and is configured with training-off where applicable. Independent controllers, including Paddle as our Merchant of Record, are noted separately. See the full subprocessor list.
-
No advertisers, no data brokers.
We don't sell your personal information, and we don't share it for cross-context behavioral advertising, as those terms are used under the California Consumer Privacy Act. We have no commercial relationship with any data broker. Because we don't sell or share your data, there's no opt-out to honor and no Global Privacy Control signal to act on; there is simply nothing to opt out of.
-
Legal compliance only.
If law enforcement serves valid legal process, we comply to the minimum required. We publish counts of such requests in the annual transparency report.
06Payments and the Merchant of Record.
-
Paddle is the legal seller.
Aperture uses Paddle (Paddle.com Market Limited, Judd House, 18-29 Mora Street, London EC1V 8BT, United Kingdom; and Paddle.com Inc., c/o Corporation Service Company, 251 Little Falls Drive, Wilmington, Delaware 19808, USA) as our Merchant of Record for all purchases. When you buy an Aperture subscription or session pass, you enter into a contract directly with Paddle as the legal seller of record.
-
Paddle is an independent controller.
For the checkout, payment authorization, invoicing, tax calculation and remittance, fraud prevention, chargeback handling, and legal compliance it performs as Merchant of Record, Paddle acts as an independent data controller. Paddle determines the purposes and means of that processing for its own legal and commercial obligations. That processing is governed by Paddle's privacy policy and Paddle's GDPR statement. To exercise data rights over personal data Paddle holds as an independent controller, contact privacy@paddle.com.
-
What Paddle shares with us.
After a transaction completes, Paddle shares limited order and subscription information with us (your name, email address, a Paddle customer and subscription identifier, plan, billing status, and country of purchase) so we can provision your account, deliver the service, provide support, manage your subscription, and meet our legal obligations. We act as a separate, independent controller for that data. Our lawful basis is our legitimate interests in delivering the service you contracted for and administering the subscription relationship, and our contract with you. We never receive or store your full payment card details; Paddle holds those as an independent controller.
-
Controller to controller.
The relationship between Aperture and Paddle for buyer transaction data is controller-to-controller. Paddle relies on its legitimate interests as the lawful basis for disclosing your order information to us. Neither Aperture nor Paddle acts as the other's data processor for buyer transaction data. Where this involves transferring the personal data of buyers in the EEA or UK to us in the United States, Paddle, as the data exporter, applies the safeguards required under GDPR Chapter V: Standard Contractual Clauses, together with the UK Addendum or IDTA for UK data, as set out in Paddle's seller terms and GDPR documentation.
-
Marketing consent.
Marketing email is opt-in and is collected by us, not by Paddle. When you first accept our Terms in the app, you may tick an optional box to hear from us about Aperture updates. We record that consent, along with what was shown to you at the time, and only then add you to our updates list. We use your contact information for that purpose only. Withdraw at any time via the unsubscribe link in any such email, or by writing to hello@aperturedeck.com.
07Your rights.
-
Access.
Download a copy of your data yourself, anytime, from your account: Account → Data Export. If you can't reach your account, email us and we respond within 30 days.
-
Deletion.
Delete your account yourself, anytime, from your account: Account → Account Deletion. Total deletion, including Selections. If you can't reach your account, email us. We don't keep zombie data. Residual copies may persist in routine encrypted database backups for up to 7 days after deletion, after which they roll off automatically; we do not restore deleted data from backups except to recover from a system failure.
-
Correction.
Update your account information any time. For anything else, email us.
-
Portability.
Export your saved decks and session notes in standard formats. No vendor lock-in.
08International.
-
US hosting.
Your data is hosted in the United States: Supabase for the database, with Cloudflare's global edge in front.
-
EU and UK buyers.
You provide account information to us directly when you sign up, and we process and store it in the United States, relying on your consent and our contract with you. Order information reaches us from Paddle as a controller-to-controller disclosure under Paddle's legitimate interests (section 06). Paddle handles VAT as Merchant of Record. We honor GDPR and UK GDPR rights (access, correction, deletion).
-
California buyers.
We comply with the California Consumer Privacy Act and California's Automatic Renewal Law, including express-consent capture for renewals and a pre-renewal notice cadence. You have the right to know what personal information we hold, to request its deletion, and to not be discriminated against for exercising these rights; exercise them from your account (Account → Data Export, Account → Account Deletion) or by writing to us. We do not sell or share your personal information, so the right to opt out of sale or sharing does not apply.
09Changes to this policy.
-
Material changes notified.
If we change anything substantive, subscribers receive email notice and a posted update. The change-history lives in the annual transparency report.
-
Versioned.
Each version of this policy is dated. Past versions are archived in the transparency report.
Questions about privacy, or want to exercise a data right? Write to privacy@aperturedeck.com.