Founding pilot / data access
Small permissions. Visible boundaries.
This is the access plan you see before paying or connecting anything. The pilot is read-only by design and every outbound action stays with you.
Access gate in progress
Applications are open. Live customer connections are not. We will not accept pilot payment until each connection and removal path below has passed a real rehearsal.
What connects
Stripe
READ ONLY
A restricted credential you create with read-only access to the payment records needed for the scoreboard. No payouts, refunds, prices, invoices, or money movement.
- We read
- Payment status, amount, customer reference, refund status, and subscription status.
- You remove it
- Delete the restricted credential in Stripe. The pilot stops instead of falling back to broader access.
Email
SELECTED ONLY
You create forwarding rules for only the conversations you want included. We do not connect to your mailbox through Zapier or request permission to send as you.
- We receive
- Only messages matched by the forwarding rules you create. No historic mailbox, contacts, drafts, labels, or unrelated mail.
- You remove it
- Delete or pause the forwarding rules. New email stops immediately.
Cal.com
BOOKING_READ
Cal.com OAuth with the single BOOKING_READ scope. It can view bookings; it cannot create, edit, cancel, or reschedule them.
- We read
- Booking time, event name, attendee details, status, and notes needed to rank follow-up work.
- You remove it
- Ask us to disconnect; stored tokens are deleted immediately and the short-lived access token expires within 30 minutes.
What people can see
Human-supervised means a human may see the evidence.
During the founding pilot, Jesse—the operator—may review source excerpts, the generated brief, and your approve/reject/done replies to catch mistakes and measure the work. No subcontractor gets routine access.
What we keep
- Source data: processed only to prepare the brief; not used to build a permanent copy of your systems.
- Briefs and decision logs: kept through the 30-day pilot so we can measure usefulness.
- Deletion: active pilot data deleted within 7 business days of the pilot ending or your written request; backups age out within 30 days.
- Application data: kept only for pilot selection and follow-up, then deleted on request.
Service providers
No mystery processor chain.
- Stripe supplies payment records.
- Google/Gmail carries only email you choose to forward.
- Cal.com supplies booking records.
- OpenAI helps generate the brief from the permitted inputs.
- Supabase and Vercel host the pilot’s forms and operating surfaces.
When something fails
The brief stops before the guardrails do.
- An incomplete or unsafe brief is withheld and you are notified.
- No connector failure unlocks wider permissions.
- If safe setup cannot be completed within 7 days of payment, you receive a full refund.
- Nothing sends to a customer and no money moves without your direct action.