Skip to content

Legal

Privacy policy

What we collect, who else touches it, why we collect it, and how to make us forget it. In plain language.

Template. Have counsel review.

This page is written in plain language and has not yet been reviewed by a lawyer. If anything here matters to a decision you’re making, ask us first: hello@finishingpass.com.

Last updated: August 23, 2026

The short version

  • We collect the email you start with, and the report your agent produced when you submit it for analysis. That’s the product working, not surveillance.
  • Your report is sent to an outside AI provider to be analysed. That is how the analysis happens, and you should know it before you send anything.
  • We never ask for your source code, repository access, or credentials, and we never receive them.
  • We don’t sell your data. We don’t run ad trackers.
  • We don’t keep it forever. A submission is kept up to 24 months, an assistant conversation 90 days, and the clock restarts each time you use it, so only a dormant record ages out.
  • Your results page has a “Delete my data” button and an “Email me a copy of my data” button. You don’t have to ask us for either one.

What we collect

  • Your start details. Your email address, and an optional first name. That is all it takes to start; we ask nothing about your project to hand you the audit skills. Every purchase requires an email address before it is created, so there is always somewhere to send your results and always an address to confirm a deletion request against.
  • Your report and project details. The markdown report your agent produced, plus the platform you built with and a project name. You submit it to get The Readiness Report, before any payment. You choose what the report contains. We ask for your agent’s findings, never for your code, and we suggest you skim it before sending.
  • Your chat with Sarah. If you use the on-site assistant, we store that conversation and a short profile it infers from it (your role, your stage, and the concern you lead with) so the thread stays coherent across turns. Common questions may be kept in a small shared cache so identical questions get consistent answers. You can use the whole site without chatting.
  • Payment records, only if you buy the Finishing Pass. Payments are processed by Stripe. We receive confirmation that you paid and basic receipt details; your card number never touches our servers. The free report involves no payment data at all.
  • Ordinary server logs. Requests to the site (address requested, time, IP) for keeping the service running and diagnosing problems.

What’s in the Readiness Report, and why we treat it carefully

Be clear-eyed about what this document is: your agent’s written account of where your own product is weak. Missing access checks, unprotected data, gaps in how payments or accounts behave. It is not your code, and it contains no credentials, but a list of your product’s soft spots is sensitive on its own terms.

So: you decide what goes in it, and you can read it before you send it. We store it in our own database on AWS, reachable only by the private link we email you and by the small number of people who run the service. We don’t publish it, don’t share it as an example, and don’t show it to anyone else without your written permission. You can delete it yourself at any time from your results page, and if you never do, it ages out on its own.

Who else processes your data

We use a few outside companies to run the service. They only get what their job needs, and only to do that job for us.

  • OpenAI— the AI model that analyses your report and powers the Sarah chat. Your report content and your chat messages are sent to OpenAI’s API to produce the analysis and the replies. OpenAI states that data sent to its API is not used to train its models.
  • Amazon Web Services (AWS)— hosting, database, and storage, in the us-east-1 region in the United States. Your application, report, results, and chat sessions live here.
  • Stripe— payment processing and receipts, only if you buy the Finishing Pass. Stripe holds the card details; we don’t.
  • Resend— transactional email: your sign-in link, your results link, and your receipt. It sees your email address and the contents of those messages.

If we add or change a provider in a way that matters, we’ll update this list and the date at the top.

Why we collect it

One reason: to run the service. Your email is how we send your Readiness Report link and answer you. The report and details you submit are the inputs to the analysis, which produces your report and, if you buy the pass, your fixes. Your results are stored so your private link keeps working. We may also read submissions when something fails, to fix the failure and improve the method. If you chat with Sarah, those messages and the short inferred profile keep the conversation coherent from one turn to the next, and the shared cache helps us answer common questions consistently.

What we don’t do

  • We don’t sell or rent your data. To anyone.
  • We don’t share it for advertising, and we don’t run ad trackers.
  • We don’t train public models on your submissions.
  • We never ask for your source code, repository access, or credentials.

Cookies

The marketing site sets no cookies of its own. The application and results flow uses only what’s strictly needed to function. If you buy the Finishing Pass, Stripe sets its own cookies during checkout, under its own policy.

How long we keep it

Nothing you send us is kept indefinitely any more. Each record carries an expiry date, and the clock runs from the last time that record was updated — so it slides. Coming back to your pass moves the date forward, and only a record nobody has touched ages out.

  • Your submission: your name, email, project details, the Readiness Report, and our analysis of it — kept up to 24 months from the last time the record changed.
  • Your chat with Sarah, and the search index built from your report: kept up to 90 days, on the same sliding basis.
  • Server logs:short-lived operational logs, kept only as long as they’re useful for diagnosing problems.
  • Payment records:held by Stripe for as long as the law requires them to keep financial records. That part isn’t ours to shorten.

Deletion at expiry is automatic: the database drops the record itself, without anyone deciding to. It isn’t to the minute — expect it within roughly 48 hours of the deadline rather than the instant it passes. So read these as “no later than” periods. If we change one of them, this page changes with it.

Deleting your data

On your results page there is a Delete my data control. Pressing it doesn’t delete anything. It sends a confirmation link to the email address on the record. That link expires in 30 minutes and works once.

The email step is there to protect you, and it’s worth saying why plainly. Anyone holding your results link can already read the page — a link in a browser history, or forwarded to a colleague. If a button on that page destroyed your data outright, the link would become a way for someone else to destroy it. Being able to open your inbox is a genuinely different thing from holding a URL, so we confirm there first.

The link only opens a confirmation page showing exactly what will go. Nothing is deleted until you press the button on that page.

What we then remove:

  • The submission: your name, email, project details, the Readiness Report, our written analysis, and what you typed.
  • The search index built from your report.
  • Any chat with Sarah tied to that results page.

Afterwards your results link stops working. This is permanent; we have no copy to restore from.

What deletion doesn’t remove

A few things survive a deletion request. None of them are buried in a footnote, because you should know before you press the button.

  • Payment records.If you bought the pass, Stripe holds its own record of that payment under its retention rules, and we can’t reach into it. Our own record of the sale is kept as a financial and accounting record. Businesses are required to keep those, which is exactly why this exception exists.
  • A promo or beta code redemption.We keep the fact that the code was used, with your email address replaced by a one-way scramble of it rather than the address itself — enough to stop a limited code being claimed twice, not enough to tell us who you were.
  • A chat that was never tied to a results page.If you talked to Sarah while browsing the site, before there was a submission, that conversation has no link to any record — so a deletion request has no way to find it. Those conversations expire on the 90-day timetable instead. We’d rather tell you that than imply the deletion reaches everything.
  • The shared answer cache.When a question gets asked often, we keep the question and its answer in a small shared cache so everyone gets a consistent reply. It isn’t tied to you or to any record, so a deletion request can’t single it out. Entries expire on the same 90-day timetable.

Getting a copy of your data

The same results page has an Email me a copy of my datacontrol, and it works the same way: a confirmation link to the address on the record, good for 30 minutes and one use. Confirm it and we send you a JSON file containing your submission record and any chat with Sarah tied to it. Security tokens attached to the record are left out on purpose — handing those back in a file would turn a data request into a way in.

Your rights

Depending on where you live (GDPR in Europe, CCPA in California, and similar laws elsewhere), you may have rights over your personal data. We honor the spirit of these regardless of geography. In plain terms, you can ask us to:

  • Show you what we hold.We’ll tell you what we have about you.
  • Send you a copy. Your submission and your chats, in a file you can keep and take elsewhere. You can do this yourself from your results page.
  • Fix something wrong. A misspelled name, the wrong email.
  • Delete it. Also yours to do, from the same page. See the sections just above for what goes and what stays.
  • Object, or complain.If you think we’ve handled something badly, tell us first and we’ll try to put it right. You can also complain to your local data protection authority.

Deletion and export are self-serve on your results page. For anything else, one address does it: hello@finishingpass.com. No form, no portal. We may need to check you’re the person the data belongs to before acting — which is the same reason the self-serve controls confirm by email.

Beta testers

If you’re testing Finishing Pass for free, this policy applies to you too, alongside the beta testing terms. The short version: we will not publish your name, your company, or anything from your report without your written permission.

Changes

If this policy changes in a way that matters, we’ll note it here with a new date. We won’t quietly expand what we collect.

Contact

Tekton, at [Tekton legal entity], [registered address]: hello@finishingpass.com