AI Employee Builder — Privacy Policy
Last updated 29 July 2026
This policy covers the AI Employee Builder connector and the server behind it
(aieb-gated-mcp.vercel.app), operated by Chief Leverage Officer.
The short version
The connector sends instructions to your AI assistant. It does not collect your work. Your files, prompts, business documents and anything your assistant produces stay on your own machine and are never transmitted to us. We store the minimum needed to check whether your subscription is active and to keep the service running — and where we store anything that could identify you, we store a one-way cryptographic hash of it rather than the value itself.
What we collect
| What | Why | Form it is stored in |
|---|---|---|
| Subscription and licence status | To confirm you are entitled to the content you request | A pseudonymous member reference derived from your payment-provider customer ID. We do not store licence keys. |
| Connection (device) token | To recognise an authorised installation without you re-entering credentials | An opaque random token; the server keeps only a hash of it, plus a pseudonymous device reference. |
| Email address | To match a sign-in to a purchase, and for support | A one-way hash only. The plaintext address is not stored in our database and cannot be recovered from it. |
| Usage events | To see which features work, and to detect faults | Fixed categories only — which skill was requested, plan tier, success or failure code, connector version, timestamp. Free text, prompts, file paths, document contents and business details are rejected by design, not merely discouraged. |
| Course sign-in and progress | So your place in the course follows you between devices | A hash of your Google account identifier, a hash of your email, and which lessons you have completed. Session tokens are stored as hashes. |
| IP address | Rate limiting and abuse prevention only | Held transiently against short-lived rate-limit counters, and in standard server logs. |
| Agreement records | To record acceptance of the content licence | A member reference, the version agreed to, and a timestamp. |
What we never collect
- The contents of your files, workspace, or business documents.
- Your prompts, conversations, or anything your assistant generates.
- Plaintext email addresses in our database.
- Licence keys, which are never logged, printed, or stored in plaintext.
- Payment card details, which are handled entirely by our payment provider and never reach us.
How it is used
Only to operate the service: confirming entitlement, serving the content you have paid for, keeping your progress in sync, preventing abuse, diagnosing faults, and understanding in aggregate which features are used. We do not sell personal data, we do not share it for advertising, and we do not use it to build profiles for third parties.
Who else is involved
- Lemon Squeezy — payments, subscriptions and licence validation.
- Vercel — hosting.
- Neon — database hosting.
- Google — optional sign-in for the course portal, if you choose to use it.
Each processes data on our behalf under its own terms. Operational alerts (for example, a failed connection) may be sent to the operator through internal messaging and reporting tools; these carry pseudonymous references and error categories, not your content.
The AI assistant you run the connector in — such as Claude or another MCP-compatible client — is provided by its own vendor under its own privacy policy. We do not receive your conversations from it.
How long we keep it
- Subscription and entitlement records — for as long as your subscription is active, and for a limited period afterwards to support reactivation, billing enquiries and our own legal and accounting obligations.
- Connection tokens — until you disconnect, reconnect on another machine, or the token is revoked, at which point the record is invalidated.
- Usage events — retained in categorised form for service analysis. They contain no content and are not linked to a plaintext identity.
- Course sessions — until you sign out or the session expires. Progress is kept while your account exists so you do not lose your place.
- Rate-limit records — transient, discarded automatically.
Your choices
You can disconnect the connector at any time, which stops all data flowing to us. You can ask us for a copy of what we hold that relates to you, ask us to correct it, or ask us to delete it — bearing in mind that records we hold only as hashes cannot be searched by address unless you tell us which address to hash. Cancelling your subscription stops further collection.
Children
This service is intended for business use by adults and is not directed at children.
Changes
If this policy changes materially we will update the date at the top of this page and, where the change affects how your data is handled, notify active subscribers by email.
Contact
Questions, requests, or anything you think this page gets wrong: rashid@thepeakperformer.io.
Chief Leverage Officer — AI Employee Builder. See also the content licence.