Privacy Statement
Last updated 3 August 2026
This describes what the Service holds about you, where it goes, and how long it stays. The data controller is MakeBelieve, LLC, a Wyoming limited liability company (United States), reachable at iamkirkperry@gmail.com.
The residents are not data subjects. AskSociety’s population is synthetic: names, ages, biographies, quotes and portraits are generated by software and correspond to no living person. This statement is about your data — your account and the material you put into the Service — not about them.
1. What we hold
| What | Why | How long |
|---|---|---|
| Your email address and name | To identify your account, sign you in, and send you results | Until the account is deleted |
| Your questions, uploaded documents, pasted material, and any URL you ask the Service to read | To run studies and to show your own work back to you | Until you delete it or the account is deleted |
| Studies and their output — audiences, resident answers, reports, exchanges, portraits, decision-ledger entries | So past work stays available to reopen and export | Until you delete it or the account is deleted |
| Credit balance and charges | Billing, and to reconcile refunds on runs that fail | Kept as a financial record for seven years, per U.S. tax record-keeping practice |
| Product-usage events (which screens and features are used, keyed to your account) | To see which parts of the product are worth keeping | Until the account is deleted |
| In-flight run state and the live answer feed | To drive the progress screen while a study runs | 30 days for run state; 6 hours for the live feed |
| Sign-in link tokens | To let you sign in without a password | 15 minutes, then unusable |
| Session cookie | To keep you signed in | 30 days, then you sign in again |
| Server logs | To diagnose failures | Held by our hosting provider for a limited period, typically no more than 30 days |
We do not ask for, and have no use for, special-category data — health, political opinions, biometrics, and so on. Please do not put it in. If you upload material containing personal data about identifiable third parties, you are the controller of that data and you need your own lawful basis for sending it to the processors below.
Cookies and tracking
One cookie: the signed session cookie that keeps you logged in. There is no advertising cookie, no third-party analytics script, no tracking pixel, and no externally hosted font. Usage measurement is first-party, stored in our own database, and never leaves it.
2. Who else processes it
Running a study means sending your material to model providers. This is not optional — it is what the product does — so it is stated plainly:
| Processor | What reaches them | What for |
|---|---|---|
| Anthropic | Your question, your material and uploaded documents, the audience description, resident answers, and follow-up questions you ask | Reading your question, reading attachments, generating resident answers, writing the report, and — if you buy a research pass — web search run on Anthropic’s servers |
| OpenAI | Dictated audio; a text description of a synthetic resident | Voice-to-text when you dictate, and generating resident portraits |
| Resend | Your email address and the message body | Sign-in links and run notifications |
| Railway | Everything, at rest — they host the app, the database and the queue | Hosting |
We do not sell data, share it with advertisers, or hand it to anyone not on this list, except where the law requires it. If we add a processor that changes what leaves our systems, we will update this table and tell you.
Everything is hosted in the United States. The Service is offered from the U.S. and is not currently marketed to the EU/EEA or UK; if you use it from elsewhere, your data is processed in the U.S. If your situation requires a specific transfer mechanism, tell us before you buy and we will work it out with you in writing.
3. Isolation between customers
Your societies, studies, residents and results are scoped to your account. Another customer cannot open them, and a request for something that is not yours is answered as if it does not exist rather than as “not allowed” — a refusal that confirms existence is itself a leak. This is enforced by tests that walk every route and fail the build if a new one ships without the check.
The operator’s view is deliberately limited. To support you we can see that a run exists, its status, its size and its cost. We cannot open your questions, your material, your residents’ answers or your reports through the operator view — the ownership rule has no administrator exception in it, and a test fails if one is ever added. Direct database access exists, as it must for any hosted service, and is used for operations and support rather than as routine reading.
4. What you can do today
Stated as it actually is, rather than as it should eventually be:
- Export a study — self-serve, now. Every completed study exports as CSV, JSON and PDF from its results page. The CSV carries the full per-resident detail, including the numeric scales the written report leaves out.
- Delete a society — self-serve, now, as long as no study has been run against it. Once a society has studies, deleting it would orphan results you paid for, so the Service refuses and asks you to say what you want removed.
- Delete a study, export your whole account, or close your account — by request. There is no button for these yet. Email us and we do it by hand, within 30 days. We will confirm in writing when it is done.
- Correct your account details — ask, and we will change them.
Closing an account removes your account record, societies, studies, resident histories, reports, conversations and saved residents. Billing records are kept as long as we are required to keep them. Material already sent to a model provider is subject to that provider’s own retention, which we do not control.
Depending on where you live you may have statutory rights of access, correction, erasure, portability and objection. The routes above are how you exercise them here, and you may also have the right to complain to your local data protection authority. We have not appointed an EU or UK representative; if you are in a jurisdiction that requires one, contact us before relying on the Service.
5. Security, honestly stated
Sign-in is by emailed link with no password to steal; sessions are signed cookies; traffic is encrypted in transit; data at rest sits in our provider’s managed Postgres and Redis; the app refuses to start in production without its credentials configured, rather than booting into an unsafe default. Access to production is limited to the people who operate the Service.
What we will not claim: we hold no security certification, we have not been independently audited, and this is early software. If you are placing genuinely sensitive material in front of it, that is a reason to keep that material out of the Service, not a reason for us to reassure you. If we confirm a breach affecting your data, we will notify you without undue delay and within any timeframe the law requires, telling you what was involved and what we are doing about it.
6. Contact
Data questions, export requests and deletion requests: iamkirkperry@gmail.com. A real person reads it.