Privacy Policy
Effective July 6, 2026 · Contact: hello@getphilos.ai
1. What we collect
Account data — your email address and the workspace profile you provide during onboarding.
Business data — campaign settings, partner enrollments (partner name, email, channels), and conversion records merchants’ systems send us (order references, amounts, timestamps).
Public site data — to generate a merchant’s onboarding report we read their public website.
Technical data — when you click a referral link or request a sign-in link we record a one-way hash of your IP address for fraud prevention and rate limiting; we do not store raw IP addresses with your activity. Sign-in tokens are stored only as cryptographic hashes.
2. Cookies
We use first-party cookies only: a session cookie that keeps you signed in (30 days) and, after you click a partner’s referral link, an attribution cookie that remembers the referral for 30 days so the partner gets credit. Both are httpOnly and never readable by page scripts. We run no third-party advertising trackers and no third-party analytics.
3. How we use data
To operate the service: signing you in, attributing referrals, verifying conversions, preventing fraud, calculating and paying rewards, generating your onboarding report and content drafts, and emailing you sign-in links and service notices. We do not sell personal data, and we do not use your business data to market to your customers.
4. Who processes it
Philos runs on a small set of processors: Vercel (hosting), Supabase (database, us-east-1), Resend (transactional email), Anthropic (AI features — content passed for drafting and analysis; not used to train their models per our API terms), and Stripe (billing and payouts, when enabled). Each receives only what its function requires.
5. Retention, and erasure by redaction
Financial records — the conversion ledger, payout history, audit log — are append-only and retained for bookkeeping and dispute integrity. Personal details inside them are removable: partners can erase their personal data from their portal, and customer (referee) erasure requests are honored by redacting the referral’s identifying details and provider references while the anonymous money history stays true. Every erasure action is itself audit-logged. Account data is deleted when a workspace closes, subject to the financial-record retention above.
6. Your rights
You can request access to, correction of, or erasure of your personal data by emailing hello@getphilos.ai. If you are in the EU/UK or California, you may have additional statutory rights (GDPR, CCPA); we honor them regardless of where you are. We respond within 30 days.
7. Security
Everything is served over TLS. Sign-in links are single-use, expire in 30 minutes, and are stored only as hashes. The database denies all direct access by default; every read and write passes through our server with live permission checks. Sensitive actions land in an append-only audit log. No system is perfect — if we learn of a breach affecting your data, we will notify you without undue delay.
8. Children
Philos is not directed at children and may not be used by anyone under 16.
9. Changes
Material changes to this policy are posted here with a new effective date; significant changes are emailed to workspace owners.
Questions or requests: hello@getphilos.ai · See also the Terms of Service.
