Public policy
Privacy Policy
This policy explains the information handled by the service, why it is used, and the choices available to workspace members and people represented in monitored public material.
Operated by What Leaders Think LLC · Last updated August 18, 2026
Scope, operator, and contact
This policy applies to What Georgia Thinks. What Leaders Think LLC operates the service and is the data controller for the information described in this policy. Our Meta developer application may appear under the name What Georgia Thinks. Buridan Software provides software-development and technical services to What Leaders Think LLC; it is not the service operator or data controller. The policy covers the website, authenticated workspace, scheduled collection, notifications, optional member email delivery, and evidence-linked briefings. It does not replace the privacy policies of social platforms or other sites linked from collected evidence. Privacy inquiries and requests may be directed to the contact below, which is monitored on behalf of What Leaders Think LLC.
Information we handle
Account and workspace information
When someone creates or uses a workspace, the service handles their display name, email address, authentication session, organization membership and role, organization settings, and information they enter into the workspace. Authentication credentials and session management are provided by Supabase; the application does not store readable passwords.
Roster and public-source information
Administrators choose the people and organizations to monitor. The service may store names, public roles, official websites, profile images, notes, public social-account identifiers, profile metadata, and canonical profile links. It may collect public post text, timestamps, source links, public media and link metadata, platform identifiers, and normalized or raw provider evidence needed to verify and deduplicate collection. The service is not designed to collect private messages or content from private accounts.
Operations, alerts, and device information
The service records collection schedules and cursors, synchronization results, operational error details, import and audit history, alert preferences, and notification delivery status. If a member enables Web Push, it also stores the browser push endpoint and subscription keys, an optional device label, browser user-agent information, and recent-use timestamps required to deliver and troubleshoot notifications.
AI-assisted briefings
Selected collected evidence is sent to OpenAI from the server to generate evidence-linked briefings. Requests use a one-way hashed safety identifier rather than a member's email address and set Responses API object storage to disabled. OpenAI may retain other API data as described in its applicable data-usage and retention terms. Passwords and social-platform access tokens are not included in briefing evidence.
Cookies and analytics
The service uses necessary Supabase authentication cookies to keep members signed in and protect private workspace routes. The current service does not use advertising pixels or third-party behavioral analytics.
Contact-form information
When you use the public contact form, the service handles the name, organization name, phone number, email address, contact reason, and comment you choose to provide. We use that information to route, review, and respond to your request. Resend processes the submission as our email-delivery provider and delivers it to designated contacts for What Leaders Think LLC.
Optional 8 AM Brief email
Members are not enrolled in briefing email automatically. An eligible member may choose delivery in Settings and may turn it off there or use the unsubscribe link in any edition. When delivery is enabled, the service uses the member's confirmed account email and stores the preference, the edition selected for delivery, delivery timestamps and status, and limited provider identifiers needed to prevent duplicates and investigate delivery problems.
Resend processes the recipient address, sender, subject, message body, and delivery events needed to send and operate the email. The service removes its temporary recipient-address copy from the delivery record when that delivery reaches a final state, while limited non-address receipt and security records may remain. The email reuses the completed All Georgia brief already stored in the service; sending it does not generate another brief or make another AI request.
Subscription and billing information
If paid membership is offered and you choose to purchase it, Stripe processes checkout, payment methods, invoices, recurring charges, taxes when enabled, disputes, refunds, and billing self-service under Stripe's own terms and privacy practices. This service stores limited identifiers and status needed to connect your account to a Stripe customer and subscription, such as billing environment, cadence, status, cancellation setting, and paid-period dates. The application does not store your full card number or raw Stripe event payload. No new Checkout or customer-portal session is created while all Stripe processing is disabled. When processor connectivity remains enabled but new Checkout is unavailable, signed webhooks and bounded reconciliation may still update an existing billing relationship, and an existing mapped customer may still use Stripe-hosted account recovery.
How information is used
- Authenticate members and enforce organization-scoped access.
- Maintain rosters, resolve approved public accounts, and collect public evidence.
- Generate feeds, alerts, operational health information, and cited briefings.
- Send The 8 AM Brief to members who expressly enable email delivery.
- Prevent duplicate collection, investigate errors, secure the service, and preserve audit integrity.
- Respond to support, correction, access, and deletion requests.
When information is shared
Workspace information is visible only to authorized members of the applicable organization, subject to their role. Information is processed by service providers needed to operate the product, including Supabase for authentication, database and storage services; Vercel for hosting; Resend for contact-form and optional member email delivery; OpenAI for requested briefings; Buridan Softwarefor software-development and technical services; the approved public APIs used to retrieve source material; and the browser push service selected by a member's device. We may also disclose information when reasonably necessary to comply with law, protect the service or another person, investigate abuse, or establish and defend legal claims.
When paid membership is enabled, Stripe acts as the payment and subscription-billing provider. Payment test data is kept separate from live membership and does not grant member access.
We do not sell personal information or use monitored information for interest-based advertising.
Security
The application uses authenticated sessions, organization-scoped database policies, role checks, server-only provider credentials, bounded provider requests, and audit records. No system can guarantee absolute security. Members should use a unique password, protect their account, and promptly report suspected unauthorized access.
Retention and deletion
Information is retained for as long as reasonably needed to operate the applicable workspace, provide requested evidence and audit history, secure the service, resolve disputes, and meet legal obligations. Retention varies by the type of record and the workspace's use. Pausing or unlinking a social account stops or changes future collection but may preserve evidence that was already collected.
Turning off The 8 AM Brief email prevents new editions from being queued for that member. Limited delivery receipts may be retained for duplicate prevention, security, suppression, and audit purposes without retaining the temporary recipient-address copy in a completed delivery record. Resend may retain message and delivery information under its applicable service terms and account-retention settings.
After a verified deletion request, information covered by the request is deleted or de-identified where applicable. Limited security, audit, backup, or legal records may remain until they are no longer reasonably necessary or age out through provider-controlled backup cycles. See the data deletion instructions for the request process.
We do not complete local account deletion while an associated processor subscription may continue recurring, or while its state cannot be verified. We first require the billing relationship to be canceled or resolved so deletion cannot conceal an ongoing charge. Limited billing, tax, fraud, dispute, and transaction records may remain where required for legal, accounting, or security purposes.
Your choices
- Workspace members may ask to access, correct, or delete their account information.
- Members may disable Web Push in the Alerts workspace or in browser settings.
- Eligible members may turn The 8 AM Brief email on or off in Settings and may unsubscribe from any delivered edition.
- Administrators may pause collection or unlink a public account from a roster.
- A person represented in monitored public material may request a correction or removal review after we verify their identity or authority.
- Removing material from this service does not remove the original material from a social platform; requests concerning the source must be directed to that platform or account owner.
Children
The service is intended for authorized professional and organizational use, not for use by children or the knowing collection of children's private information.
Policy changes
We may update this policy when the service or its data practices change. The date at the top identifies the current version. Material changes will be presented through the service or another appropriate notice.
Contact
For privacy questions or requests, use the contact form. Do not send passwords, social-platform access tokens, or other secrets.
