ModelHubby scout badgeModelHubbyFIELD MANUAL · EST. 2026
Field Manual · Legal · Doc 2 of 3

Privacy Policy

Last updated: 2026-07-18

ModelHubby collects very little, and this page lists all of it. The data controller is J. Peter Wheeler, trading as CHAOSAiGENT. For anything privacy-related — questions, access, deletion — email hello@jpeterwheeler.com. Where EU/UK GDPR applies, that address is also your contact point for exercising your rights.

1. What we collect, and why

  • Waitlist: your email plus an optional “what are you building” note. Used to tell you about launch and founding pricing. Legal basis: your consent (you typed it into the form).
  • Account: your sign-in email and session data (magic-link/OTP auth — no passwords stored, ever). Legal basis: performing our contract with you.
  • Entitlements: which plan you’re on and its status, so paid content unlocks. Legal basis: contract.
  • Payments: handled entirely by Stripe. We see plan, amount, and billing status — never your card number.
  • Analytics (once enabled): product usage events via PostHog — pages viewed, features used. We use it to see what’s working, not to build ad profiles; there is no third-party ad tracking on this site. Legal basis: legitimate interest in improving the product.
  • Emails you send us: kept as ordinary correspondence.
  • Hosting logs: Vercel keeps short-lived request logs (IP, user agent) to serve and secure the site.

We do not sell or rent your data to anyone, and we don’t buy data about you.

2. Who processes it for us

  • Supabase — database and authentication (waitlist, accounts, entitlements).
  • Stripe — payment processing and billing.
  • Vercel — website hosting.
  • PostHog (US cloud) — product analytics, once enabled.

Some of these process data in the United States. Transfers rely on the processors’ standard safeguards (EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework, per each processor’s terms).

3. Cookies & localStorage

  • Supabase session — a token in your browser’s localStorage that keeps you signed in. Strictly functional.
  • PostHog — if analytics is enabled, PostHog stores an anonymous identifier (cookie/localStorage) to count visits sensibly. If analytics isn’t enabled in the build, nothing is set and no analytics network calls are made.

There are no advertising or cross-site tracking cookies.

4. How long we keep it

  • Waitlist: until launch outreach wraps up or you ask to be removed, whichever comes first.
  • Account & entitlements: while your account is active; deleted on request (see below).
  • Billing records: kept as long as tax and accounting law requires, even after account deletion.
  • Analytics events: per PostHog’s standard retention; not tied to deleted accounts.

5. Your rights

You can ask for a copy of your data, correct it, export it, object to processing, or have it deleted. One email to hello@jpeterwheeler.com does it — expect a reply within a few days, not a legal runaround. If you’re in the EU/UK and think we’ve handled your data badly, you also have the right to complain to your local data protection authority (but please try us first).

6. Changes

If this policy changes materially — for example when analytics is switched on, or a processor is added — we’ll update this page and its date stamp, and email account holders when it matters. See also our Terms of Service.

Questions about any of this? Write to hello@jpeterwheeler.com — a human (the only one here) reads every message.