ExcelsiusBuilt to compound.
The systemWhat it doesSee a sample weekProofPricingStart free

Privacy Policy

What we collect

To run your account and the weekly work, we hold:

  • Your email address and Stripe customer ID (from checkout) — to associate your subscription with your account and contact you about support.
  • Encrypted OAuth tokens (AES-256-GCM) for the accounts you connect — Notion, and optionally Google (Calendar + Gmail) and Stripe. These are held encrypted for as long as you're subscribed and used only inside a managed run to do your weekly work. Each is revocable from that provider's settings.
  • The intake answers you give the Setup Specialist (primary venture, ICP, stage, objectives, voice profile) — used to configure your operating system, stored on your account record.
  • An audit log of runs and provisioning steps (succeeded, retried, failed) — for support and debugging.

How the connected services are used — and their limits

Each connection is scoped to the narrowest access its job needs:

  • Notion — read and write the operating-system workspace we install. Your business data lives here, in your account.
  • Google Calendar — reads your events to avoid conflicts, and creates only solo time-blocks (focus / prep) that you can undo. It never touches your real meetings and never invites anyone.
  • Gmail — draft-only. It creates drafts and never sends; drafts stay in your Gmail for you to send. To draft a reply it reads only that one thread — never the broader inbox and never your contacts.
  • Stripe — read-only, to report on your revenue and subscriptions. It never moves money.

What we do not collect

  • Your business data at large. Your records live in your own Notion workspace and connected accounts — not custodied by us as our own.
  • Your broader mailbox or contact lists. Gmail access is draft-only and single-thread (above); we do not read or index your inbox or build a contact graph.
  • Your customers' financial records or card data. Stripe access is read-only aggregate figures; Stripe never exposes card numbers.
  • Advertising or cross-site tracking. We run no ad pixels and no third-party advertising cookies, and we do not sell your data. For what our analytics tools do collect, see Site analytics below.

Site analytics

We use two analytics tools on excelsius.co. These measure how the site and product are used. That is a separate matter from your business data, which lives in your own connected accounts as described above — analytics tools are never given access to those accounts.

  • Plausible — privacy-focused, cookieless analytics. Aggregate page views, referrers, and country. It sets no cookies and holds no personal identifiers.
  • Microsoft Clarity — product analytics, including session recordings and heatmaps. It captures page interactions — clicks, scrolls, mouse movement — and a replay of the session as it appeared on screen. It sets two first-party cookies (_clck, _clsk) holding a pseudonymous ID so repeat visits can be stitched into one session.

What is masked. Text you type into form fields is masked by Clarity before anything is sent: masking happens in your browser, so the contents of input boxes never reach Microsoft's servers. Under Clarity's default setting, numbers and email addresses shown on the page are masked as well. Other text displayed on screen is not masked.

Where it runs. Clarity is loaded on every page of excelsius.co, including the signed-in product. A recording can therefore include what your cockpit displayed on screen during that session, subject to the masking above.

How long it is kept. Microsoft retains Clarity session recordings for 30 days. Heatmap data, and any individual session that has been labelled or favourited, are retained for 9 months.

We use this to find where the site and the setup flow confuse people, and to fix them. Excelsius does not sell this data or use it for advertising. Microsoft's own handling of Clarity data is governed by the Microsoft Privacy Statement.

How we store it

Account records, sessions, run records, and audit logs live in a Supabase Postgres database we operate, with row-level security. OAuth tokens are encrypted with AES-256-GCM at rest and decrypted only inside a run. We do not sell, rent, or share your data with third parties. See our Security page for how the token vault and infrastructure work.

How long we keep it

For as long as you have an account, so you can return, resume, and see your history. To request deletion of your account record and sessions, email support@excelsius.co with the subject “Delete my data” and we'll process within 30 days.

Your rights

You can revoke any connection at any time from that provider's settings (Notion, Google, or Stripe). If you cancel, you keep your data and operating structure and the managed automation stops running — nothing of yours is taken away. You can request data export or deletion anytime via support email.

Cookies

We use a session cookie to keep you signed in. Plausible sets no cookies at all. Microsoft Clarity sets two first-party cookies, _clck and _clsk, which hold a pseudonymous ID used to group a visitor's page views into a single session — see Site analytics. We do not use third-party advertising cookies.

Changes to this policy

If we materially change this policy, we'll update the date above and notify customers via email.

Contact

Questions or requests: support@excelsius.co