Legal
Privacy policy
Last updated · Document version 1.2.0 · Policy set 2026-09-10.710ed20a
What BuildPersona stores about an executive, how long it is kept, and what deletion removes.
Who this policy is between
BuildPersona is operated by TODO(legal): registered legal entity name, registered at TODO(legal): registered office address, contactable at TODO(legal): privacy contact address. Where the law requires a data protection officer or a representative, that is TODO(legal): data protection officer and any EU/UK representative, or a recorded decision that neither is required. The statutory framework that applies is TODO(legal): governing data protection law and the supervisory authority a customer may complain to.
BuildPersona has two kinds of customer, and the relationship differs between them.
An executive using BuildPersona for themselves
You are the customer, and we decide how your account data is handled in order to run the service. The profile in the workspace is yours.
An agency workspace holding client profiles
An agency creates a profile for each executive it works with, and that profile contains personal data about a person who is not the account holder. In that arrangement the agency decides what to collect and what to publish, and BuildPersona processes that data on the agency’s instructions. The agency is responsible for having the executive’s authorisation before entering their LinkedIn URL, uploading their voice, or publishing in their name, and for telling that executive that BuildPersona holds their data. A written data processing agreement between the agency and BuildPersona is TODO(legal): data processing agreement: whether one is offered, its terms, and whether standard contractual clauses are needed.
What BuildPersona stores
Account and session
- Your name, email address and a hashed password.
- Whether your email is verified, and the one-time tokens used to verify it or reset a password.
- Session records, which include the IP address your request arrived from and your browser’s user agent string.
Workspace and billing
- Workspace name, plan, billing cadence, profile limit, trial end and subscription status.
- The customer and subscription identifiers issued by our payment provider. BuildPersona never receives or stores card details.
- Invitations you send, including the invitee’s email address, and metered usage counts per billing period.
The executive profile
- Name, role, company, LinkedIn profile URL and the goal written at setup.
- The interview answers, the personalised question set and the voice brief derived from them.
- The public LinkedIn profile data returned by our scraping sub-processor: headline, about text, experience, skills, recommendations, activity, follower and connection counts, and profile and banner image URLs, together with the score and analysis computed from them. Each evaluation adds a new report; earlier reports are kept and can be compared.
- Corrections you make to extracted values. A correction is append-only: the original extracted value, the corrected value, the reason and who made it are stored permanently and cannot be edited or withdrawn while the profile exists.
- Source visibility choices. Marking a source private or removed excludes it from what is sent for generation; it does not delete the underlying record.
Voice, ideas and content
- Voice recordings you make in the interview, send over a capture link, or send over WhatsApp, stored as files in private object storage, and the transcripts produced from them.
- Your original ideas and notes, every draft, and an immutable snapshot of every revision of a post.
- Approval records, publication attempts, the destination LinkedIn member identifier and the published post URL.
Messaging and integrations
- If a capture link is created for your profile: the notes and voice notes sent to it become ideas and stored files, alongside a record of when the link was created, how many submissions it received, and when it was last used. The link itself is stored only as a hash, and whoever holds it is not identified or asked to sign in.
- If you connect WhatsApp: the phone number or business-scoped user identifier you verified, a short-lived hash of the verification code while it is pending, the connection history, and one routing record per inbound message. The message text and any media you send become ideas and stored files.
- If you connect LinkedIn: your LinkedIn member identifier, display name, granted scopes, and an access token encrypted at rest.
Activity
An activity log records who did what and when — corrections, visibility changes, exports, assignment changes, deletion requests — so a workspace owner can see how a profile was handled.
Where it is stored
All records are held in a Cloudflare D1 database. All uploaded and received files — images, PDFs and voice notes — are held in a private Cloudflare R2 bucket. No stored file is publicly addressable: every read is served through the application, which re-checks that the requester still has access to that profile. The regions these run in are TODO(legal): Cloudflare data location and any residency commitment.
Generated text is never treated as something you said
BuildPersona drafts posts from material you supply. Those drafts are drafts. The generation instructions forbid inventing employers, names, qualifications, clients, anecdotes, metrics, dates, endorsements or results, forbid inferring sensitive personal traits, and forbid promising reach, leads or growth. Values you supplied as corrections are marked as your own statements rather than as verified extracted evidence, and material you marked private is withheld from the request entirely.
Your original interview answers and your voice-note transcripts are preserved unchanged alongside the drafts. Generated text does not replace them and is never recorded as evidence of what you actually said.
Who else sees this data
BuildPersona sends data to a small number of named sub-processors in order to work at all. Each one, what reaches it and why is listed in Data processing and sub-processors. There are no advertising networks, no analytics services and no data brokers in that list, and BuildPersona does not sell personal data.
Inside a workspace, an owner sees every profile. Editors see only the profiles they are assigned to. Nothing is shared between workspaces.
The lawful basis relied on for each purpose is TODO(legal): lawful bases per purpose — contract, legitimate interests, or consent — and the legitimate-interests assessment where relied on.
How long it is kept
BuildPersona is honest about this rather than aspirational: outside the deletion workflow below, customer content does not expire. Profiles, reports, ideas, drafts, revisions, publication records, stored files and the activity log are kept until a workspace or account is deleted. Whether an inactive or cancelled workspace should be aged out automatically, and after how long, is TODO(legal): retention period for an inactive or cancelled workspace, and for the retained billing and audit records below.
Only these short-lived records are removed on a schedule:
| Record | Removed after |
|---|---|
| Pending LinkedIn sign-in state | 10 minutes |
| Pending WhatsApp verification code | 10 minutes |
| Application rate-limit counters | 24 hours past expiry |
| Expired email verification and reset tokens | 7 days past expiry |
| Provider webhook de-duplication keys, including WhatsApp message identifiers | 30 days |
Session records are not removed when they expire: a session stops authenticating after seven days, and the row itself is deleted when the account is deleted. The rate-limit keys the authentication library keeps for sign-in attempts are not swept at all.
Deleting your data
A workspace owner can delete a workspace, and any account holder can delete their account, from workspace settings. Deletion is scheduled, never immediate: there is a seven-day grace window in which you can cancel it. After that the purge runs on the next scheduled sweep, and retries automatically if it fails.
What deletion removes
Every stored file for the workspace is deleted from object storage before any database row is removed, so nothing is left pointing at a file that is gone. Then the workspace and everything scoped to it goes: profiles, interview answers, reports, assessments, corrections, source visibility, ideas, posts, every revision, publication attempts, media records, invitations, activity, queued work, usage counts, memberships, LinkedIn connections and WhatsApp pairings. Deleting an account also deletes the owner’s workspaces, the password record, all sessions, all pending verification tokens and all assignments.
What deletion deliberately keeps
- A billing record — plan, billing cadence, billing status, and the payment provider’s customer and subscription identifiers — kept for accounting and payment-dispute purposes. It contains no content.
- A deletion audit record: what was requested, by whom, when it was requested and when it completed.
- If another member’s retained content still names your account as its author, approver, inviter or LinkedIn connector, the user row becomes an anonymised tombstone rather than disappearing: the name becomes “Deleted account”, the email becomes a non-routable placeholder, and the profile image is removed. Only the internal identifier survives, so another member’s content history does not silently break.
What deletion cannot reach
- Posts already published to LinkedIn. They are on LinkedIn and must be removed there.
- LinkedIn access. LinkedIn publishes no token revocation endpoint, so BuildPersona destroys its copy of the token and records the token’s real state at LinkedIn rather than claiming a revocation. Remove the BuildPersona application from your LinkedIn settings to be certain.
- Copies held by sub-processors under their own retention: scraping run datasets, WhatsApp message history at Meta, email delivery logs, and payment records at the payment provider.
- Encrypted backups taken before the deletion, until those backups age out. The backup retention period is TODO(legal): backup retention period and restore reconciliation.
Security
- Passwords are hashed; the plain password is never stored.
- LinkedIn access tokens are encrypted with AES-GCM before being written to the database.
- Uploaded files live in a private bucket and are only ever served through an access check.
- Incoming webhooks from WhatsApp and the payment provider are rejected unless their signature verifies, and a repeated event is processed once.
- Sessions expire after seven days.
The breach-notification commitment and timeline is TODO(legal): breach notification commitment: who is told, how quickly, and under which statutory deadline.
Your rights
You can see and correct your profile data in the application, export a profile’s source material and reports, and delete your workspace or account as described above. The statutory rights that apply on top of that — access, portability, objection, restriction, and how to complain to a regulator — depend on the jurisdiction, which is TODO(legal): governing jurisdiction and the statutory rights and response deadlines that follow from it. Requests can be sent to TODO(legal): privacy contact address.
BuildPersona is a business tool and is not directed at children. The minimum age of use is TODO(legal): minimum age of use and how it is checked.
Changes to this policy
Each policy carries a document version and the whole set carries a policy-set version, both shown at the top of this page and published as page metadata so a change can be detected. When the set version changes, the application asks you to review and accept the new version the next time you sign in, and records that you did with a timestamp.