Privacy Policy

What we collect, why we collect it, and the choices you have.

Last updated

This policy explains how Escape Hatch, LLC (“Escape Hatch,” “we,” or “us”), a North Carolina limited liability company, handles personal information on heymeri.com and in the Northstar preview (together, the “Service”).

Northstar is currently an invite-only preview. We are not selling subscriptions, and we do not process payments through the Service today. If that changes, we will update this policy before the change takes effect.

The short version

  • We run no advertising or analytics trackers on this site. No Google Analytics, no ad pixels, no third-party session recording.
  • We never sell or rent personal information, and we never have.
  • The only cookie we set is the one that keeps you signed in. There is no tracking cookie to consent to.
  • If you are on the invite list and want off it, email privacy@heymeri.com and we will delete your address.

Information we collect

If you join the invite list

We collect the email address you submit, plus the date you confirmed. Signup is double opt-in: submitting the form sends you a confirmation email, and your address is only added to the list after you click the link in it. If you never confirm, the address is not added.

If you have an account

  • Account details — your name and email address. If you sign in with a password, we store only a salted hash of it, never the password itself.
  • Sign-in provider identifiers — if you use GitHub or Google to sign in, we receive your identifier, email address, name, and profile image from that provider. We do not receive your password, and we do not get access to your repositories or documents.
  • Content you create — projects, stories, decisions, sessions, notes, and anything else you enter into Northstar.

Automatically, on every visit

  • IP address — used to rate-limit the signup and password-reset forms so they cannot be abused to send mail to people who did not ask for it. We do not build profiles from it or use it for advertising.
  • Session cookie — set only after you sign in, so you stay signed in between pages. It is strictly necessary for the Service to function.
  • Standard server logs — request paths, timestamps, and error traces, kept for security and debugging.

How we use it

Under the GDPR, our legal bases are:

  • Consent — sending you invite-list email. You gave it by confirming the double opt-in, and you can withdraw it at any time.
  • Performance of a contract — operating your account and storing the content you create, so the Service works.
  • Legitimate interests — keeping the Service secure, preventing abuse of our forms, diagnosing errors, and understanding aggregate usage. We balance these against your rights and use the least data that achieves the purpose.

AI processing — please read this part

Northstar uses large language models to help plan and analyze your work. When a feature does this, the relevant content you have entered is transmitted to a third-party model provider (currently Anthropic and/or OpenAI) so it can generate a response. That content leaves our infrastructure.

We access these providers through their business/API offerings and do not authorize them to use your content to train their models. We do not use your content to train models of our own. If you would rather not have particular material processed this way, do not enter it into Northstar.

Who we share it with

We do not sell, rent, or trade personal information. We share it only with service providers who process it on our behalf:

ProviderWhat they handle
MailjetDelivering confirmation and notification email; storing the invite list
Anthropic / OpenAIProcessing content you submit to AI-assisted features
Our hosting and database providersRunning the servers and storing the database

We may also disclose information if legally required, or to protect the rights, safety, or property of Escape Hatch or others. If Escape Hatch is ever involved in a merger, acquisition, or asset sale, information may transfer as part of that transaction; we will give notice before your information becomes subject to a different privacy policy.

How long we keep it

  • Invite-list addresses — until you unsubscribe or ask us to delete them, or until we retire the list.
  • Account data and your content — for as long as your account exists. Delete your account and we remove them, other than anything we must retain by law.
  • Server logs — a short operational window, then discarded.

Your rights

Wherever you live, you can ask us to access, correct, export, or delete your personal information by emailing privacy@heymeri.com. We will not treat you differently for exercising any of these rights.

If you are in the EEA or UK

You have the right to access, rectify, erase, restrict, and port your data, to object to processing based on legitimate interests, and to withdraw consent at any time (withdrawal does not affect processing already carried out). You may also lodge a complaint with your local supervisory authority.

If you are in California

You have the right to know what we collect and why, to delete it, to correct it, and to be free from discrimination for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not process it for cross-context behavioral advertising.

International transfers

We operate from the United States, and our providers may process data there and in other countries. If you access the Service from outside the US, you understand your information will be transferred to and processed in the US, where data-protection law differs from your own.

Security

Traffic is encrypted in transit with TLS. Passwords are stored only as salted hashes. Credentials you connect to Northstar are encrypted at rest with AES-256-GCM. Access to production data is limited to people who need it to operate the Service. No system is perfectly secure, and we cannot guarantee absolute security.

Children

The Service is not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child has given us information, email us and we will delete it.

Changes to this policy

We will update the date at the top when this policy changes. For material changes we will give notice through the Service or by email before they take effect.

Contact

Escape Hatch, LLC — a North Carolina limited liability company.
privacy@heymeri.com