Privacy
What I do with data.
Plain version: this site collects nothing, and client data stays in the client's own systems.
§01 — The short version
Nothing here is collected. Everything else belongs to the client.
I'm an independent consultant. I build AI-native software for a small number of client organizations — restaurants, foundations, nonprofits, and churches. Two different things are worth separating: this website, and the systems I build for those clients.
This website has no analytics, no cookies, no tracking, and no forms. There is nothing to opt out of.
The client systems hold real operational data, sometimes including data drawn from connected platforms like Google Business Profile. That data is the client's. I handle it on their instruction, use it only to run the software they've asked me to build, and never sell it or reuse it for anyone else.
§02 — This website
timcox.co is a static page.
It's plain HTML served from Vercel. It sets no cookies, runs no analytics or tracking scripts, and has no contact forms or accounts. I don't build a profile of you and I have no way to identify you.
Two ordinary exceptions apply, and they're the same on almost any website:
- Hosting logs. Vercel, which serves this site, records standard request data such as IP address and user agent for security and reliability. I don't use these logs for marketing or analysis.
- Fonts. Typefaces load from Google Fonts, so Google's servers receive your IP address as part of that request. Nothing else about your visit is shared.
If you email me, I have your email — because you emailed me. I keep correspondence as long as it's useful and delete it on request.
§03 — Client systems
I'm a processor, not the owner.
Inside a client engagement I build and operate systems that handle that organization's own data — point-of-sale records, accounting, labor and scheduling, reservations, guest and donor records, and communications. That data belongs to the client, not to me.
Consistent commitments across every engagement:
- Data is used only to deliver the service that client asked for.
- Data is never sold, rented, or shared for advertising.
- Data is never pooled or cross-referenced between clients. Each engagement is isolated.
- Data lives in infrastructure the client controls or that is dedicated to them, and it stays there if we stop working together.
- I take the minimum access needed, and only for as long as the engagement needs it.
If you're a guest, donor, member, or customer of an organization I work with and you want your information corrected or removed, the fastest route is to contact that organization directly — they control the record. You can also reach me at the address below and I'll route it.
§04 — Connected platforms
Access is granted by the client, scoped, and revocable.
Client systems often connect to third-party platforms the organization already uses, so their own information can appear in one place. Examples include point-of-sale and reservation providers, accounting and scheduling systems, email, and business-listing platforms such as Google Business Profile.
How that access works
- The client authorizes it. Access happens only where the organization owns or manages the account and grants access, through that platform's normal authorization flow.
- It's scoped to what's needed. For business-listing platforms that means listing details and reviews — including the review text, rating, and the reviewer's public display name as the platform itself publishes it. I don't request access to unrelated data.
- It's used only for that client. Platform data is displayed to that organization's own authorized staff inside their system, so they can see and respond to feedback about their own business. Replies are published only at a staff member's explicit direction.
- It isn't redistributed. Platform data is not sold, not shared with third parties, not published anywhere else, and not combined with any other client's data.
- It's revocable. The client can withdraw access at any time from their own platform account. On revocation, syncing stops, and stored copies are deleted on request.
Platform data is stored only as a cache so the client's team can work with it — it is never the system of record. The platform remains authoritative, and each platform's own terms and privacy policy continue to govern the underlying data.
§05 — Service providers
Who else touches it.
Client systems run on standard infrastructure. Each provider handles data only to deliver its service, under its own terms:
| Provider | Role |
|---|---|
| Vercel | Application hosting and serving |
| Neon | Managed Postgres database |
| Resend | Transactional and inbound email |
| Anthropic / OpenAI | AI assistant providers, when a user queries their data through an assistant |
| Platform APIs | The client's own connected services — POS, reservations, accounting, listings |
On AI specifically: when someone on a client's team asks a question, the relevant data is sent to the AI provider to answer it. These systems use commercial API terms under which submitted data is not used to train the provider's models. Data is not used to train any model of mine either — I don't train models.
§06 — Retention and deletion
It goes when you say so.
- Website: nothing is retained, because nothing is collected.
- Email to me: kept while relevant, deleted on request.
- Client data: retained per the engagement, for as long as the client needs it operationally. On request or at the end of an engagement, I delete or hand over my copies and remove my access.
- Connected-platform data: deleted from the client's system on request, or when the client revokes access.
Requests are handled promptly — in practice within 30 days, usually much sooner.
§07 — Changes
If this changes, the date changes.
If practices change materially, this page is updated and the effective date at the top moves with it. There's no mailing list to notify, so the date is the honest signal.
Questions, corrections, deletions.
Email is the fastest route, and it reaches me directly — there's no ticket queue.