Tim Cox Back to timcox.co

Privacy

What I do with data.

Plain version: this site collects nothing, and client data stays in the client's own systems.

Effective 20 July 2026 · Tim Cox · Brooklyn, NY

§01 — The short version

Nothing here is collected. Everything else belongs to the client.

I'm an independent consultant. I build AI-native software for a small number of client organizations — restaurants, foundations, nonprofits, and churches. Two different things are worth separating: this website, and the systems I build for those clients.

This website has no analytics, no cookies, no tracking, and no forms. There is nothing to opt out of.

The client systems hold real operational data, sometimes including data drawn from connected platforms like Google Business Profile. That data is the client's. I handle it on their instruction, use it only to run the software they've asked me to build, and never sell it or reuse it for anyone else.

§02 — This website

timcox.co is a static page.

It's plain HTML served from Vercel. It sets no cookies, runs no analytics or tracking scripts, and has no contact forms or accounts. I don't build a profile of you and I have no way to identify you.

Two ordinary exceptions apply, and they're the same on almost any website:

If you email me, I have your email — because you emailed me. I keep correspondence as long as it's useful and delete it on request.

§03 — Client systems

I'm a processor, not the owner.

Inside a client engagement I build and operate systems that handle that organization's own data — point-of-sale records, accounting, labor and scheduling, reservations, guest and donor records, and communications. That data belongs to the client, not to me.

Consistent commitments across every engagement:

If you're a guest, donor, member, or customer of an organization I work with and you want your information corrected or removed, the fastest route is to contact that organization directly — they control the record. You can also reach me at the address below and I'll route it.

§04 — Connected platforms

Access is granted by the client, scoped, and revocable.

Client systems often connect to third-party platforms the organization already uses, so their own information can appear in one place. Examples include point-of-sale and reservation providers, accounting and scheduling systems, email, and business-listing platforms such as Google Business Profile.

How that access works

Platform data is stored only as a cache so the client's team can work with it — it is never the system of record. The platform remains authoritative, and each platform's own terms and privacy policy continue to govern the underlying data.

§05 — Service providers

Who else touches it.

Client systems run on standard infrastructure. Each provider handles data only to deliver its service, under its own terms:

ProviderRole
VercelApplication hosting and serving
NeonManaged Postgres database
ResendTransactional and inbound email
Anthropic / OpenAIAI assistant providers, when a user queries their data through an assistant
Platform APIsThe client's own connected services — POS, reservations, accounting, listings

On AI specifically: when someone on a client's team asks a question, the relevant data is sent to the AI provider to answer it. These systems use commercial API terms under which submitted data is not used to train the provider's models. Data is not used to train any model of mine either — I don't train models.

§06 — Retention and deletion

It goes when you say so.

Requests are handled promptly — in practice within 30 days, usually much sooner.

§07 — Changes

If this changes, the date changes.

If practices change materially, this page is updated and the effective date at the top moves with it. There's no mailing list to notify, so the date is the honest signal.

Questions, corrections, deletions.

Email is the fastest route, and it reaches me directly — there's no ticket queue.