✦ The Hidden Door Terms

Privacy Policy

Last updated 31 July 2026  ·  what we hold, who holds it, and what we can actually see

Most privacy policies are written so that nothing in them can ever be wrong. This one is written so that you can actually use it. It goes system by system — every service The Hidden Door runs on — and says what each one holds, who can see it, and where our visibility stops.

◆ The whole thing in four lines

We do not sell your information. Not to anyone, in any form, ever. There is no ad network here and no data broker on the other end.

We do use it to work. Running a business means invoices, email, hosting, analytics and books, and those live in ordinary third-party systems. Pretending otherwise would be the lie.

We say where our own visibility stops. Several times below the honest answer is "we can see that" — including on our own Discord, where we are the server owner.

We use AI to do the work. That is not a footnote here, it is the business, and §11 says exactly what that means for your data.

1. Who we are

Hidden Door LLC, operating as The Hidden Door — a single-member company in the Memphis, Tennessee metropolitan area, United States. One person and her tools; there is no staff with a login.

Everything goes to [email protected]. That is a real address, read by a real person. Use it for questions, corrections, deletions, complaints, or to tell us this page is wrong. We will not ignore a lawful request because it arrived some other way.

2. Find yourself here

We deal with several different kinds of people and they have genuinely different answers. Start with the one that is you.

§3You read THE ATOM §4You're in the Discord §5We build or run your site §6You used a site we built §7You emailed or called us

3. If you read THE ATOM

The reading room at mcp.thehiddendoor.ai is a single stateless program on Cloudflare Workers with no database attached — no key-value store, no SQL, no object storage. It cannot build a profile of you because it has nowhere to keep one. We have not enabled application logging or log export on it.

There are no accounts. Access is proved by a signed token holding your key, this service's address, and an expiry — verified by recomputing the signature, never stored. When it expires it stops working.

Where that stops: Cloudflare processes the request itself and keeps limited operational records including IP addresses, as it does for any website. And the material comes from Discord — see the next section, which applies to you too.

4. If you're in the Discord

This is the section people most often assume is friendlier than it is.

We own the server. Not a partner, not a vendor — The Hidden Door. So when this page says "we keep no record," that is about the reading room, and it is not a statement about Discord. As server owner we can see what Discord shows any server owner: the member list, join dates, roles, and the contents of channels our account and bot can read. Assume we can see what you post in our rooms, because we can.

Discord itself holds far more than we do — your account, your IP, your message history, your DMs — under Discord's own privacy policy, not ours. If that matters to you, read theirs; we cannot change it and cannot delete it for you.

Your writing may be read outside Discord. Certain rooms are served through the reading room to people holding a Library Card, under your display name. Rooms are read live, so deleting a post in Discord removes it from what is served — withdrawal is immediate and needs no request. We are building an opt-in so that contributors choose this and share in what it earns; until that ships, tell us and we will exclude you.

Timing. At low traffic, a request arriving at Cloudflare and our bot's fetch leaving for Discord moments later share a timestamp. We do not correlate those and have built nothing that could. We mention it because "impossible" would be a stronger word than we have earned.

5. If we build or run something for you

For client work we hold what any web shop holds: your business details, contacts, invoices, domains, credentials for systems you asked us to manage, and the analytics for your own properties. This lives in the systems in §9 — principally our CRM, Google Cloud, Stripe and QuickBooks.

Where we act on your instructions for your customers' data, you are the controller and we are the processor. We do not use your customers' data for our own purposes, we do not move it between clients, and we do not sell it. If you leave, ask and we will hand over or delete what we hold.

6. If you used a website we built for somebody else

This is the section most policies skip, and it covers more people than all the others combined.

If you filled in a form, called a tracked number, or simply visited a page on a site The Hidden Door built for one of our clients, some data about that reached a system we administer. It belongs to that business, not to us. We hold it on their behalf.

Not every client site does all of this, and some deliberately do none of it. At least one is built cookie-free on purpose, because its visitors' safety depends on it. If you want to know what a specific site does, ask us and we will tell you plainly.

7. If you emailed or called us

Email arrives in Google Workspace and stays there until it is deleted — with what any mailbox holds: your address, your message, and when you sent it. One mailbox is read through a third-party client (Superhuman). If you phone or text a Hidden Door number, that runs through a telephony provider (§9) and there will be a record of the call.

Ask us to delete correspondence and we will, except where we have to keep it for tax or a live dispute.

8. What is open, what is limited, what we cannot reach

You asked for privacy; here is where it actually exists. This is our own visibility, stated honestly — not a promise about the third parties themselves.

SurfaceOur visibilityWhat that means
What you read in the reading roomNoneNo database exists to hold it. This is structural, not a policy we could quietly change.
Your conversation with your own ClaudeNoneBetween you and Anthropic. We receive a request for material, never the conversation around it.
Your card numberNoneStripe-hosted. It never touches our servers.
Your Discord DMs with other peopleNoneServer owners cannot read member-to-member DMs.
What you post in our Discord roomsFullWe own the server. Post accordingly.
Your Discord membership and rolesFullMember list, join date, roles — anything Discord shows an owner.
Your email to usFullIt is an inbox. It is read.
Your payment recordPartialEmail, amount, date, receipt id. Not the card.
Your IP addressPartialProcessed by Cloudflare at the network layer. We do not pull it into anything.
Your visit to a client's sitePartialIn that client's analytics, held for them, not merged with anything of ours.

9. Every system we run on

The full list, not the flattering subset. If a service is not here and it touches personal data, that is an omission — write to us and we will correct this page.

SystemWhat it holdsAbout whom
CloudflareWeb requests, IP addresses, DNS, bot protection, the reading room itselfAnyone visiting our sites
DiscordThe community and all the written material in the roomsMembers
Anthropic (Claude)The AI that reads the rooms with you, and that we work with dailyReaders; our own business data
Google WorkspaceEmail, calendar, documentsAnyone who writes to us
Google Cloud & BigQueryAnalytics warehouse, business records, our own operational logsClients; site visitors, in aggregate
Google AnalyticsSite traffic for client propertiesVisitors to client sites
StripePayments, receipts, customer emailAnyone who buys
PayPalSome invoicingSome clients
QuickBooksBookkeeping, invoices, expensesClients and suppliers
Telephony & messaging
(Twilio, OpenPhone, Quo)
Calls, texts, and in some client setups recordings and transcriptsPeople who call client or company numbers
ResendTransactional email deliveryRecipients of our system email
Laravel Forge · Linode · DigitalOceanThe servers the websites run onAnyone using those sites
SupabaseApplication databases for some productsUsers of those products
Amazon Web ServicesFile and object storageClient files
SentryError reports when something breaks, which can include the URL and technical context of the failureWhoever hit the error
Linear · GitHubProject tracking and source codeClient and project names
Ahrefs · Search Console · Bing Webmaster · DataForSEOSearch-ranking dataNobody individually — aggregate only
Shopify · PrintfulA merchandise store and its fulfilmentAnyone ordering from it
Internal agent tooling
(a private IRC network, automation bots)
Coordination between our own automated toolsNobody — internal only

10. What we do not do

11. AI, plainly

The Hidden Door is run with AI as a working partner, not as a feature. Being straight about what that means:

12. How long we keep things

13. Your rights

Wherever you live, you may ask what we hold about you, get a copy, correct it, or have it deleted. If you are in the EEA or UK you may also complain to your data protection authority; if you are in California you have CCPA rights, including the right not to be treated worse for using them — easy here, since nothing we offer depends on giving us data.

Write to [email protected]. In most cases the honest answer will be short, because there is not much. Where data sits with a client as controller, we will pass your request to them and tell you we did.

14. Security

Everything is served over HTTPS. Credentials are held as encrypted secrets and never appear in any page sent to your browser. Access tokens are signed, short-lived, and bound to the one service that issued them. No system is perfect and we will not claim otherwise — if you find a problem, tell us and we will treat it seriously.

15. Children

The Library Card requires confirmation that you are 18 or older. We do not knowingly collect personal information from anyone under 13. If you believe a child has given us information, write to us and we will delete it.

16. Sensitive material and safety

◆ Please read this one

The SIG rooms hold material on domestic violence, coercive control and psychological abuse, including crisis resources. It is free to read because it should be.

It is not professional advice — not medical, psychological, or legal, not therapy, and not a substitute for a qualified professional or emergency services.

If you are in immediate danger, call 911 (or your local emergency number). In the US: National Domestic Violence Hotline 1-800-799-7233, or text START to 88788. Suicide & Crisis Lifeline: call or text 988. Outside the US, these numbers will not work — please find your local service.

On privacy, do not rely on us. We record nothing about your reading, but a record can exist anyway: your own device, your browser, your AI client's history, notifications on a shared screen, and — if you read inside Discord — Discord's records and our own visibility as server owner. If your safety depends on this reading not being discovered, assume a record exists somewhere and choose your device accordingly. A library computer or a trusted friend's phone is often safer than your own.

17. International

We operate from the United States and the systems above process data in the US and elsewhere. Reading from outside the US means sending your request to US infrastructure.

18. Changes

The date at the top changes when this page does. If a change materially affects what we collect or who can see it, we will say so here in plain words rather than revising quietly.

If any of this is wrong, out of date, or missing a system — tell us and we will fix the page.
See also the Terms of Service.