Most privacy policies are written so that nothing in them can ever be wrong. This one is written so that you can actually use it. It goes system by system — every service The Hidden Door runs on — and says what each one holds, who can see it, and where our visibility stops.
We do not sell your information. Not to anyone, in any form, ever. There is no ad network here and no data broker on the other end.
We do use it to work. Running a business means invoices, email, hosting, analytics and books, and those live in ordinary third-party systems. Pretending otherwise would be the lie.
We say where our own visibility stops. Several times below the honest answer is "we can see that" — an inbox is read, and a client's analytics are real.
We use AI to do the work. That is not a footnote here, it is the business, and §9 says exactly what that means for your data.
Hidden Door LLC, operating as The Hidden Door — a single-member company in the Memphis, Tennessee metropolitan area, United States. One person and her tools; there is no staff with a login.
Everything goes to [email protected]. That is a real address, read by a real person. Use it for questions, corrections, deletions, complaints, or to tell us this page is wrong. We will not ignore a lawful request because it arrived some other way.
We deal with several different kinds of people and they have genuinely different answers. Start with the one that is you.
For client work we hold what any web shop holds: your business details, contacts, invoices, domains, credentials for systems you asked us to manage, and the analytics for your own properties. This lives in the systems in §7 — principally our CRM, Google Cloud, Stripe and QuickBooks.
Where we act on your instructions for your customers' data, you are the controller and we are the processor. We do not use your customers' data for our own purposes, we do not move it between clients, and we do not sell it. If you leave, ask and we will hand over or delete what we hold.
This is the section most policies skip, and it covers more people than all the others combined.
If you filled in a form, called a tracked number, or simply visited a page on a site The Hidden Door built for one of our clients, some data about that reached a system we administer. It belongs to that business, not to us. We hold it on their behalf.
Not every client site does all of this, and some deliberately do none of it. At least one is built cookie-free on purpose, because its visitors' safety depends on it. If you want to know what a specific site does, ask us and we will tell you plainly.
Email arrives in Google Workspace and stays there until it is deleted — with what any mailbox holds: your address, your message, and when you sent it. One mailbox is read through a third-party client (Superhuman). If you phone or text a Hidden Door number, that runs through a telephony provider (§7) and there will be a record of the call.
Ask us to delete correspondence and we will, except where we have to keep it for tax or a live dispute.
You asked for privacy; here is where it actually exists. This is our own visibility, stated honestly — not a promise about the third parties themselves.
| Surface | Our visibility | What that means |
|---|---|---|
| Your card number | None | Stripe-hosted. It never touches our servers. |
| Your email to us | Full | It is an inbox. It is read. |
| Your payment record | Partial | Email, amount, date, receipt id. Not the card. |
| Your IP address | Partial | Processed by Cloudflare at the network layer. We do not pull it into anything. |
| Your visit to a client's site | Partial | In that client's analytics, held for them, not merged with anything of ours. |
The full list, not the flattering subset. If a service is not here and it touches personal data, that is an omission — write to us and we will correct this page.
| System | What it holds | About whom |
|---|---|---|
| Cloudflare | Web requests, IP addresses, DNS, bot protection | Anyone visiting our sites |
| Anthropic (Claude) | The AI we work with daily | Our own business data |
| Google Workspace | Email, calendar, documents | Anyone who writes to us |
| Google Cloud & BigQuery | Analytics warehouse, business records, our own operational logs | Clients; site visitors, in aggregate |
| Google Analytics | Site traffic for client properties | Visitors to client sites |
| Stripe | Payments, receipts, customer email | Anyone who buys |
| PayPal | Some invoicing | Some clients |
| QuickBooks | Bookkeeping, invoices, expenses | Clients and suppliers |
| Telephony & messaging (Twilio, OpenPhone, Quo) | Calls, texts, and in some client setups recordings and transcripts | People who call client or company numbers |
| Resend | Transactional email delivery | Recipients of our system email |
| Laravel Forge · Linode · DigitalOcean | The servers the websites run on | Anyone using those sites |
| Supabase | Application databases for some products | Users of those products |
| Amazon Web Services | File and object storage | Client files |
| Sentry | Error reports when something breaks, which can include the URL and technical context of the failure | Whoever hit the error |
| Linear · GitHub | Project tracking and source code | Client and project names |
| Ahrefs · Search Console · Bing Webmaster · DataForSEO | Search-ranking data | Nobody individually — aggregate only |
| Shopify · Printful | A merchandise store and its fulfilment | Anyone ordering from it |
| Internal agent tooling (a private IRC network, automation bots) | Coordination between our own automated tools | Nobody — internal only |
thehiddendoor.ai. Client sites are the client's decision — see §4.The Hidden Door is run with AI as a working partner, not as a feature. Being straight about what that means:
Wherever you live, you may ask what we hold about you, get a copy, correct it, or have it deleted. If you are in the EEA or UK you may also complain to your data protection authority; if you are in California you have CCPA rights, including the right not to be treated worse for using them — easy here, since nothing we offer depends on giving us data.
Write to [email protected]. In most cases the honest answer will be short, because there is not much. Where data sits with a client as controller, we will pass your request to them and tell you we did.
Everything is served over HTTPS. Credentials are held as encrypted secrets and never appear in any page sent to your browser. Access tokens are signed, short-lived, and bound to the one service that issued them. No system is perfect and we will not claim otherwise — if you find a problem, tell us and we will treat it seriously.
We do not knowingly collect personal information from anyone under 13. If you believe a child has given us information, write to us and we will delete it.
We operate from the United States and the systems above process data in the US and elsewhere. Reading from outside the US means sending your request to US infrastructure.
The date at the top changes when this page does. If a change materially affects what we collect or who can see it, we will say so here in plain words rather than revising quietly.
16 September 2026 — THE ATOM and the Discord were discontinued. The reading room at mcp.thehiddendoor.ai has been shut down and the Discord server deleted. The sections describing them, and the entries for Discord in the systems and visibility tables, were removed because there is no longer any such processing to disclose. Nothing was migrated anywhere else. If you were a member and want to know what we held, write to us — the answer will be that it went with the server, and we will say so in writing.