What is active today
The public homepage offers optional, consent-gated analytics. Nothing is collected for analytics until a visitor selects Allow analytics. A limited member preview may use a signed, HTTP-only session cookie to remember access and progress; that cookie is functional, not an advertising profile.
Optional homepage analytics
If you opt in, HowToJailbreakAI.com uses PostHog (US Cloud, project HowToJailbreakAI.com) to understand how visitors use the public homepage. We measure broad page and section views, selected navigation and FAQ actions, scroll-depth milestones, device/browser categories, referrers or campaign tags, and Core Web Vitals. Heatmaps and session replay are enabled only on the homepage, with inputs and sensitive fields masked; replay retention is currently 30 days.
The browser analytics layer discards client IP addresses, does not create identified profiles, and never initializes on member pages, recovery, purchase-success, design-lab, or API routes. It does not send access codes, recovery tokens, email addresses, payment or Stripe identifiers, private curriculum, or raw visitor-entered text to PostHog. The public page may still contain ordinary visible copy in a replay; do not submit confidential information into public fields.
You can choose No thanks instead, or reopen Privacy choices from the footer at any time. Analytics retention follows the configured PostHog project settings; session replay is limited to 30 days at present.
Operational data
Vercel hosts the application, Cloudflare provides DNS and scheduled recovery delivery, and Neon stores protected entitlement, progress, rate-limit, and recovery records. These services may process ordinary request data such as an IP address, browser type, requested route, timestamp, and error information to deliver and protect the site. Member and recovery records are used for access and support operations, not advertising.
Stripe payment infrastructure and Resend transactional email are configured, but checkout is closed. The recovery form returns the same public response for every address; Resend is used only when an active entitlement matches, and no live purchases exist today.
Do not submit secrets, credentials, sensitive personal information, or confidential project material through public site fields.
Checkout attribution
When checkout is eventually opened, Stripe Checkout will ask one required question: How did you hear about us? The choices are YouTube, X / Twitter, Google Search, and Other. An optional follow-up lets a customer describe an Other source in up to 200 characters.
The selected category and optional Other text are stored with the Stripe/Neon purchase record for basic attribution and support. If the customer previously allowed analytics, the verified webhook may also send PostHog a purchase event linked to that anonymous browser ID with the fixed amount, currency, plan, and selected category. It never sends an email address, access code, raw Stripe or payment identifier, or Other text. No checkout collection is active while purchasing is disabled.
What is not active
- No live checkout or payment collection.
- No client analytics or session replay on member, recovery, purchase-success, design-lab, or API routes.
- No sale of personal information or targeted advertising program.
What will be finalized before launch
Before checkout opens, this notice will be reviewed against the final commercial terms, regional requirements, retention decisions, and support workflow. Material changes will be dated on this page.
Requests and contact
For privacy questions or requests, contact support@howtojailbreakai.com. We may need to verify a request before acting on it. This working draft is informational and is not legal advice.