Privacy Policy
Last updated: 7 April 2026
The short version
We collect only what we need to run MethodPunks. We do not sell your data. We use privacy-friendly, self-hosted analytics that do not track you across the web. You can delete your account and data at any time.
Who we are
MethodPunks is operated by SpiceBox Consulting SARL. For privacy questions, please use our contact page. These terms should be read alongside our Terms of Service.
What we collect and why
| Data | Why | Where |
|---|---|---|
| Email and password hash | Account authentication | Database (self-hosted) |
| Subscription and billing info | Payment processing | Polar (we never store card details) |
| AI Coach chat messages | Providing AI responses and chat history | Database (self-hosted) |
| Canvas entries and bookmarks | Saving your work and preferences | Database (self-hosted) |
| Page views and events | Understanding how the product is used | Umami (self-hosted, cookieless) |
| Email engagement (opens, clicks) | Improving our email communications | Brevo |
| Email address | Transactional emails (welcome, password reset) | Resend |
AI Coach and your data
- Messages you send to the AI Coach are processed to generate responses. They are sent to our AI infrastructure (RunPod) for this purpose only.
- Your messages are not used to train or fine-tune AI models.
- Chat history is stored in your account so you can reference past conversations.
- We may review anonymised, aggregated usage patterns to improve the AI Coach, but we do not read individual conversations unless required for support or safety reasons.
Analytics
We use Umami for website analytics. Umami is self-hosted on our own infrastructure and is privacy-focused - it does not use cookies, does not track you across sites, and does not collect personal information. It records page views and events in aggregate only.
We use Brevo for email marketing and engagement tracking (open rates, click rates).
We do not use Google Analytics, Meta/Facebook pixels, or any third-party advertising trackers.
Cookies
We keep cookies to a minimum:
- Essential cookies - Database (self-hosted) auth uses session cookies to keep you logged in. These are strictly necessary and cannot be opted out of.
- Marketing cookies - Brevo may set cookies for email campaign attribution. You can block these in your browser without affecting site functionality.
- We do not use advertising cookies.
Third-party services
We use the following services to run MethodPunks. Our infrastructure is hosted with an ISO/IEC 27001:2022 certified hosting provider, and we strive to maintain 99.99% uptime. Each service has its own privacy policy:
Data retention
We keep your data while your account is active. If you delete your account, we remove your personal data within 30 days. Some anonymised, aggregated data (like analytics) may be retained. You can request deletion of specific data (such as AI Coach chat history) at any time by contacting us.
Your rights
You can access, export, or delete your data by emailing us. We will respond within 30 days.
EU/EEA residents: You have rights under GDPR including access, rectification, erasure, portability, and objection.
California residents: You have rights under CCPA. We do not sell personal information.
Security
All data is encrypted in transit (HTTPS). Passwords are hashed with bcrypt. We follow reasonable security practices for a product of our size. No system is 100% secure - if we ever discover a breach, we will notify affected users promptly.
Children
MethodPunks is not intended for users under 16. We do not knowingly collect data from children.
Changes to this policy
We may update this policy as needed. For material changes, we will notify you by email. The "last updated" date at the top always reflects the most recent version.
Contact
Privacy questions or data requests? Use our contact page.
