Plain-language privacy

Your data, your call.

This notice explains what Rails Builders collects, why it is needed, who receives it, and what you can do about it.

Who is responsible

Rich Steinmetz operates Rails Builders and is responsible for its use of personal data. Email rich@looplabs.cc with privacy questions or requests.

What Rails Builders uses

Your email address verifies your identity, operates your account, manages enrollment and seat offers, and delivers essential account messages. This processing is necessary to provide the service you request under Article 6(1)(b) GDPR. Providing an email address is required to register; profile publication and the newsletter are optional.

A private seed list contains the email addresses of past Rails Builders participants so the service can recognize them as OG builders when they register. The list is stored in private server configuration, not in the public source-code repository, and is available only to authorized administrators.

If you add them, Rails Builders also stores your name, picture, testimonial, and product links. We use request information such as your IP address, browser details, and request time to prevent abuse, keep the service secure, diagnose errors, and record newsletter consent. Security and reliability processing is based on our legitimate interests under Article 6(1)(f) GDPR. Newsletter consent records support the consent you give under Article 6(1)(a).

Sessions, attendance, transcripts, and analysis

Rails Builders stores the session schedule copied from the Program’s Google Calendar, including event titles, descriptions, locations, times, facilitator assignments, and Google Meet links. Before a session, it shows expected Active Builders and may record their attendance choices. Once the session starts, it also records arrival time when observed, timer and phase history, pauses, and speaker order. These records operate the Program and preserve its shared history under Article 6(1)(b) GDPR.

A session may be transcribed in Google Meet or recorded by a facilitator with Wispr Flow. Rails Builders displays a transcription notice beside the meeting link and may import speaker labels, timestamps, transcript text, and Wispr Flow summary notes after the session, including the hangout. OpenAI’s Codex may process that private transcript, its summary notes, and previous session analyses to prepare a concise participant-by-participant analysis and a one-sentence trend. The transcript, notes, and analysis are encrypted in the Rails Builders database.

The public homepage shows only a session’s title, time, core-session duration, and a facilitator name when that facilitator has an approved public profile. It may also show that a session is live. Attendees, attendance status, descriptions, locations, Google Meet links, transcripts, summary notes, and session analyses are never published there. The private session page shows all expected Active Builders regardless of whether they publish a public profile. Signed-in Active Builders, facilitators, and Administrators can view the private session record. Facilitators and Administrators operate session controls and may correct the notes or analysis; Builders do not edit the transcript. An Administrator can delete the stored transcript together with its notes and analysis.

Hosting, access, and service providers

The Rails Builders app, database, and uploaded profile images run on a Hetzner server in Finland. Hetzner keeps rolling daily server backups. Access is role-based: Administrators manage the service; facilitators operate sessions, review profile publication, and manage Active Builder promotions; and Active Builders can view the private Program session record.

We share only the data needed to operate the service with Hetzner for hosting and server backups, Resend for account and enrollment emails, Honeybadger for error and host monitoring, PostHog’s EU service for product analytics, Google for the facilitator-owned Calendar and Meet integration, Wispr Flow for facilitator-controlled meeting recording and notes, and OpenAI for transcript analysis through Codex. Rails Builders stores the Google OAuth credential needed for that connection in encrypted form. The read-only Google grant covers the account’s Calendar list, events on calendars the account owns, and Meet spaces the account can access; Rails Builders queries only the selected Program calendar and Meet links synced from it. Rails Builders’ use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. Google-derived data is not used for advertising or to train generalized AI models. Honeybadger does not receive your Rails Builders session or the URL that produced an error. PostHog receives normalized page names, selected join interactions, and anonymous counts of completed registration and enrollment outcomes; it does not receive application errors, Rails Builders account identifiers, emails, names, form values, query strings, session or transcript content, or administration pages. If you separately confirm the Loop Labs newsletter, we send your email address and, if provided, your name to ClickFunnels. We do not sell registrants’ personal data.

Google, Wispr Flow, OpenAI, Resend, Honeybadger, PostHog, and ClickFunnels may process account or service data outside the European Economic Area even where application data is stored in an EU region. Their applicable data-processing terms describe the safeguards used for covered international transfers. Email us to request information about the safeguard that applies to your data.

Public profiles

Your email is never displayed publicly. Your name, picture, testimonial, and product links appear on rails.builders only when you request publication and a facilitator approves it. Profile or product changes return the profile to facilitator review. You can turn publication off at any time.

Loop Labs newsletter

The newsletter is optional and separate from Rails Builders. Selecting the newsletter box sends a newsletter-specific confirmation email. Visiting that link does not subscribe you; you must confirm again on rails.builders. Only then do we send your email address and optional name to ClickFunnels. You can withdraw consent at any time through the unsubscribe link in any newsletter email. Withdrawing consent does not affect processing that happened before withdrawal.

Deleting your Rails Builders account does not unsubscribe the separate Loop Labs newsletter. Use a newsletter unsubscribe link to stop it.

Cookies and tracking

Rails Builders uses an encrypted session cookie to keep you signed in and protect account actions. PostHog stores a pseudonymous analytics identifier in your browser’s local storage so related page views and selected join interactions can be measured; it is not linked to your Rails Builders account. Rails Builders does not use advertising trackers or sell analytics data.

Retention and deletion

Unverified registrations are deleted after 30 days. The private OG seed list remains until an address is removed from the server configuration. Verified account and enrollment data remain until you delete your account or Rails Builders no longer needs them to provide the service.

Session schedule and attendance records remain as Program history. Automatic transcript import is attempted for no more than 24 hours; an imported or manually added transcript, its summary notes, and its analysis remain until an Administrator deletes that session record. Deleting your account removes the live Rails Builders profile, products, image, enrollment state, and local newsletter consent record, changes linked attendance names to “Former Builder,” and anonymizes any facilitator label tied to the account. It does not rewrite historical transcript text, notes, or analysis, which may still contain a name or contribution from a session. You may contact us about a specific transcript or other session record.

Deleting a Rails Builders transcript also deletes its stored notes and analysis, but does not delete a source copy held by Google or Wispr Flow. Google, Wispr Flow, OpenAI, and the other service providers apply their own retention rules. Hetzner keeps seven rolling daily server backups, so deleted application data may remain in those backups until the copies expire.

Your rights

You may ask to access, correct, delete, restrict, or receive a portable copy of your personal data. You may object to processing based on legitimate interests and withdraw consent at any time. Email rich@looplabs.cc to exercise these rights. You also have the right to lodge a complaint with the data protection authority responsible for you.

Last updated: 4 September 2026.