Privacy Policy — Protocol 2444
Last updated: September 2026
Faccio, LLC, a digital product studio organized in Delaware, United States, and owner of Protocol 2444 (the "Company", "we", "us"), takes the protection of your personal information seriously. This Privacy Policy explains, clearly and transparently, what information we collect, why we collect it, how we use it, who we share it with and what choices and rights you have.
This policy applies to the website, the web app and the other services operated under the Protocol 2444 brand ("the Protocol" from here on). It is written for users in the United States. Users in Brazil are covered by our Portuguese-language policy.
- Who is Responsible for Your Information
Faccio, LLC 131 Continental Dr, Suite 305, Newark, DE 19713, United States Contact email: contact@protocol2444.com Website: https://faccio.studio
Privacy contact: Email: dpo@protocol2444.com
- Information We Collect
We collect only the information needed to deliver the Service, to promote the Service and to measure how well that promotion works. The categories are:
2.0. Information collected BEFORE you create an account (onboarding and email capture)
Part of the Service happens before you create an account. When you start building your Protocol (the "onboarding"), we process the following information, even if you have not signed up or paid yet:
- Onboarding answers (pre-login): your profession, a description of your workday, what takes up most of your time, your biggest difficulty with AI and the goal you want to reach. These are free-text answers typed by you.
- Visit identifier (
lead_id): an identifier generated by the system and stored as a first-party cookie, which links the steps of your onboarding to each other. - Email (optional, before sign-up): if you choose to receive the preview of your Protocol by email, we collect your email address at that moment, before and independently of any sign-up or payment.
- Campaign and attribution parameters: the source of your visit (UTM parameters) and advertising identifiers where applicable (for example Meta parameters such as
fbp/fbc, see Section 3.8), to measure which ad or channel you came from. - IP address and technical data of the request (see Section 2.5), also used to limit abuse (rate limiting) of pre-login calls.
This pre-login information may be reconciled with your account if you later sign up from the same device or with the same email.
2.1. Account information
- Email address (required, provided by you at checkout or in the preview email capture)
- Date and time the account was created
- A unique identifier generated by the system (UUID)
2.2. Payment information
- Payments are processed by Stripe. We do not store full card numbers, CVV codes or bank passwords.
- From Stripe we receive only: the transaction identifier, the payment status, the last 4 digits of the card, the card brand, the issuing country and the billing address used for sales tax (for tax and anti-fraud purposes).
2.3. Onboarding information (professional profile)
During onboarding we collect:
- Basic information: name, age range, city and state, and phone number (optional).
- Open answers: questions about your profession, field, prior experience with AI, goals and challenges. Each answer is limited to 500 characters.
This information is used to personalize the examples in your track.
2.4. Usage information
- Progress in the track (practices started and completed)
- The depth toggle you selected ("simpler" / "deeper")
- Dates and times of access
- Clicks on "regenerate example" (for rate limiting)
2.5. Technical logs and usage events
- IP address (retention period in Section 6)
- Browser and operating system (user agent)
- Pages visited, response time, technical errors
- Records of AI calls (observability): the model used, the number of input and output tokens, latency, cost, success or error, and a record of the prompt (with personal information redacted) and of the generated answer (possibly truncated). These records are used for content quality control, cost control and troubleshooting; they are accessible only to the internal team, under least-privilege administrative access, and pass through the server-side PII filter described in Sections 3.4 and 9 before being stored
- Behavioral events captured through PostHog (CTA clicks, scrolling, funnel step completion, practice openings). See Section 3.7 for details about PostHog and session recording (Session Replay).
2.6. Cookies and similar technologies
We use the following categories of cookies and similar technologies:
- Functional cookies (strictly necessary):
sb-*-auth-token.0andsb-*-auth-token.1(Supabase Auth) keep you signed in.protocol2444_cookie_consentrecords your choice in the cookie notice, including an opt-out of ad measurement (180 days).lead_idis the first-party visit identifier that links the steps of the pre-login onboarding.NEXT_LOCALEremembers your language choice.
- Analytics cookies: PostHog measures aggregate use and generates anonymous session identifiers for Session Replay (see Section 3.7).
- Marketing and advertising cookies and technologies (third parties): we use the Meta Pixel and Meta's Conversions API (CAPI) (Facebook/Instagram) to measure the effectiveness of our ads and optimize campaigns. This may involve Meta cookies (for example
_fbp) and the sending of conversion events to Meta (see Section 3.8). Other advertising platforms (for example Google) may be added, in which case this policy will be updated.
See also Section 8 for more details about cookies and how to opt out.
- Use of AI and Information Sent to Anthropic
This section describes the most sensitive processing covered by this policy.
3.1. Technology
The Protocol uses the Claude models (Haiku and Sonnet), provided by Anthropic, PBC (a US company based in San Francisco, CA), through a secure API, to generate and personalize the content and the examples of your track. To build the track for a profession, the system may also run web searches (through the same API) to gather real, current references and resources, without sending your personal information in those searches.
3.2. What is sent
The following is sent to Anthropic's API:
- Your onboarding answers, including those collected before sign-up (Sections 2.0 and 2.3 above). The personalization of your Protocol preview already happens in the pre-login flow;
- The system prompts curated by the Company to guide the generation;
- Occasionally, your depth choice ("simpler" / "deeper") when you regenerate an example.
Before sending, we apply a server-side filter that detects and blocks obvious patterns of personal identifiers (for example Social Security numbers, phone numbers and professional license numbers) and can redact proper names identified in free text (see Sections 3.4 and 9).
3.3. What is not sent
- Your name and basic information (age range, city and state, phone number) stay only in our database and do not travel to the AI;
- Your email;
- Payment information;
- Unique identifiers tied to your billing profile.
Communication with Anthropic uses anonymous identifiers.
3.4. Explicit notice about third-party information
The Service shows visible notices during onboarding asking you not to enter information about patients, clients or third parties (names, medical records, diagnoses, contracts, sensitive information). We also apply a server-side filter that blocks obvious patterns of personal identifiers and can redact proper names in free text before forwarding the call to Anthropic. This filter is an additional layer of protection; it does not replace your own attention.
3.5. Anthropic's policy
To understand how Anthropic handles information received through its API, see its policy: https://www.anthropic.com/legal/privacy. Under Anthropic's current commercial API policy, information sent through the API is not used to train models.
3.6. Analytics and session recording (PostHog)
The Company uses PostHog (operated by PostHog Inc., based in the United States) to understand how the product is used, identify friction points and prevent abuse. PostHog combines two uses:
What is collected:
- Behavioral events (CTA clicks, navigation between screens, funnel step completion, scrolling, time on screen);
- Anonymous session identifiers (not tied to government identifiers, phone numbers or sensitive information);
- Session recording (Session Replay) of your interactions with the product, including mouse movements and clicks.
What is NOT recorded:
- Content typed into sensitive fields (password, email, payment information). These inputs are automatically masked by PostHog;
- Your free-text onboarding answers (free-text fields are masked);
- Full card or authentication data.
PostHog's policy: https://posthog.com/privacy.
3.7. Advertising and measurement (Meta Pixel and Conversions API)
The Company uses advertising tools from Meta Platforms, Inc. (Facebook/Instagram) to promote the Service, measure the effectiveness of its ads and optimize campaigns:
- Meta Pixel (in the browser) and the Conversions API / CAPI (server to server).
What is shared with Meta:
- Events such as page views, start of onboarding, email capture (a "Lead" event) and conversion (purchase);
- Advertising identifiers (for example the
_fbp/_fbccookies); - Contact information in hashed form (one-way encrypted) when available, such as your email, used for audience matching and attribution. The Company does not send Meta the content of your free-text onboarding answers.
Your choice: ad measurement is on by default and you can opt out at any time, with one click, using the "Opt out of ad measurement" button at the bottom of this page. From then on no new events are sent to Meta and the _fbp/_fbc cookies are removed from your browser. You can also opt out by writing to dpo@protocol2444.com (see Sections 7 and 8). Under some state privacy laws, this type of sharing for cross-context behavioral advertising is treated as a "sale" or "sharing" of personal information; the button above is how you opt out of it.
Meta's policy: https://www.facebook.com/privacy/policy.
- Purposes of Processing
| Purpose | Information involved |
|---|---|
| Build the Protocol preview during onboarding (before sign-up) | Pre-login onboarding answers, lead_id |
| Personalize the preview and the track with AI (pre- and post-login) | Onboarding answers |
| Send the Protocol preview by email (when requested) | Email (pre-sign-up) |
| Create and maintain your account | Email, UUID, creation date |
| Process payment and calculate sales tax | Stripe information, billing address |
| Record progress | Usage information |
| Security, fraud prevention and rate limiting (including pre-login) | Technical logs, IP address, lead_id |
| Analytics and product improvement (PostHog, Session Replay) | Usage events, session recording (with sensitive information masked) |
| Advertising, measurement and campaign optimization (Meta Pixel/CAPI) | Conversion events, advertising identifiers, hashed email (with a one-click opt-out, see Sections 3.7 and 8.3) |
| Comply with tax and accounting obligations | Payment information |
| Communicate important Service updates | |
| Direct marketing (newsletter / email sequences) | Email (every marketing email includes an unsubscribe link, in compliance with the CAN-SPAM Act) |
We do not use your information to make decisions that produce legal or similarly significant effects about you without human involvement.
- Sharing with Third Parties (Service Providers)
We share only what is strictly necessary, with partners essential to operating the Service:
| Partner | Purpose | Location | Policy |
|---|---|---|---|
| Stripe | Payment processing and sales tax calculation | USA | https://stripe.com/privacy |
| Anthropic | Generation of personalized examples with AI (including the pre-login preview) | USA | https://www.anthropic.com/legal/privacy |
| Supabase | Database, authentication and storage | USA | https://supabase.com/privacy |
| Vercel | Hosting of the web app | USA / global edge network (CDN) | https://vercel.com/legal/privacy-policy |
| PostHog | Behavioral analytics and session recording (Session Replay) | USA (US Cloud) | https://posthog.com/privacy |
| Meta (Facebook/Instagram) | Advertising, measurement and campaign optimization (Pixel + Conversions API) | USA / global | https://www.facebook.com/privacy/policy |
| Resend | Sending of transactional emails and the Protocol preview | USA | https://resend.com/legal/privacy-policy |
All partners are contractually required to handle information in accordance with applicable privacy law and industry security standards.
We do not sell your personal information for money. We share information with advertising platforms (such as Meta) solely to promote the Service, measure the effectiveness of our ads and optimize campaigns, as described in Section 3.7. You can opt out of that sharing at any time (see Sections 7 and 8).
The Company may disclose information if required by law, subpoena, court order or a request from a competent authority, or to protect the rights, property or safety of the Company, its users or others.
- Data Retention
| Category | Retention period |
|---|---|
| Account information (email, UUID) | While the account is active, plus 5 years after inactivity or deletion (to establish, exercise or defend legal claims) |
| Payment information | 7 years after the transaction (tax and accounting record-keeping) |
| Onboarding answers (active account) | While the account is active, or until you request deletion |
| Pre-login onboarding information that did not convert (lead) | Up to 12 months after the last interaction, or until you request deletion, whichever comes first |
| Usage and progress information | While the account is active |
| Technical logs with IP address | 6 months |
| Marketing emails (after opt-out) | We keep only the opt-out record, to avoid emailing you again |
After the period ends, the information is anonymized or securely deleted.
- Your Choices and Rights
Regardless of where you live, you can exercise the following choices free of charge at any time:
- Access the information we hold about you;
- Correct incomplete, inaccurate or outdated information;
- Delete your information, subject to the retention periods required by law or needed to defend legal claims;
- Receive a copy of your information in a structured format (for example JSON);
- Opt out of ad measurement and of the sharing of your information with advertising platforms (see Section 8.3);
- Unsubscribe from marketing emails, using the link in every email or by writing to us;
- Know which categories of third parties we share information with (this policy already provides that information).
Residents of states with comprehensive privacy laws (for example California, Virginia, Colorado, Connecticut and Texas) may have additional rights under those laws, including the right not to be discriminated against for exercising them. We honor those rights for all users. We currently do not respond to browser "Do Not Track" or Global Privacy Control signals; use the opt-out button described in Section 8.3 instead.
How to exercise your rights
Send an email to contact@protocol2444.com or dpo@protocol2444.com, stating:
- Which right you want to exercise;
- The email address registered on your account (for verification);
- Additional details, if applicable.
Response time: within 30 days of the request. If we need more time, we will tell you why and when to expect a reply.
If we have doubts about your identity, we may request additional information to prevent fraud. You may also authorize an agent to make a request on your behalf; we may ask for proof of that authorization.
- Cookies and Similar Technologies
8.1. Functional cookies (strictly necessary): they keep you signed in (sb-*-auth-token.0, sb-*-auth-token.1, Supabase Auth), record that you saw the cookie notice (protocol2444_cookie_consent), link the steps of the pre-login onboarding (lead_id), remember your language (NEXT_LOCALE) and preserve your progress in the track. Without them, the Service does not work.
8.2. Analytics cookies (PostHog): they capture usage events and generate anonymous identifiers for Session Replay (see Section 3.6), with automatic masking of sensitive inputs.
8.3. Marketing and advertising cookies and technologies (third parties): we use the Meta Pixel and related cookies (for example _fbp, _fbc) to measure and optimize our ads (see Section 3.7). These cookies are on by default. The cookie notice informs you of this and links to this page.
8.4. How to opt out: use the "Opt out of ad measurement" button at the bottom of this page. Measurement stops immediately, without reloading the page, and the _fbp/_fbc cookies already stored are removed. Your choice is recorded in protocol2444_cookie_consent for 180 days and can be reversed with the same button. You can also block cookies in your browser settings, knowing that blocking functional cookies may affect features of the Service, or write to dpo@protocol2444.com.
- Information Security
We adopt reasonable technical and organizational measures to protect your information:
- Encryption in transit (TLS 1.2+) in all communications;
- Encryption at rest in the database (Supabase);
- Row Level Security (RLS) in the database, so each user can access only their own information;
- Anthropic API key kept only on the server, never exposed to the browser;
- Stripe webhook validation with cryptographic signatures and idempotent recording;
- Server-side PII filter (government identifiers, phone numbers, professional license numbers and proper names in free text) before AI calls;
- Durable rate limiting to prevent abuse, including on pre-login calls;
- Audit logs for administrative access;
- Least-privilege principle for internal access to information.
Despite these measures, no system is completely immune. In the event of a security incident affecting your personal information, we will notify you and, where required, the competent authorities within the time frames set by applicable state breach notification laws.
- Children
10.1. The Protocol is intended exclusively for professionals aged 18 or older.
10.2. We do not knowingly collect information from children under 13, in accordance with the Children's Online Privacy Protection Act (COPPA), nor from anyone under 18.
10.3. If we learn that a minor has created an account, we will suspend the account and delete the information.
10.4. If you are a parent or guardian and believe a minor has signed up, contact dpo@protocol2444.com.
- Changes to This Policy
11.1. This policy may be updated to reflect changes in the Service, in technology partners or in the law.
11.2. Material changes (especially those that affect your privacy choices or how we process your information) will be communicated:
- By email to registered users, at least 15 days in advance;
- By a visible notice in the Service.
11.3. The "Last updated" date at the top of this page always indicates the version in effect. Previous versions can be requested by email at dpo@protocol2444.com.
- Contact
- General email: contact@protocol2444.com
- Privacy contact: dpo@protocol2444.com
- Responsible company: Faccio, LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, United States
- Website: https://faccio.studio
Last revision: September 2026.