Your data and privacy

Executive Council is a paid deliberation tool. Here is exactly what we keep, who else touches it, and what we never do with it. No fine print.

What we store

  • Your account. Your email and login, handled by Supabase, our auth and database provider.
  • Your deliberations. The questions you ask, your project-context notes, and the council's answers. We save these so you can reopen past sessions, and they stay tied to your account only.
  • Your OpenRouter API key. Encrypted on our server so it follows you across devices. We never show it back to you, and we only ever send it to OpenRouter to run your deliberations. A copy also sits in your browser on the device where you typed it.
  • Your credit ledger. When you buy credits or run a deliberation, we record the credit movement and what the run cost. This is billing data, and it stays tied to your account.
  • Contact and waitlist messages. What you send through the contact form or the waitlist box, so we can reply and notify you.

Who else is involved

  • Vercel serves this website.
  • Render runs the council backend.
  • Supabase stores accounts and data (also listed above).
  • OpenRouter runs the AI models and charges your key, never ours.
  • The model providers (OpenAI, Anthropic, Google, DeepSeek and others) read your question through OpenRouter so they can answer it.
  • Cloudflare Turnstile runs a quick bot check when you sign in or send us a message.
  • Web3Forms passes along anything you send through the contact or waitlist forms.

What we never do

  • We never sell your data.
  • We never train our own models on it.
  • We never share your API key with anyone but OpenRouter.

About the AI providers

Your questions and context go to OpenRouter and the model providers for one reason: to answer you. Whether they keep or train on that input is set by their own policies, not ours. If that matters to you, you can tighten it in your OpenRouter account's data settings, and it applies to every deliberation you run here.

Your control

  • Remove your stored API key any time from inside the app.
  • To delete your account or wipe your data, just ask through the contact form.

Consent versions

  • v2 (current): the consent recorded at signup since July 2026, covering this policy as written.
  • v1: the original signup consent from the first public release.

Questions, or a deletion request: support@executivecouncil.app, or use the contact form.

This is a plain-language summary, not a formal legal policy.