Privacy Policy
Your information.
Handled carefully.
Effective date: July 13, 2026 · CULT+MATH LLC · Texas, United States
01
Who we are
CULT+MATH LLC (“A2A™,” “we,” “us,” or “our”) operates the A2A™ platform at alignedtoact.com. This Privacy Policy describes how we collect, use, disclose, and protect information in connection with your use of our services.
By accessing or using A2A™, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please discontinue use of the platform.
02
Your book — what we hold, and why
A2A™ keeps your book for you. Your client list, your notes, and your outputs are stored — encrypted, isolated to you — so the tenth run knows more than the first, and so you can look back in two years and see why an account went the way it did. We do not train AI models on it. We do not sell it. You can switch the note-keeping off, delete any of it, and take all of it with you.
A2A™ holds three kinds of information you give us, and it is worth being precise about which is which:
- Your accounts — the client list you build: company names, websites, fees, renewal dates, the people you deal with, and which of your services each client buys.
- Your intake — what you type into a tool when you run it: the situation, the context, your own read on what is really going on.
- Your outputs — the results you choose to save.
All three are stored securely, encrypted at rest, and isolated to your account — no other user of A2A™ can reach them. The one exception is an output you choose to share, and we explain exactly what that means below. We hold your information for one reason: to make the platform work better for you over time. A tool with no memory cannot tell you that you have gone four months without bringing a client a proactive idea. That is the job, and it requires the record.
Training AI models — a promise we can keep. We do not train artificial-intelligence models on your information. We are telling you what we do today, and we are also telling you what would have to happen before that ever changed: if we ever build something that would learn from your data, it will be opt-in, it will be off by default, and we will ask you first. We would rather write a sentence that survives contact with our own roadmap than one that sounds better today and quietly stops being true. You will never wake up to find that a policy update turned this on for you.
What we never do with it. We do not sell your information. We do not use it for advertising or to build an advertising profile of you. Authorized personnel may review inputs and outputs only where necessary to operate, secure, and support the platform.
Sharing a read — and what it costs. You can generate a link to share a single output with someone else. Read this before you use it. A shared link is a public web address. It is long and unguessable, it stops working after 7 days, and you can revoke it at any time — but while it is live, anyone who has the link can open it, without signing in. If it is forwarded, it works for whoever receives it. Nothing else in your book is exposed — only the one output you shared. But that output may name your client, name what you have found out about them, and say what you plan to do about it. Do not share a read with anyone you would not hand the printed document to. We are building a version that requires the recipient to sign in; it does not exist yet, and we would rather tell you that than let you assume otherwise.
How to switch it off. Note-keeping is on by default, because a half-kept history is worse than none — it leaves gaps the platform cannot see. You can turn it off at any time in settings. When it is off, what you type into a tool is used to produce your output and then discarded — nothing from a run is kept against the account. Your client list, the notes you deliberately write onto an account, and your saved outputs all remain either way. You put those there on purpose; we do not take them away because you changed a setting.
Deleting, and leaving. You can delete an individual output, delete an entire account and everything held against it, or close your account and have all of it removed within 30 days. A self-serve export button is being built and does not exist yet — until it does, ask us and we will send you everything we hold, in a readable format, at no charge. A custodian who will not return the deposit is not a custodian.
Information about people at your clients. Your accounts will often contain names, roles, and contact details of people who work at your clients. Those people are not our users. You are the controller of that information; we process it on your instructions, hold it under the same protections as the rest of your book, and delete it when you delete the account. You are responsible for having the right to give it to us — see the Terms.
During processing, your information passes transiently through operational systems — application memory and third-party AI infrastructure. We contractually require our service providers to use your information only to operate the platform on our behalf, and not to train their own models on it. Your intake is never written to our application logs, error traces, or usage-metrics tables.
03
Information we collect automatically
We collect limited operational data necessary to provide and improve the platform:
| Category | Purpose |
|---|---|
| Account information (email address, subscription tier, subscription status) | To authenticate you and manage your subscription access |
| Usage metadata (which tool was used, timestamp, anonymized session identifier) | To understand platform usage patterns and improve our services |
| Payment transaction records | To fulfill payment obligations and maintain required financial records. Payment card details are handled exclusively by our payment processor. |
| Authentication session tokens | To maintain your authenticated session between visits |
We design our operational logging and analytics to avoid and minimize capturing Intake Content. Usage metadata focuses on which tool was used and when — not on the substance of your deal descriptions, contact names, or account context.
04
How we use your information
We use information we collect for the following purposes:
- To provide, operate, maintain, and improve the A2A™ platform
- To authenticate your identity and manage your subscription
- To process payments and prevent fraud or unauthorized use
- To communicate with you regarding your account, subscription, and material platform updates
- To analyze aggregated usage patterns for product development purposes
- To review inputs and outputs, where authorized, to operate, secure, and improve the platform
- To enforce our Terms of Service and protect the rights, property, and safety of CULT+MATH LLC and its users
- To comply with applicable legal obligations
We do not sell, rent, or trade your personal information to third parties for their own commercial purposes. We do not use your information for behavioral advertising.
05
Third-party service providers
We engage third-party service providers (“Sub-processors”) to assist in operating the platform. All Sub-processors are contractually bound to process your information only on our documented instructions, to maintain appropriate security measures, and not to use your information for any purpose other than providing services to us.
Our Sub-processors operate in categories including AI processing infrastructure, payment processing, database and authentication services, email delivery, and cloud hosting. Each Sub-processor receives only the minimum information necessary to perform its designated function.
We do not authorize any Sub-processor to sell your information or to disclose it to third parties except as required to perform services for us or as required by applicable law.
To request information about our current Sub-processors, contact us at privacy@alignedtoact.com.
06
Cookies and tracking technologies
A2A™ uses only essential cookies required for the platform to function. We do not use advertising cookies, behavioral tracking technologies, or third-party analytics services.
Essential cookies include authentication tokens that maintain your signed-in session. These cookies are strictly necessary and cannot be disabled without preventing platform functionality. You may configure your browser to block or delete cookies, but doing so may impair your ability to use the platform.
07
Data retention
We retain account information for as long as your account remains active and for such additional period as may be required by applicable law or as necessary to protect our legitimate legal interests.
Usage metadata may be retained indefinitely in anonymized or aggregated form that cannot reasonably be used to identify you.
Your accounts are retained until you delete them or close your account. Your intake is kept against the account it relates to, for a limited retention period (a 24-month default), and you can delete it at any time — individually, or by deleting the account. Outputs you save are retained until you delete them or close your account. If you switch note-keeping off in settings, intake is used to produce your output and then discarded, and nothing new is kept against the account.
Deleting an account does not destroy your saved work. When you delete an account, everything held against it is removed — the record, the contacts, the notes. Outputs you previously chose to save are kept, and simply stop being linked to that account. We will not quietly destroy something you deliberately saved.
Usage metadata — that a run happened, which tool, when, how long it took — is retained separately and never contains what you typed.
Shared links expire. A link you generate to share an output stops working 7 days after you create it, and you can revoke it sooner. Deleting the underlying output also kills the link. We do not keep a separate copy of a shared output, and we do not index shared links or make them findable by search.
When you close your account, we will delete your personal information within 30 days, subject to any retention required by law.
08
Security
We implement and maintain reasonable technical and organizational security measures designed to protect your information against unauthorized access, disclosure, alteration, or destruction. These measures include encryption of data in transit and at rest (AES-256), tenant isolation, access controls, and periodic security assessments.
Where our protections stop. Two limits, stated plainly rather than buried. First: a link you choose to share is not authenticated. Anyone holding it can open the shared output without signing in, until it expires or you revoke it. That is a deliberate trade for convenience, it is the one place your book leaves its walls, and it happens only when you decide it should. Second: your notes about your clients are the most sensitive thing we hold — more sensitive than a client list, because they contain your candid read on relationships and on the people inside them. We hold them to a standard that matches that, and we would rather say so than let it go unsaid.
No security measure is infallible. We cannot guarantee the absolute security of information transmitted to or stored by us. You provide information to A2A™ at your own risk. You are responsible for maintaining the confidentiality of your account credentials.
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and applicable regulatory authorities as required by law.
09
Your rights and choices
Subject to applicable law and verification of your identity, you may have the right to: access the personal information we hold about you; request correction of inaccurate information; request deletion of your personal information; object to or restrict certain processing; and receive a copy of your information in a portable format.
To exercise these rights, contact us at privacy@alignedtoact.com. We will respond within 30 days. We reserve the right to decline requests that we are not legally required to fulfill, that are manifestly unfounded or excessive, or that would adversely affect the rights of others.
If you are a resident of California, the European Economic Area, or the United Kingdom, you may have additional rights under applicable privacy law. Please contact us for jurisdiction-specific information.
You have the right to lodge a complaint with your applicable data protection authority if you believe we have processed your information unlawfully.
10
International data transfers
A2A™ is operated in the United States. If you access the platform from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our Sub-processors operate. By using A2A™, you acknowledge and consent to the transfer of your information to countries that may have different data protection laws than your country of residence.
11
Children
A2A™ is intended solely for use by individuals who are at least 18 years of age. We do not knowingly collect personal information from persons under 18. If we become aware that we have collected information from a person under 18, we will delete that information promptly. If you believe we have inadvertently collected such information, contact us at privacy@alignedtoact.com.
12
Changes to this policy
We reserve the right to modify this Privacy Policy at any time. We will notify subscribers of material changes by email no fewer than 14 days before the effective date of such changes. The effective date at the top of this page will be updated to reflect the date of the most recent revision. Your continued use of A2A™ following the effective date of any modification constitutes your acceptance of the revised policy.
Privacy inquiries: privacy@alignedtoact.com
General support: support@alignedtoact.com
CULT+MATH LLC · Texas, United States