
Privacy Policy
Last Updated: February 14, 2026
1. Introduction
The Right Consultant ("we," "our," or "us") is an AI-powered consulting platform that helps professionals generate insights, manage projects, and organize their work through intelligent conversations. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use our platform.
By creating an account or using our services, you agree to the practices described in this policy. If you do not agree, please do not use the platform.
2. Information We Collect
2.1 Account Information
When you register, we collect:
Email address (required for all accounts)
Username (optional)
Password (hashed and stored securely for username/password accounts)
Google account identifier (if you sign in with Google)
Profile avatar image (if you choose to upload one)
2.2 Content You Create
Through your use of the platform, you may create and store the following types of content:
Conversations (consultations) and messages
Uploaded documents and files
Generated reports (including PDF exports)
Projects and tasks
Blueprints (coaching plans)
Journal entries
Time tracking entries and task hierarchies
Metrics and data visualizations
Brand/client profiles
Resource records including contacts, locations, websites, and references
2.3 Subscription and Payment Information
If you subscribe to a paid plan, we collect:
Subscription plan selection and billing cycle
Payment processing is handled entirely by Stripe. We do not store your credit card number, bank account details, or other sensitive payment credentials on our servers. Stripe provides us with a customer identifier and subscription status.
2.4 Usage and Activity Data
We collect activity logs that record:
Actions you take within the platform (e.g., creating, updating, or deleting content)
The type and title of content affected
Timestamps of activity
AI model usage and token consumption for billing purposes
2.5 Session Data
We use server-side sessions to keep you logged in. A session cookie is stored in your browser to identify your authenticated session. We do not use third-party tracking cookies or advertising cookies.
3. How We Use Your Information
We use your information for the following purposes:
Providing the Service: To create and manage your account, deliver AI-powered consultations, generate reports, and enable all platform features.
AI Processing: Your conversation messages and uploaded documents are sent to AI language models to generate responses, extract structured data (such as contacts, locations, and metrics), and produce reports. See Section 4 for details on which AI services process your data.
Email Communications: We use your email address to send password reset links and transactional notifications related to your account. We do not send marketing emails.
Payment Processing: Your subscription and payment details are used to manage your plan, process payments, and enforce usage limits based on your subscription tier.
Platform Improvement: Activity logs and usage data help us monitor platform performance and improve the service.
4. Third-Party Services
We rely on the following third-party services to operate the platform. Each has its own privacy policy governing how it handles data:
4.1 AI Processing Services
Google Gemini / Vertex AI: Your conversation messages, document contents, and prompts are sent to Google's Gemini models (including Gemini 2.5 Flash via Vertex AI) to generate AI responses, extract structured data, and produce reports. Google's Vertex AI Search is used for retrieval-augmented generation (RAG) over private knowledge. Google Search Grounding may be used for real-time market research. Data sent to these services is subject to Google's Cloud Data Processing Terms.
OpenAI (GPT-4o): When you select OpenAI as your AI model for a conversation, your messages and documents are sent to OpenAI's API. Data is subject to OpenAI's Usage Policies and API Data Privacy.
4.2 Payment Processing
Stripe: Handles all payment processing, subscription management, and billing. We share your email address and subscription details with Stripe. We never receive or store your full payment card information. Subject to Stripe's Privacy Policy.
4.3 Email Service
Postmark: Used to send transactional emails such as password reset links. Your email address is shared with Postmark for delivery purposes. Subject to Postmark's Privacy Policy.
4.4 Data Storage
Neon PostgreSQL: Your account data, conversations, messages, documents metadata, reports, projects, and all other structured data are stored in a PostgreSQL database hosted by Neon. Subject to Neon's Privacy Policy.
Replit Object Storage: Uploaded files, document attachments, avatar images, and generated report files are stored in cloud object storage provided by Replit. Subject to Replit's Privacy Policy.
4.5 Maps and Location Services
Google Maps: When location data is extracted from your consultations, it may be displayed using the Google Maps JavaScript API. Your use of Google Maps features is subject to Google's Privacy Policy.
4.6 External Platform Integrations (Optional)
If you choose to connect external project management platforms (such as Todoist, Asana, Jira, Trello, ClickUp, Monday.com, Teamwork, or Wrike), project data will be synchronized between The Right Consultant and the connected platform. This sync is initiated by you, and only project/task data is shared. Each external platform is governed by its own privacy policy.
5. Data Storage and Security
All data is stored on secure, cloud-hosted infrastructure.
Passwords are hashed before storage and are never stored in plain text.
Sessions are managed server-side with secure, HTTP-only cookies.
File uploads are stored in cloud object storage with access restricted to authenticated users who own the content.
Time tracking hierarchy data supports encryption for portable export, using encryption keys that you control.
We implement ownership verification on all data access and modification endpoints to ensure users can only access their own data.
While we take reasonable measures to protect your information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
6. Your Rights and Data Deletion
6.1 Access and Control
You can access, view, and export your data at any time through the platform. This includes conversations, documents, reports, projects, journal entries, time tracking data, blueprints, metrics, and all resource records.
6.2 Deletion of Your Content
You have the ability to delete the following types of content at any time, either individually or in bulk where supported:
Conversations (individual or multiple at once) — deleting a conversation also removes all associated messages and documents
Documents (individual deletion)
Reports (individual or bulk deletion)
Projects (individual or bulk deletion, with status changes also available in bulk)
Blueprints (individual deletion)
Journal entries (individual deletion)
Time tracking entries (individual deletion; time node hierarchies can be archived)
Metrics (individual deletion)
Contacts, Locations, Websites, and References (individual deletion; references also support bulk deletion)
Brand/Client profiles (individual deletion)
Groups (individual deletion — conversations within the group are preserved)
All deletion operations verify ownership before proceeding. Deleted data is permanently removed from our database.
6.3 Account Deletion
If you wish to delete your entire account and all associated data, please contact us at the email address listed in Section 11. We will process your request and remove all your data from our systems within 30 days.
6.4 Limitations
Once data is deleted, it cannot be recovered. Data that has already been processed by third-party AI services (Google, OpenAI) is subject to those providers' data retention policies. We do not control how long third-party services retain data sent to their APIs.
7. Data Retention
Your account data and content are retained for as long as your account is active.
Completed or cancelled background AI jobs are automatically cleaned up after 30 days.
Activity logs are retained for platform monitoring purposes and may be periodically purged.
If you delete your account, all associated data will be removed within 30 days.
8. Cookies and Tracking
We use a single session cookie to maintain your authenticated login session. This cookie is:
Essential for the platform to function
HTTP-only and secure
Not used for tracking, advertising, or analytics
We do not use third-party tracking cookies, advertising pixels, or analytics services that track individual users.
9. Children's Privacy
The Right Consultant is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that a child under 18 has provided us with personal information, we will take steps to delete that information.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by updating the "Last Updated" date at the top of this page. Your continued use of the platform after any changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy, wish to exercise your data rights, or need to request account deletion, please contact us at:



