Privacy Policy
Who is responsible for your data
Broomstick AI LLC operates this website and the training program, and is the company responsible for the data described in this policy. If you have a question about anything in this policy, or about data we hold that relates to you, contact us at [email protected]. The later sections explain what we collect, what it can be linked to, how to opt out, and how to ask us to delete what we hold.
The short version
This site sets one first-party cookie, whose only job is to keep the version of the page you see stable between visits. It stores nothing else in your browser and loads nothing from third parties: no analytics services, no advertising pixels, no social media code, no outside fonts. Your browser talks only to our own servers, except when you choose to pay, which happens on Stripe's own pages. As you use the site, we record usage events on our servers; those events never contain your email address or your IP address, but our server does separately record your IP address and how you arrived. Personal details such as your email are collected only when you type them in. A Manage cookies control in the footer of every page lets you opt out at any time.
The one cookie we set
The cookie is named bs_assignment. Our own JavaScript sets it when the page loads; there is no consent banner. It is sent only to this site, lasts up to 365 days, is limited to same-site requests (SameSite=Lax), can be read by scripts running on our pages, and is not marked Secure. It holds four values: an assignment id (a random identifier minted by our server), a campaign id, the time of your last visit, and the version number of the page configuration you last saw. It holds no email address, no name, and no IP address. Its job is to keep the page stable, so the arrangement you see does not change between visits. If your browser blocks it, the site works normally and shows the standard default page; we never ask you to enable cookies. This cookie is the only thing the site stores in your browser: no localStorage, no sessionStorage, no IndexedDB, no cache storage, no service worker.
What we record as you use the site
As you use the site, your browser sends usage events to our own servers: pages opened, which sections of a page came into view, which buttons were used, column toggles, checkout being started, booking requests, and interest captures. Each event carries an event id, a session id, your assignment id, the event type, which version of the page you were shown, a small structured value, timestamps, and software version stamps, plus whether your browser requests reduced motion, an accessibility setting. The version of the page you were shown is chosen by a calculation in your browser using your assignment id; no outside service is involved, and the choice itself is not stored in your browser. Your email address is never in this event stream: the events have no field for it, and a scanner rejects any event containing anything shaped like an email. Where a reference to a signup is needed, an opaque random identifier issued by our server stands in; it is not derived from your email and cannot be turned back into it. Your IP address is likewise never in the event stream.
What our server records about your visit
When your browser connects to our server, the server itself records information the events do not carry. Against your assignment id, we record the IP address of your connection, updated on every visit rather than captured only once; the page that referred you to us, if your browser sent one; and any campaign or UTM parameters in the link you clicked. We state this plainly because the event stream's omission of your IP address does not mean we never see it: we see it, and record it, on every visit.
The assignment id, and what it can be linked to
The assignment id is a random identifier; it is not built from your name, your email, or your device. But it is pseudonymous, not anonymous, and the difference matters. In your browser it is a meaningless string. On our server it is a key. It links your usage events to each other across visits, and to the IP address and referral information described above. If you ever give us your email, name, or phone number, or make a payment, those are recorded on our server too, and the assignment id can join your usage history to them. So while the id itself contains nothing about you, the data behind it can identify you, and you should assume that in our hands it does. We do not describe this id as anonymous, because in our hands it is not.
When you give us your email, name or phone
We collect personal contact details only at moments you choose: joining a waitlist, asking to be notified, or requesting a call. A call request asks for your name, phone number, and email address. These details are stored in two places on our server. We do not use an email marketing service of any kind, and there is no automated mailing: giving us your email does not put you on an automated list. A call request may be forwarded to an internal alert channel so that a person on our team sees it promptly; that notification path is internal to our systems.
Payment and Stripe
Stripe processes payments, and it works by redirect: our server creates a Stripe Checkout session and sends your browser to a page hosted by Stripe, where you enter your card details on Stripe's domain. We never see or store your card number. Stripe's code is not loaded on our pages, so Stripe sets no cookie on our domain and learns nothing about your browsing here; it sees you only when you arrive at its checkout page. With the checkout session we send Stripe your assignment id (used as the client reference), the campaign id, any UTM values from your arrival link, the cohort you are enrolling in, and the version numbers of the Terms and Privacy Policy you accepted. We do not send Stripe your email address; Stripe may collect one itself on its own page, under its own privacy policy.
Third parties, and the ones we do not use
The only third party involved is Stripe, and only when you choose to pay, by leaving our site for Stripe's. Beyond that, the only network requests this site causes your browser to make are to our own servers. There is no third-party analytics or tag management (no Google Analytics, Segment, Mixpanel, Amplitude, PostHog, or Plausible), no advertising or social pixels (no Meta, LinkedIn, X, TikTok, Google Ads, or DoubleClick), no session recording or heatmap tools (no Hotjar, FullStory, LogRocket, or Clarity), no third-party A/B testing or personalization vendors, no error-monitoring services (no Sentry or Datadog), no embedded video, maps, iframes, or reCAPTCHA, and no outside fonts: the fonts on this site are served from our own servers.
Your choices and the Manage cookies control
Every page has a Manage cookies control in its footer; it is always present and cannot be switched off by any setting on our side. Opting out takes effect immediately, with no page reload: the cookie is deleted, a latch prevents anything from writing it back, events not yet sent are discarded, no further events are sent for the rest of your visit, and every section of the page you are viewing switches to its plain default version. We keep no record of the opt-out itself, because storing your choice would be a second piece of storage in your browser. That means a later visit starts fresh and sets the cookie again unless you opt out again. If you want a lasting opt-out, block the cookie in your browser settings; the site works identically without it.
How long we keep things, and how to ask us to delete
We do not have an automatic deletion schedule, and we are not stating a retention period, because none is built into our systems today. The data described in this policy — usage events, server visit records, and any contact details you gave us — is kept until we delete it. You can ask us to delete it: write to [email protected] and request deletion of your contact details and the records tied to your assignment id. Include the email address you used and, if you can, the assignment id from the bs_assignment cookie, so we can locate what relates to you. The same address is the way to reach us with any question about this policy.
This is interim prose
This policy was drafted with AI assistance and has not yet been reviewed by a law firm; the page that displays it says so in a banner. We publish it now because it is a correct description of what this site does. The version you accept at checkout is recorded, so later edits do not change what you agreed to, and when counsel's review is complete, any changes will appear as a new published version.
Entity
Broomstick AI LLC
Changelog
- v1 — 2026-08-05 — Initial privacy policy.
- v2 — 2026-08-25 — Full rewrite. Corrects three things v1 stated too favourably: the assignment id is now described as pseudonymous rather than anonymous, with the links it can be joined to on our server spelled out; your IP address is recorded on every visit rather than only the first; and a claim about which company hosts our database is removed, because we could not confirm it. Adds the cookie's real settings and lifetime, the fact that nothing else is stored in your browser, a named list of the third parties we do not use, the absence of any retention schedule, and how to ask us to delete what we hold.
- v3 — 2026-09-28 — Published as our current privacy policy. What it describes is unchanged from v2.