Legal

Privacy Policy

Last updated: August 27, 2026

COOKBOOK is an internalauthoring platform operated by Jack Morton (“we”, “us”). Our team uses it to structure pitch material and develop client presentation and experience concepts. Access is invite-only and protected by a site-wide gate and per-account sign-in; the platform is not open to the public, and clients do not log in to it. This policy explains what the platform processes, and how.

Information we process

  • Account information.For team members who sign in: email address, name, and role. Access is protected by a shared site-wide access password (a gate) and per-account sign-in via a one-time code emailed to you — we do not store individual account passwords.
  • Project content you provide. Presentations (e.g. PowerPoint files) and other materials uploaded to a project, the text and images extracted from them, and the concepts, renders, microsites, and documents generated from that content.
  • Activity & usage records.An audit log of actions taken in the platform (who did what, and when) and AI-usage/cost records — used for security, accountability, and operating limits such as daily spend caps.

What we do not collect

We do not run third-party advertising or analytics trackers, build behavioral profiles, or sell or rent any information. There is no public sign-up, no marketing list, and no external contact form. The platform sets only the strictly-necessary cookies described below.

Cookies

COOKBOOK sets only essential cookies: a sign-in/session cookie that keeps you authenticated, the site-gate cookie that controls access, and a small preference cookie that remembers your light or dark theme. These are required for the platform to function; there are no advertising or cross-site tracking cookies.

How we use it

We use this information solely to provide and operate the platform: to ingest and structure uploaded material, generate concepts and deliverables, render output, enforce operating limits, and secure and administer the service. We do not sell personal information.

AI processing

Generating intelligence, concepts, copy, and renders sends the relevant project content to third-party AI providers for processing on our behalf: Anthropic (the Claude API) and Google Cloud(Vertex AI / Gemini). Under those providers’ API terms, content submitted through their commercial APIs is not used to train their models; it is sent only to produce the output requested.

The Image Tool works differently and we describe it separately for that reason. Generating an image sends the compiled prompt — which can include client and brand names — and any reference-image identifiers to Artlist, and the finished images are delivered to your browser from Artlist’s network. That step runs through an Artlist account and a Claude account session rather than the commercial APIs above, so it is governed by those accounts’ own subscription terms. We are confirming their training and retention terms in writing, and until that is settled you should not put material into the Image Tool that your engagement agreement forbids sharing with sub-processors.

Hosting & sub-processors

  • Supabase — database, authentication, and file storage (US region).
  • Vercel — application hosting and content delivery.
  • Anthropic (Claude API) and Google Cloud (Vertex AI / Gemini) — AI processing of project text and images, as above.
  • Google Cloud Run — server-side rendering of uploaded presentations to images, and the document-editing service. These components download and process the original uploaded file.
  • Artlist — AI image generation, as described above.
  • Cloudflare — network transit for the Image Tool’s backend.
  • The Image Tool’s prompt-compilation and generation steps run on a dedicated always-on machine operated on Jack Morton’s behalf, outside Supabase and Vercel, which keeps its own append-only record of each run and its prompt.

Each is engaged under its data-processing terms. We do not share project content with anyone else except as needed to operate the service or as required by law.

Storage & security

Data is encrypted in transit and at rest. Access is restricted by row-level security and role, the original uploaded files are preserved byte-for-byte, and the service-role credential has a single audited entry point. See our security overview for the threat model and the vulnerability-reporting path.

Retention

We keep project content and account information for as long as the related project is active and as needed to operate the platform. Deleting a project removes its content, including the original uploaded file and the images extracted from it. Revoking a team member’s access removes them from the sign-in allowlist and ends their sessions; their user record and the security-log entries referencing them are retained, and deleting that record is a manual administrator action on request. There is no automated public deletion-request flow today — an internal team member can ask the platform administrator to delete a project and its files.

Security and usage records (the audit log and AI-cost ledger) are an append-onlyrecord kept for security and accountability, for the life of the engagement and a reasonable period afterward. These entries name the action, the account that took it (including their email address) and, for uploaded presentations, the document’s own author and organisation properties. Because the record is append-only by design it is not edited in place, so an erasure request against it is handled by the administrator directly and case by case rather than by an automated flow. Specific retention periods are confirmed with counsel before any use outside the internal team.

Your choices & contact

Because COOKBOOK is an internal, invite-only tool, requests to access, correct, or delete information it holds — including the data-subject rights that may apply to you (access, correction, deletion/erasure, and a copy of your data) — are handled internally: contact your COOKBOOK platform administrator at Jack Morton, who will action the request and confirm completion. We do not operate a public contact form or external request inbox for this platform.

Changes

We may update this policy as the platform evolves. Material changes will be reflected by the “last updated” date above.