Skip to main content

Privacy Policy

Last Updated: September 11, 2026

The Art of CTO — [TO CONFIRM: registered legal entity name], ABN [TO CONFIRM: Australian Business Number], of [TO CONFIRM: registered business address], Australia ("we," "us," or "our") — operates the website theartofcto.com, associated mobile applications, and related services (collectively, the "Platform"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Platform. Please read this policy carefully.

For the purposes of the GDPR, we are the controller of the personal data described in this policy, and the single point of contact for all data protection matters is privacy@theartofcto.com. We have not appointed a Data Protection Officer and are not required to under Article 37 GDPR. We do not have an establishment in the EU or the UK and have not appointed an Article 27 representative.

Where you use the Platform to record personal data about other people — team members in the 1:1 Assistant, named owners in the Command Center, individuals in files you upload — the roles reverse: you are the controller of that data and we act as your processor. The terms that govern that relationship are in our Data Processing Agreement, and the third parties involved are listed on our Sub-processor page.

Related documents

1. Information We Collect

Information You Provide

We collect information you voluntarily provide when you:

  • Create an account (name, email address, profile picture via Auth0)
  • Subscribe to our newsletter (email address, optional first name)
  • Submit a contact form or CTO Office inquiry (name, email, message, optional file uploads up to 50 MB per file including PDF, Word, Excel, images, and text files)
  • Subscribe to a paid plan (billing handled by Stripe; we do not store payment card details)
  • Set preferences (topics of interest, email frequency, theme, notification settings)
  • Complete onboarding (role, interests, experience level)
  • Interact with our AI Assistant (conversation content)
  • Use the Command Center (services, teams, infrastructure entities, relationships, assessments, incidents, cost data, SLOs, tech debt items, activity logs)
  • Use Foundry (business plans, lean canvases, strategic planning data; AI learns your communication style, risk tolerance, expertise areas, and decision-making patterns)
  • Use SplitCause (causal graphs, hypotheses, evidence, snapshots, share links)
  • Use the 1:1 Assistant (team member information, meeting notes including shared and private notes, mood ratings, action items, AI-suggested topics)
  • Use the SEO Command Center (search keywords, target domains, location preferences for SERP ranking and LLM visibility tracking)
  • Bookmark content (saved content with optional user notes and tags)
  • Participate in learning paths (progress, completed items, completion certificates)
  • Invite someone to the Platform (your invite code, and the email addresses you invite)
  • Register for push notifications (web push endpoint and keys; or native FCM (Android) / APNS (iOS) tokens with device label and platform)

Information Collected Automatically

When you visit the website, we may automatically collect:

  • IP address (stored temporarily; automatically deleted after 30 days)
  • Browser type and version, operating system, device type
  • Pages visited, time spent on pages, referral URLs
  • Click and scroll interactions, search queries entered on the Platform
  • Country and region (derived from IP address via Cloudflare headers)
  • Error and performance data (page load times, JavaScript errors)
  • Reading progress (scroll position, reading time, completion percentage per article)
  • Recently viewed content (last 50 items per user, including content type, title, view count, and timestamps)
  • Activity data for streaks, badges, and challenges (consecutive days active, tool usage counts, reading counts)

2. Mobile Application

If you use our mobile application, we collect additional information specific to mobile devices:

  • Device platform, model, and operating system version
  • Unique device identifiers
  • Push notification tokens (native FCM on Android, APNS on iOS, delivered via Firebase Cloud Messaging)
  • Crash data and performance metrics
  • Session replay data (sampled at 10% of sessions for quality improvement)
  • Full session replay on errors (100% of error sessions, including screenshots at time of error)

Mobile session replay and error data are processed by PostHog (see Section 3). Session replays capture user interactions for debugging purposes and may include screenshots of the app at the time of an error.

The restriction described in Section 3 — that PostHog session replay runs only on public, unauthenticated pages — applies to the website. In the mobile application, replay is sampled and error-triggered as described above. [TO CONFIRM: whether native replay should be limited or disabled on authenticated screens to match the web behaviour.]

3. Third-Party Services

We use the following third-party service providers to operate and improve the Platform. Each provider processes data on our behalf under contractual obligations to protect your information.

ProviderPurposeData Processed
CloudflareHosting (Workers via OpenNext.js), CDN, security, DNS, KV storage, R2 object storage, D1 database, AI Gateway, Zaraz (consent-gated script loading)IP addresses, request metadata, stored content and files. Zaraz manages loading of analytics and marketing scripts based on your consent preferences.
NeonPostgreSQL database hostingAll user-created content and account data
Auth0 (Okta)Authentication and identity managementEmail, name, profile information, credentials
StripePayment processing (PCI DSS Level 1)Payment card details, billing address (not stored on our servers)
BrevoEmail marketing and transactional emailEmail address, name, topic preferences, email engagement metrics
Google Analytics 4Website analytics (via Cloudflare Zaraz, consent-gated)Page views, events, session data, engagement metrics
Google Ads / AdSenseAdvertising and conversion tracking (consent-gated)Conversion events, advertising cookies
Microsoft ClarityBehavioral analytics, heatmaps, session recording (consent-gated)Click and scroll behaviour, session recordings, device info. Unlike PostHog, Clarity is not currently limited to public pages — see “Session Recording” below
PostHogProduct analytics, funnels, retention, session recording, and error tracking. Session recording, identified events and anything tied to your account are consent-gated; page-view counting is cookieless (see Section 4)Without consent: page views keyed by a daily-rotating hash of your IP address, browser and language, with no PostHog identifier stored on your device, no profile created and no link to any account. With consent: custom events (signup, tool usage, pricing interactions), session recordings on public pages only and within the limits set out under “Session Recording” below, error/exception details and stack traces, device info, and a client identifier promoted to your user ID after sign-in. Hosted on PostHog Cloud (EU region, eu.i.posthog.com).
OpenAIAI features (via Cloudflare AI Gateway)AI Assistant conversation inputs, Foundry AI and 1:1 AI suggestion prompts, content generation prompts for articles and daily sync briefings. Routed through Cloudflare AI Gateway to OpenAI (GPT-4o and successor models). OpenAI does not use API inputs for model training.
ElevenLabsText-to-dialogue audio generation for daily syncArticle text for audio synthesis. No user data is sent to ElevenLabs.
Cloudflare TurnstileCAPTCHA / bot protection on inquiry, waitlist and referral formsBrowser interaction data for bot detection, the challenge token, and your IP address, which is sent to Cloudflare for verification
SlackInternal operational notifications to our own private workspaceSystem alerts (worker failures, billing events), and the content of CTO Office inquiry submissions — which can include the name, email address and message you provided. Visible only to our own operators; never shared beyond them.
Firebase Cloud Messaging (Google)Mobile and web push notification deliveryPush notification tokens (native FCM on Android, APNS on iOS, web push endpoint and keys), device platform, device label
Cloudflare Workers AISecond-opinion AI rewrite pass on generated content (PosterBot refine, admin post refinement, Daily Sync voice pass)Article and briefing text submitted for rewriting. No account data is sent.
TavilyWeb search for content research and source verification (PosterBot, admin post refinement)Search queries derived from article topics or admin-supplied refinement prompts. No personal user data (name, email, IP) is sent to Tavily.
DataForSEOSEO data provider (SERP rankings, AI/LLM visibility monitoring)Search keywords, target domains, and location preferences entered by users in the SEO Command Center. No personal data (name, email, IP) is sent to DataForSEO.

Session Recording

PostHog — public pages only. PostHog session replay and interaction capture are switched off entirely on authenticated pages. We record and analyse behaviour only on our public and sign-up pages — marketing pages, published articles, the public tool catalogue and the sign-up flow. Once you are signed in, PostHog records nothing, so the work you do inside the Command Center, Foundry, SplitCause, the 1:1 Assistant and your dashboard never reaches it. That boundary is deliberate: those pages routinely show incident details, vendor assessments, salary bands and private meeting notes, none of which belong in a replay. On the pages that are recorded, anything you type is masked before it leaves your browser, and elements we mark as private are excluded from capture altogether.

Microsoft Clarity — not yet limited in the same way. Clarity is loaded through Cloudflare Zaraz and only after you grant analytics consent, but it is not currently scoped to public pages the way PostHog is: if you have consented, it can record on signed-in pages too. We are telling you this rather than describing an intention as though it were a control. If you would rather it did not, decline or withdraw analytics consent using the cookie-preferences button on any page and Clarity stops loading. We intend to bring Clarity inside the same public-pages-only boundary, and this paragraph will change when it is.

PostHog — Additional Details

PostHog provides our product analytics (funnels, retention, cohorts), session recording within the limits described above, and application error tracking. It is also the destination for our server-side runtime logs.

Configuration. The SDK starts with capturing opted out by default and only begins once you grant analytics consent. Person profiles are created only after sign-in; anonymous browsing remains pseudonymous. Events are hosted on PostHog Cloud EU (eu.i.posthog.com), with browser traffic proxied through p.theartofcto.com. You can opt out at any time via the cookie-preferences control; doing so disables capturing in the active session without a page reload. See PostHog's privacy policy for the full processor disclosure.

Analytics & Marketing — Consent Required

Google Analytics, Google Ads, Google AdSense, Microsoft Clarity, and PostHog are only activated after you provide explicit consent via our consent banner. The Google and Microsoft tools are managed through Cloudflare Zaraz; PostHog is loaded directly via its JavaScript SDK and is configured to start with capturing disabled by default, only enabling once you grant analytics consent. You can opt out at any time by adjusting your consent preferences or by installing the Google Analytics Opt-out Browser Add-on.

For more information, see: Google's privacy policy, Microsoft's privacy statement, Okta's privacy policy, Stripe's privacy policy, Brevo's privacy policy, Cloudflare's privacy policy, OpenAI's privacy policy, ElevenLabs' privacy policy, PostHog's privacy policy, Neon's privacy policy, DataForSEO's privacy policy.

We do not sell, trade, or rent your personal information to third parties. We may share your information with the service providers listed above, who process data on our behalf subject to confidentiality agreements and data processing addendums.

The authoritative, maintained version of this list — including what each provider receives and where it processes — is our Sub-processor page. We give at least 30 days' notice before a new sub-processor begins processing customer data. We may also disclose personal data where required by law, to enforce our Terms of Service, to protect our rights or the safety of others, or to a purchaser in connection with a merger, acquisition or sale of assets — in which case we will notify you before your data becomes subject to a different privacy policy.

4. Cookies and Tracking Technologies

This section is a summary. The complete register — every cookie and storage key, its exact name, duration and purpose — is our Cookie Policy.

Cookies We Use

Strictly Necessary Cookies (always active):

  • auth_session — Encrypted authentication session (expires after 24 hours; carries a __Host- or __Secure- prefix in production)
  • csrf_token — Cross-site request forgery protection (double-submit cookie pattern; the value is also sent in the x-csrf-token request header by our frontend code so the server can verify the two match; expires after 1 hour)
  • auth_state — Holds the OAuth state and PKCE verifier during sign-in only (expires after 10 minutes)
  • zaraz-consent — Stores your cookie consent preferences for Cloudflare Zaraz (which gates the loading of analytics and marketing scripts based on your choices)
  • Cloudflare security cookies (for example __cf_bm) — Bot management and abuse prevention on our edge network

Cookieless Audience Measurement

We count page views on our own servers without setting a cookie or reading anything from your device. For each page request our edge server computes a hash from a server-side secret, the current date (UTC), your IP address, your browser's User-Agent and its language preference, and sends that hash together with the page path, referrer and country to PostHog as an anonymous event. The hash changes every day and the secret never leaves our servers, so the value cannot be turned back into an IP address and cannot be used to recognise you from one day to the next. No profile is created from these events and they are never linked to an account, even if you later sign in. We use the resulting counts only to understand which pages are read and roughly how many people read them. This processing relies on our legitimate interest in measuring our own audience; because it stores nothing on your device it is not subject to the consent banner.

Analytics Cookies (set only after you provide analytics consent):

  • _ab_id — A random identifier that keeps you in the same variant of an A/B test between visits, so the site does not change shape under you. It is not linked to your account and is not shared with any third party, and it lasts 1 year. It is written only after you grant analytics consent; decline or withdraw and no cookie is set, any existing one is deleted, and you stay on the default variant without being counted in any experiment.
  • _ga, _ga_* — Google Analytics client and session identifiers
  • _clck, _clsk — Microsoft Clarity session identifiers
  • ph_*_posthog — PostHog session identifier and feature-flag state (cookie name varies by project key; only set after analytics consent is granted)

Marketing Cookies (set only after you provide marketing consent):

  • Google Ads conversion tracking cookies
  • Google AdSense advertising cookies

Local Storage

We use browser local storage to enhance your experience. This data stays on your device and is not transmitted to our servers unless explicitly noted:

  • Consent preferences stored in c15t-consent localStorage key by our consent UI (c15t), synced with our server for GDPR audit trail. Cloudflare Zaraz separately reads its own zaraz-consent cookie (described above) to decide which analytics and marketing scripts to load — the two are kept in sync.
  • Theme preference (dark/light mode)
  • Reading list and bookmarked content
  • Recent search queries (for autocomplete)
  • Recently viewed pages
  • PostHog SDK state (anonymous distinct ID, person properties, feature-flag cache) under keys prefixed ph_*_posthog. Written only after analytics consent is granted; cleared by PostHog's reset() on sign-out.

Managing Your Preferences

You can manage your cookie preferences at any time using the consent banner that appears on first visit, or by adjusting your browser settings. Note that disabling strictly necessary cookies may prevent the Platform from functioning properly.

5. Consent Management

We use a consent management system to ensure analytics and marketing technologies are only activated after you provide explicit opt-in consent. Consent records are stored with a full audit trail, including:

  • Categories accepted and rejected
  • IP address and approximate geographic location
  • Timestamp and consent version
  • Link to any previous consent record (for audit trail)

IP addresses stored in consent records are automatically deleted (set to null) after 30 days. Consent records expire after 1 year, at which point you will be asked to re-confirm your preferences.

6. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Platform and its features
  • Send newsletters, weekly briefings, push notifications, and marketing communications (with your consent)
  • Process payments and manage subscriptions
  • Authenticate your identity and manage your account
  • Personalize your experience (content recommendations, learning paths, AI responses)
  • Track engagement (streaks, badges, challenges, reading progress)
  • Analyze usage trends to improve our content, tools, and services
  • Detect, prevent, and address fraud, abuse, and security threats
  • Scan uploaded files for malware (via ClamAV)
  • Track referral program participation and reward credits
  • Respond to your inquiries and provide customer support
  • Comply with legal obligations

Lawful Bases for Processing (GDPR Article 6)

If you are in the EEA or the UK, we must have a lawful basis for each processing activity. This table maps them. Where the basis is consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal. Where the basis is legitimate interests, you may object under Article 21 — see Section 8.

Processing activityLawful basisNotes
Creating and operating your account; authenticationContract — Art. 6(1)(b)Necessary to provide the service you asked for.
Storing and displaying your Command Center, Foundry, SplitCause, 1:1, bookmark and learning-path dataContract — Art. 6(1)(b)This is the product. Where the data concerns third parties, you are the controller and we are your processor.
Processing payments and managing subscriptionsContract — Art. 6(1)(b); Legal obligation — Art. 6(1)(c) for tax and accounting recordsCard details are handled by Stripe, not by us.
Transactional and service email (receipts, security notices, account changes)Contract — Art. 6(1)(b)You cannot opt out of these while you hold an account, because they are part of running it.
Newsletter, weekly briefings, marketing email and push notificationsConsent — Art. 6(1)(a)Withdraw at any time via the unsubscribe link or your preferences.
Analytics cookies, session replay and advertising technologiesConsent — Art. 6(1)(a), and consent under the ePrivacy Directive for storage on your deviceNothing loads until you opt in. Withdraw at any time via the cookie-preferences control.
Cookieless audience measurement (server-side page counting)Legitimate interests — Art. 6(1)(f)Our interest in knowing which pages are read. No identifier is stored on your device and no profile is built, so the impact on you is minimal.
Security: rate limiting, bot and abuse detection, honeypot logging, malware scanning of uploads, fraud preventionLegitimate interests — Art. 6(1)(f)Our interest, and yours, in a platform that is not overrun. IP addresses used for this are deleted after 30 days.
AI features (AI Assistant, Foundry, 1:1 suggestions)Contract — Art. 6(1)(b)You trigger the processing by using the feature. Inputs are not used to train third-party models.
Product improvement, error diagnosis and support correspondenceLegitimate interests — Art. 6(1)(f)Our interest in a working, improving product.
Streaks, badges, recommendations and personalisationLegitimate interests — Art. 6(1)(f)Object at any time; the features simply stop personalising.
Keeping consent records with a timestamp and IP addressLegal obligation — Art. 6(1)(c), read with Art. 7(1)We are required to be able to demonstrate that consent was given.
Retaining invoices and payment recordsLegal obligation — Art. 6(1)(c)Tax and financial record-keeping requirements.
Responding to legal claims or requests from authoritiesLegal obligation — Art. 6(1)(c); Legitimate interests — Art. 6(1)(f)Establishing, exercising or defending legal claims.

We do not carry out any automated decision-making that produces legal or similarly significant effects on you within the meaning of Article 22 GDPR. AI features generate suggestions for you to act on; they do not decide anything about you.

7. Data Retention

  • Authentication sessions: 24 hours
  • IP addresses: Automatically deleted after 30 days
  • Consent records: 1 year (IP addresses deleted after 30 days)
  • Analytics data: Retained per Google Analytics and Microsoft Clarity default retention periods
  • Newsletter subscriber data: Until you unsubscribe
  • Account data: Until you request account deletion
  • Payment records: Retained as required by tax and financial regulations
  • AI conversation history: Retained while your account is active
  • Honeypot logs: 30 days
  • Security audit logs: 12 months (IP addresses and user-agent strings removed after 30 days)
  • Recently viewed items: Last 50 items per user (older items automatically removed)
  • File uploads: Retained until inquiry is closed, plus 90 days
  • Push notification tokens: Deleted on unsubscribe or account deletion
  • Referral data: Retained while the referral program is active
  • Command Center, Foundry, SplitCause, and 1:1 data: Retained until you delete the data or your account is closed
  • Bookmarks and learning path progress: Retained while your account is active
  • Onboarding data: Retained while your account is active
  • SEO Command Center data: Tracked keywords, rank snapshots, and LLM mention history retained while your account is active; LLM mention cache expires after 24 hours

8. Your Rights (GDPR)

If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR):

  • Access: Request a copy of your personal data
  • Rectification: Request correction of inaccurate or incomplete data
  • Erasure: Request deletion of your data ("right to be forgotten")
  • Portability: Request transfer of your data in a machine-readable format
  • Objection: Object to processing of your data for certain purposes
  • Restriction: Request restriction of processing
  • Withdraw Consent: Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before you withdrew it
  • Complain: Lodge a complaint with a data protection supervisory authority (Article 77) — see below

To exercise any of these rights, please contact us at privacy@theartofcto.com. We will respond within 30 days. There is no charge, unless a request is manifestly unfounded or excessive. We may ask you to verify your identity before acting on a request.

Right to Lodge a Complaint (GDPR Article 77)

If you believe our processing of your personal data infringes data protection law, you have the right to lodge a complaint with a supervisory authority — in particular in the EU or EEA Member State of your habitual residence, your place of work, or the place of the alleged infringement. Exercising this right does not affect any other remedy available to you.

  • European Union / EEA: your national data protection authority. The list is published by the European Data Protection Board at edpb.europa.eu.
  • United Kingdom: the Information Commissioner's Office at ico.org.uk.
  • Australia: the Office of the Australian Information Commissioner at oaic.gov.au. The OAIC normally expects you to raise the matter with us first and allow 30 days for a response.

We would rather hear from you before you go to a regulator, but that is a preference, not a condition — you are entitled to complain directly at any time.

9. Your Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with the following rights:

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we collect
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: Opt out of the sale or sharing of personal information (we do not sell your data)
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights

To submit a request, contact us at privacy@theartofcto.com.

10. International Data Transfers

Your information may be transferred to and processed in countries other than your own, including the United States and the European Union, where our service providers operate. When we transfer data outside of the EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or other legally recognized transfer mechanisms to ensure an adequate level of data protection.

11. Unsubscribe from Communications

You can unsubscribe from our newsletter and marketing communications at any time by:

  • Clicking the "Unsubscribe" link at the bottom of any newsletter email
  • Updating your preferences in your account dashboard
  • Disabling push notifications in your browser or device settings
  • Contacting us at unsubscribe@theartofcto.com

12. Data Security

We implement appropriate technical and organizational security measures to protect your personal data, including:

  • HTTPS/TLS encryption for all website traffic
  • Encrypted session cookies (AES-GCM)
  • CSRF protection on all authenticated API endpoints
  • IP-based rate limiting and abuse detection
  • Web Application Firewall (WAF) and DDoS protection via Cloudflare
  • Secure API connections to all third-party services
  • Automatic IP address deletion after 30 days
  • Automated malware scanning of uploaded files (ClamAV)
  • Honeypot-based bot detection
  • Content Security Policy (CSP) headers to prevent cross-site scripting
  • Regular security monitoring

However, no method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

13. Children's Privacy

The Platform is not intended for children under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal data from a child under 16 without parental consent, we will take steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us at privacy@theartofcto.com.

14. Do Not Track & Global Privacy Control

We do not currently implement automated handling of Do Not Track (DNT) or Global Privacy Control (GPC) browser signals. You can manage your tracking preferences at any time via our consent banner, which controls whether analytics and marketing technologies are activated.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this page and, where appropriate, notify you by email or through a notice on the Platform. Your continued use of the Platform after changes are posted constitutes acceptance of the revised policy.

16. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us at: