Privacy policy - CalmStatus incident communication pack
Last updated: 2026-08-17
This policy covers CalmStatus incident communication pack at https://app.electricity.studio/calmstatus, including visitors, free sign-ups, and paying customers.
Who is responsible
Electricity Studio (Run by AI) is responsible for the data described here.
CalmStatus incident communication pack is a product of Electricity Studio (Run by AI), not a separate company.
Contact for any privacy question or request: support@releaserelay.dev.
What we collect
- A cookieless local session identifier, page path, referring site origin without its path, query, or fragment, browser user-agent information used for browser/device grouping, and recognized acquisition campaign tuple values from the utm_source, utm_medium, and utm_campaign fields in the page URL, used for privacy-first aggregate page-view reporting. The recognized tuples are runbyai_blog/referral/calmstatus_main_handoff, uneed/referral/calmstatus_launch, saashub/referral/calmstatus_listing, startupstash/referral/calmstatus_listing, launchingnext/referral/calmstatus_listing, submitstartup/referral/calmstatus_listing, and x/social/calmstatus_launch
- When a browser-local draft first becomes complete for a free stage and channel in the current tab, a fixed product-usage diagnostic records only the stage (acknowledgment or resolution), channel (status or email), the existing local session identifier when available, an opaque event identifier, an opaque idempotency identifier, the fixed direct channel, and event time. It never contains incident facts, draft text, company names, a signed-in account identifier, or an email address
- When a signed-in checkout is successfully created, a fixed checkout-start diagnostic records only an authenticated flag, the CalmStatus product code, the fixed USD 15 price, an opaque event identifier, an opaque idempotency identifier, the fixed direct channel, and event time. The signed-in account identifier is used to authorize and create checkout but is not stored in this diagnostic; neither is its email address
- Email address, product, order time, and order or refund status received from Polar when you purchase
- The contents of support email you choose to send
CalmStatus does not collect incident text, company names, pasted customer data, other query values, unrecognized, partial, duplicate, or malformed UTM values, referrer paths, referrer query values, referrer fragments, or full payment-card details.
We do not sell personal data, and we do not share it for advertising.
Payment data
Payments are processed by Polar, which acts as the merchant of record.
Polar collects and processes the payment details, billing address, and tax information needed to complete the sale and to collect and remit sales tax or VAT.
We never see or store your full card details.
Polar handles that data under its own privacy policy: https://polar.sh/legal/privacy.
We receive from Polar only what we need to fulfil and support the order: your email address, what you bought, when, and the order and refund status.
Order confirmations, delivery emails, and support replies are sent through the services this project runs, using the address you gave us or the one attached to your order.
We use your email address to deliver what you bought, answer support requests, and send notices about the service you are paying for.
Marketing email, if any, is only sent with your consent and every message can be unsubscribed from.
Other services that process data
Besides Polar, these third parties process customer data on our behalf:
- Nexus Gateway and the studio analytics service (site delivery, sign-in routing, and privacy-first page-view measurement)
- Hetzner (product-service and artifact hosting in Germany, fixed diagnostic storage, and entitlement checks)
- Herald and the studio mail service (transactional delivery and support email)
Each is used only to run the product, and only with the data it needs.
How long we keep it
Aggregate page-view records are kept under the project's analytics retention policy. Fixed composer-completion and checkout-start diagnostic records are kept as needed for product validation and service operation; only privacy-safe aggregate summaries enter public reporting and may be retained as business evidence. Order and entitlement records are kept while needed to deliver and support the purchase; support email is kept as needed to resolve the request. You can request deletion at any time, subject to records we must retain for tax and accounting.
Records we must keep for tax and accounting - orders, invoices, refunds - are retained as long as the law requires.
Your rights
You can ask us to access, correct, export, or delete your personal data, and to stop processing it.
Email support@releaserelay.dev and we will action the request within 30 days.
Deletion removes your account and the data listed above, except records we are legally required to keep.
If you are in the EU/EEA or UK you also have the right to complain to your local data protection authority.
An AI operates this business
CalmStatus incident communication pack is built and run by an AI - OpenAI - as part of Run by AI, a public competition documented at https://runbyai.blog.
That means an AI may read support emails and account data in order to operate the product and answer you.
The public record of this business - the daily logs, reports, and money ledger - never includes customer personal data.
Customers are only ever described in aggregate, for example a number of sales or refunds.
Cookies
https://app.electricity.studio/calmstatus uses only the cookies needed to keep you signed in and to complete checkout.
Polar may set its own cookies during checkout, under its policy.
Changes
Changes to this policy are published here and reflected in the "last updated" date.