Privacy Policy

Last updated: September 15, 2026

This policy describes what personal information AI Creators Roundtable ("we," "us," the "Roundtable") collects when you use aicreatorsroundtable.com and the membership it sells, why we collect it, where it is stored, and what you can do about it. It is written against how the site is actually built, not copied from a template. If something here stops matching how the site works, the date above changes.

The short version: we collect your email address when you ask us for something, your payment status (never your card) when you join, and your Discord account ID when you link it to your membership. We do not run advertising trackers, we do not sell or share your information for advertising, and there is no analytics script on the site.

1. Who we are

AI Creators Roundtable is a creator community operated from the United States by its founder, JayyRedd. The membership is delivered through a private Discord server, the free resources are delivered through this website, and public videos are published on YouTube. For anything in this policy, reach us through the channels on our Contact page.

2. What we collect, by what you do

Reading the site

You can read every public page, post, and brief without giving us anything. Our host, Cloudflare, processes your IP address, browser type, and the pages you request in order to serve the site and protect it from abuse. We do not add an analytics script of our own, so we do not build a profile of your visits, and we do not use advertising cookies.

Getting a free resource or joining the mailing list

When you enter your email address to unlock the Buy-Back Playbook, the Vault, or another free resource, we store:

  • your email address,
  • which part of the site you signed up from (for example "playbook" or "homepage"),
  • the country your request came from, as reported by Cloudflare's edge, and
  • when you first signed up and when you last did so.

We deliberately do not store your IP address or browser details alongside your subscription. The country is coarse and exists only so we can tell which resources are useful and where. The signup form also includes a hidden anti-spam field that real visitors never see or fill in.

Each new signup also triggers a one-time notification email to us through Web3Forms so the request actually reaches a person. Web3Forms receives your address for that delivery.

The list lives in a Cloudflare D1 database on our own account. If we start sending regular email to it, that will run through a mailing provider that handles unsubscribes, bounces, and complaints, and every message will carry an unsubscribe link.

Creating a free account

The Vault and other gated resources use a free account with a magic link instead of a password. When you sign in, we send a one-time link to your email address through Supabase, our authentication provider. Supabase stores your email address and the sign-in record. We keep no password because there isn't one.

On your first sign-in in a given browser, your email address is also copied into our own mailing-list table (above) so the list is ours and not locked inside a vendor. Your browser remembers that this copy has happened so it is not repeated.

Downloading gated files

Gated files are served from Cloudflare KV storage through a function that checks your signed-in session before releasing the file. That check sends your session token to our function; it is not stored beyond the request.

Becoming a paid member

Payments are handled entirely by Stripe. Card numbers are entered on Stripe's pages and never touch our servers. From Stripe we receive and store:

  • your Stripe customer ID and subscription ID,
  • the email address you used at checkout,
  • your plan (monthly or annual), and
  • your subscription status as Stripe reports it (active, past due, or canceled).

Stripe sends us webhook events when your subscription changes so that Discord access can be granted and, when a membership ends, removed. Stripe's own privacy policy governs what Stripe keeps.

Linking Discord

After checkout, you can link your Discord account so the paid role is applied automatically. That uses Discord's OAuth flow with two permissions: identify (your Discord user ID and username) and guilds.join (so we can add you to the server). We store your Discord user ID against your Stripe customer record, plus the time the link happened and whether the role is currently applied. That mapping is the only way a canceled membership can have its access revoked, which is why it exists. We do not store your Discord messages, friends, or other servers.

Everything you post inside the Discord server is governed by Discord's privacy policy and Discord's retention.

Contacting us

If you email us, we keep the email and our reply for as long as the conversation is useful, then delete it in the ordinary course of housekeeping.

3. Cookies and browser storage

We do not set tracking cookies. The site stores a small amount of information in your browser's local storage so it works the way you left it:

Key What it does Cleared by
acr-theme Remembers light or dark mode Clearing site data
acr-playbook-unlocked Remembers that you already unlocked a free resource so the form doesn't reappear Clearing site data
acr-mirrored-… Remembers that your account email has already been copied to our list Clearing site data
Supabase session Keeps you signed in to your free account Signing out, or clearing site data

None of this is read by anyone but this site, and none of it is sent to an advertising or analytics service.

4. Third parties who process your information

Service What they do for us What they receive
Cloudflare (Pages, Functions, D1, KV) Hosts the site, runs our signup and access functions, stores the mailing list, membership records, and gated files Request data needed to serve the site; the records described above
Stripe Processes membership payments and billing Your payment details, name, email, and billing address, under Stripe's policy
Supabase Magic-link sign-in for free accounts Your email address and sign-in events
Discord Hosts the member community; OAuth for linking Your Discord account; the identify and guilds.join grants
Web3Forms Emails us a notification when someone signs up Your email address, signup source, and country
YouTube (Google) Hosts our public videos, which we link to and may show thumbnails from Your interaction with YouTube, under Google's policy

We do not sell personal information and we do not share it with anyone for their own marketing. The services above act on our instructions to run the site and the membership.

5. Why we process it, and on what basis

For visitors in the UK, EU, or other places where a legal basis is required:

  • Delivering what you asked for (a free resource, a sign-in link, a paid membership, Discord access): performance of a contract or the steps you asked us to take before one.
  • Keeping the site running and safe (hosting logs, abuse protection, the anti-spam field): our legitimate interest in operating a working website.
  • Understanding which resources people want (signup source and country): our legitimate interest in publishing things people find useful. No profile is built about you.
  • Sending you email you signed up for: your consent, which you can withdraw with the unsubscribe link or by asking us.
  • Keeping billing records: legal obligation.

6. How long we keep it

Information Kept until
Mailing-list address You unsubscribe or ask us to delete it
Free-account email and sign-in record (Supabase) You ask us to delete the account
Membership record (Stripe IDs, plan, status, Discord ID) Your membership ends, plus the period required for tax and accounting records
Stripe billing history As Stripe and the law require
Contact emails Until the conversation is closed and routine cleanup removes it
Cloudflare request logs Cloudflare's standard retention, which is short and not under our control

7. Your choices and rights

Wherever you are, you can:

  • Unsubscribe from any email we send using the link in the message, or by asking us.
  • Sign out of your free account at any time; the session token is removed from your browser.
  • Unlink Discord by leaving the server; your membership record keeps only the ID needed to reconcile billing.
  • Cancel your membership through Stripe's customer portal linked from your receipt, or by asking us.

If you are in the UK or EU, you also have the right to access, correct, export, or delete your personal data, to restrict or object to certain processing, and to complain to your local data protection authority. If you are a California resident, you have the right to know what we collect, to delete it, to correct it, and to not be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined in California law, so there is nothing to opt out of.

To exercise any of these, contact us through the Contact page. We will verify the request against the email address on file and respond within 30 days, or tell you why we need longer.

8. Children

The site and the membership are for adults. You must be 18 or older to join, and we do not knowingly collect information from anyone under 18. If you believe a minor has given us information, contact us and we will delete it.

9. Security

The site is served over HTTPS. Signup and membership functions run on Cloudflare's edge on the same origin as the site, so there are no cross-origin credentials to leak. Card data never reaches us. Discord linking uses signed state tokens so a customer ID cannot be forged in a URL. Secrets are held in Cloudflare's environment, not in the code. No system is perfectly secure, and if we learn of a breach that affects you we will tell you.

10. Where your information lives

We are based in the United States and our providers store data in the United States and, in Cloudflare's case, at edge locations worldwide. If you are outside the US, your information is transferred there. Our providers rely on their own standard contractual protections for those transfers.

11. Changes to this policy

When this policy changes in a way that matters, we update the date at the top and say so in the community and on the blog. Continued use of the site after a change means the updated policy applies.

12. Contact

Questions, requests, or complaints about privacy: use the Contact page. Billing and refund questions go to the same place, and our Refund Policy and Terms of Service cover the rest.