Privacy policy

Last updated 2 September 2026

What we collect, why we have it, and how to get rid of it.

The short version

Three places on this site keep what you type: the readiness check, joining Circle, and registering for a session. All of them want your email, most want your name, and the rest is optional. We keep it so we can talk to you about what you asked for. We do not sell it. There are no advertising trackers on this site. If you want all of it deleted, one email to egils@areteaios.com does it.

Who is responsible for your data

The controller is Full Digital, a registered association in Latvia, registration number 40008303188, registered on 18 December 2020. AreteAIOS is run by that association. The postal address is Priedaines iela 16, Ikšķile, Ogres novads, LV-5052, Latvia. The person you can always reach is Egils Boitmanis, at egils@areteaios.com. One person reads that inbox.

What you type into the readiness check

The form at /apply has five fields. Your name, first and last, required. Your email, required. A link to your LinkedIn page or your website, required. A short answer saying why you want to build a business brain, required. A tick box saying you agree to get emails about this cohort, required. We open the link you give us and read what is publicly there, so send us a page you are happy for us to look at.

The Nine questions at /start

If you answer the nine questions at /start, your answers and your first role are stored under a private address that only you have. To open the full plan you give a first name and an email and tick the same consent line as in Circle; that starts the same pending Circle registration as /join, and a Circle person is only created when you enter the code we email you. If you paste a website or LinkedIn link or write one sentence there, a person reads it; nothing fetches, rates or analyses it automatically.

What the form records without asking you to type it

When you press send, five more things are saved next to your answers. Your browser language. The page you came from, if you clicked a link to get here. And up to three campaign tags from the web address, which tell us whether an ad, a post or an email brought you. In the database they are called locale, referrer, utm_source, utm_medium and utm_campaign. Nothing else about your device is stored.

Circle, and registering for a session

Circle is separate from the readiness check. Joining Circle asks for your name and your email, and lets you add a link to your work and a short line about what you want to build. Those two are optional. Registering for a masterclass session asks only for your name and your email, and records which session it is, in which language, at what time. Both ask you to agree that we may hold your details and reach you about what you registered for, which is required, and both offer a separate tick box for occasional Circle updates, which is not.

Requests are held until you confirm the address

Sending either of those forms does not yet create anything in your name. It creates a short lived pending request, tied to the address you typed and to the browser you sent it from, which expires within the hour and is deleted. It becomes a real Circle record, a consent record and, for a session, a session registration only after you confirm that the address is yours by typing the six digit code we send to it. Until then it cannot touch anyone else's details, and if you never confirm, nothing of it remains. The reply on the page is the same whether or not an address is already known to Circle, and that sameness is on purpose, so the form cannot be used to find out whether an address is registered.

The access code

You ask for the code on the page and it lasts an hour. It stops working after five wrong tries, or the moment it is used. We do not store the code, only a fingerprint of it that cannot be turned back into the digits. The message carries the code and nothing else: no link, no joining address, nothing that works on its own. To stop someone hammering the form we also count requests for a short while, against fingerprints of your network address and of the email address you typed. The fingerprints are mixed with a secret before they are stored, so neither address can be read back from them.

The cookie behind an unfinished request

While a Circle or masterclass registration request is still unconfirmed, your browser holds a cookie called __Host-circle_claim. It is necessary: it carries an opaque random value that ties that one unfinished request to the same browser, so nobody else can confirm it from elsewhere and it cannot touch another person's details. It contains no name, no email and nothing else about you, scripts cannot read it, and it only travels over a secure connection. It lasts one hour at most, and the request it points to is deleted when the hour runs out or the address is confirmed. We keep only a fingerprint of the value on the server, never the value itself.

Your readiness result in My Circle

Your readiness result lives inside My Circle, the private area of this site, and there is no public or shareable link to it. My Circle opens with your email address and a one time six digit code we send to it, so only someone who can read that inbox can see the result. Inside you see your readiness score and the five layer breakdown, the answers you gave in the check, and a machine written reading of those answers. The contact details we hold for you are your name, your email and your phone number if you gave one. If you want it all gone, the Profile section of My Circle has a danger zone where you can delete your Circle yourself.

Your phone number

We ask for a phone number in one place only, on your result page after you finish the readiness check, and only so we can add you to the cohort WhatsApp group. Nothing is stored unless you tick the box. Other people in the group see the number, the same way you see theirs. Saying no changes nothing about your place, your emails or your result, and you can remove the number from the same page at any time.

What we collect if you pay

Payment runs through Stripe. You type your card details into Stripe's own form, not ours. Your card number never reaches this site and never reaches our database. When a payment finishes, our server receives the facts it needs to record the sale and to create and email your Full Digital invoice: the email you paid with, your name or your company name, the billing address, the business registration number if you filled that field in, the amount, the currency, the date, the ids Stripe gives the payment, and the card brand and last four digits when Stripe passes them. The durable order record we keep holds only the payment and order facts we need for our books, not every line of the invoice. Paying is not connected to Circle. No Circle account is required to pay, and a payment does not create one, does not change one and is not matched to one.

Cookies

Three cookies. The first is called __cf_bm. It comes from Cloudflare, the company that serves these pages, and its job is to tell real visitors apart from bots. It lasts about half an hour and scripts cannot read it. The second is called __dpl. This site sets it itself, it holds the id of the version of the site you were served, and it lasts a day. The third is called aa_consent. It stores the choice you made on the cookie banner, it lasts a year, and it is the reason we do not ask you again on every page. None of the three profiles you. If you press Accept, Google Analytics then sets cookies of its own, and those are described in the next section. Press Reject and it never runs, so those cookies are never set.

The Circle sign in cookie

If you sign in to Circle with a code, one more cookie appears, called __Host-circle_session. It is necessary: without it the page cannot tell that the person reading it is you. It holds a random value and nothing about you, scripts cannot read it, it only travels over a secure connection, and it stops working thirty days after you signed in, or the moment you press sign out. We keep only a fingerprint of it, so the value in your browser is the only copy.

What we measure

Two things count visits here, and only one of them is our choice. The first is built into the platform that hosts these pages. Lovable loads a small script called flock.js on every page and counts visits. It reads which page you opened, what kind of browser and device you are on, your browser language, and the page you came from if you clicked a link. It goes to an address on this same domain, not to an advertising network, it is not used to build a profile of you, and it is part of the hosting platform, so we cannot switch it off from inside the site. The second is Google Analytics, loaded through Google Tag Manager, and that one runs only if you press Accept on the cookie banner. Before you choose, no Google script is on the page at all and every Google consent setting is denied. Press Reject and it stays that way. The container id is GTM-MD3QFXGM and the Analytics property is G-0P3MCMD47W, so you can open your browser tools and check that this paragraph is true.

WhatsApp

There is a WhatsApp link on this site, in the footer, as a floating button and on the about page. It points at wa.me, which belongs to Meta, so when you click it Meta sees the request, including the usual things a web request carries: your IP address, your browser and the page you came from. The conversation after that happens inside WhatsApp, under Meta's own terms, not on this site. This site loads no Meta script and sends nothing to Meta unless you click that link.

Fonts

The type on this site comes from this site. The font files sit on our own server. Opening a page does not tell Google, or anyone else, that you were here. Until August 2026 the fonts were pulled from Google on every page, which meant Google saw your IP address before you had clicked anything or agreed to anything. That is fixed, and this paragraph stays here so you can see what changed.

Video

The short video on the front page sits on YouTube, but nothing from Google loads until you press play. There is no hidden player and no thumbnail pulled from a Google server. When you do press play, the video comes from youtube-nocookie.com, and from that moment Google knows you are watching it.

What is not on this site

No Facebook, LinkedIn or TikTok advertising pixel. No retargeting of any kind. No session recorder and no heatmaps. No profiling, and no automated decision that has any effect on you. Google Analytics is here, but only after you accept, and it is described above. Until 8 August 2026 this page said there was no analytics on the site at all. That stopped being true when the tags went in, and this sentence stays here so you can see what changed.

About email

Email is sent through Resend, a service that delivers mail for websites. When you send the readiness check form, one message goes out automatically to Egils saying that you applied; your result itself waits for you inside My Circle rather than arriving by email. Later messages about the cohort go to you on the same permission you ticked. Resend sees your email address and the message, and it keeps a delivery record so we can tell whether the message arrived. Every email we send you has an unsubscribe link at the bottom, and it works on the first click. Anything beyond those is written and sent by hand.

Circle email is different

After you send a Circle or session form, the next step on the page asks for a six digit access code for the address you typed, and the only Circle message that exists is that one time code. It is not a newsletter confirmation and it does not subscribe you to anything. Occasional Circle updates are a separate choice, controlled by the optional tick box on the form and by the same preference in your profile, and they stop the moment you take that back. If the mail service cannot deliver a message, the page still answers the same way, so a silent inbox never confirms or denies anything about an address.

Why we are allowed to hold this

The emails about the cohort rest on the permission you ticked, and you can take that back whenever you like. The rest of your answers we hold because you asked to be considered for a cohort, and we cannot consider you without them. Payment records we hold because a business has to keep a record of what it sold. The security cookie is there because a site has to be able to defend itself.

Who else can see it

Lovable, which hosts the site and holds the database. Supabase, the database engine behind Lovable Cloud. Cloudflare, which serves the pages and blocks bots. Resend, which delivers the emails. Google, through Analytics and Tag Manager, and only if you accepted cookies. Stripe, only if you pay. YouTube, only if you press play. Anthropic, which scores the three written answers in the readiness check and writes the reading of your answers that is stored on your result page: only the answers are sent, never your name, your email or your link, and data sent to the Anthropic API is not used to train their models. Meta Platforms Ireland, which runs WhatsApp, if you give us a number for the group or if you click the WhatsApp link. And Egils Boitmanis, who reads the inbox. Nobody else. We do not sell your details and we do not rent them out.

How long we keep it

If you apply and we do not end up working together, we keep your answers until you ask us to delete them, and one email is enough. Circle details follow the same rule: we hold them while the relationship is alive and we delete them when you ask. A registration request that is never confirmed expires within the hour and is deleted by a cleanup that runs shortly after that. Access codes die after an hour or five wrong tries. Sessions end after thirty days at the latest. The hashed identifiers behind rate limiting may stay up to 49 hours, because they are kept for 48 hours and removed by a cleanup that runs every hour. If you become a customer, the payment records stay as long as Latvian accounting law makes a business keep its books. If you ask us to delete everything, we do it, and we do not keep a quiet copy.

What you can ask us to do

You can ask for a copy of everything we hold about you. You can ask us to correct it. You can ask us to delete it. You can ask us to stop emailing you, and you can take back the permission you ticked at any time, which does not undo the emails already sent. You can ask for your answers in a file you can take elsewhere. One email to egils@areteaios.com starts any of these and you do not owe us a reason. We answer within one month. If you think we handled your data badly, you can complain to the supervisory authority in Latvia, Datu valsts inspekcija.

Changes to this page

When something on this site changes what we collect, this page changes first and the date at the top moves with it. We do not backdate it.