← Back to home
Legal · Last updated April 9, 2026

Privacy policy.

This Privacy Policy describes how Ruslan Galba, operating as Draft Protocol ("Company," "we," "us," or "our"), collects, uses, and protects your personal information when you visit draftprotocol.com (the "Site") or purchase our products. By using the Site or making a purchase, you consent to the practices described in this policy.

1. Information We Collect

1.1. Information You Provide

  • Email address — Collected when you make a purchase or sign up for the free framework download. Used to deliver your purchased materials and send transactional communications.
  • Payment information — Credit card details, billing address, and related payment data are collected and processed exclusively by Stripe. We do not store, access, or process your full credit card number on our servers.

1.2. Information Collected Automatically

  • Analytics data — We use PostHog to collect anonymized usage data including pages visited, referring URLs, browser type, device type, and approximate geographic location. This data helps us understand how visitors interact with the Site and improve the experience.
  • Cookies — PostHog may set cookies on your browser to track sessions and distinguish unique visitors. See Section 5 for details.

1.3. Information We Do Not Collect

We do not create user accounts or logins on the Site. We do not collect passwords, social security numbers, government-issued identification, or sensitive personal data categories as defined by applicable privacy regulations.

2. How We Use Your Information

We use the information we collect for the following purposes:

  • To deliver purchased digital products to your email address.
  • To process payments and prevent fraud (via Stripe).
  • To send transactional emails related to your purchase (delivery confirmation, refund communication).
  • To analyze Site usage and improve our products and user experience (via PostHog).
  • To respond to your inquiries or support requests.
  • To comply with legal obligations or enforce our Terms of Service.

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

3. Third-Party Services

We share limited information with the following third-party service providers, solely to operate the Site and fulfill purchases:

3.1. Stripe

Stripe processes all payments on our behalf. When you make a purchase, your payment information is transmitted directly to Stripe and is subject to their Privacy Policy. We receive only a confirmation of payment, your email address, and a truncated card identifier from Stripe.

3.2. PostHog

PostHog provides product analytics. It collects anonymized behavioral data about how visitors use the Site. PostHog's processing of this data is subject to their Privacy Policy.

3.3. Vercel

The Site is hosted on Vercel. Vercel may process server logs containing IP addresses and request metadata as part of its hosting services, subject to their Privacy Policy.

4. Data Retention

4.1. Email addresses associated with purchases are retained for the duration necessary to fulfill our contractual obligations (product delivery, refund processing) and comply with legal requirements such as tax record keeping. This is typically a minimum of three (3) years from the date of purchase.

4.2. Payment records are retained by Stripe in accordance with their data retention policies and applicable financial regulations.

4.3. Analytics data collected by PostHog is retained according to PostHog's data retention settings and policies.

5. Cookies

The Site uses cookies solely for analytics purposes via PostHog. These cookies help us understand visitor behavior by tracking session information and distinguishing unique visitors.

We do not use cookies for advertising, retargeting, or cross-site tracking. No third-party advertising cookies are present on the Site.

You may disable cookies through your browser settings. Disabling cookies will not affect your ability to purchase or access products, but may limit our ability to improve the Site experience.

6. Legal Basis for Processing (EEA/UK Users)

If you are located in the European Economic Area or United Kingdom, we process your personal data under the following legal bases as defined by the General Data Protection Regulation (GDPR):

  • Contract performance — Processing your email and payment information is necessary to fulfill our contractual obligation to deliver your purchased product.
  • Legitimate interest — We use anonymized analytics (PostHog) to improve our products and website experience. You may object to this processing at any time.
  • Legal obligation — We retain purchase records as required by applicable tax and financial regulations.

7. California Privacy Rights (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights:

  • Right to know — You may request disclosure of the categories and specific pieces of personal information we have collected about you.
  • Right to delete — You may request deletion of your personal information, subject to legal exceptions.
  • Right to non-discrimination — We will not discriminate against you for exercising your CCPA rights.
  • Do Not Track — The Site does not currently respond to Do Not Track (DNT) browser signals. You may opt out of analytics tracking by disabling cookies in your browser settings.

We do not sell personal information as defined by the CCPA.

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information:

  • Access — Request a copy of the personal data we hold about you.
  • Correction — Request correction of inaccurate personal data.
  • Deletion — Request deletion of your personal data, subject to legal retention requirements.
  • Portability — Request your data in a structured, machine-readable format.
  • Objection — Object to certain types of processing, such as analytics tracking.

To exercise any of these rights, contact us via @iamgalba on X. We will respond to verified requests within thirty (30) days.

9. Data Security

We implement reasonable administrative, technical, and physical safeguards to protect your personal information. Payment processing is handled entirely by Stripe, which is PCI DSS Level 1 certified. However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

10. Children's Privacy

The Site and our products are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected data from a child under 18, we will take steps to delete it promptly.

11. International Data Transfers

Your information may be transferred to and processed in the United States and other countries where our service providers operate. By using the Site or making a purchase, you consent to the transfer of your information to jurisdictions that may have different data protection laws than your country of residence.

12. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top will reflect the most recent revision. Material changes will be communicated via the email address associated with your purchase, where practicable. Continued use of the Site after any modification constitutes acceptance of the updated policy.

13. Contact

For questions, concerns, or data requests related to this Privacy Policy, contact Ruslan Galba via @iamgalba on X.