Privacy Policy

Effective July 23, 2026

Conifer LLC ("Conifer," "we," "us," or "our") operates the Conifer application and website (collectively, the "Service"). This Privacy Policy explains what personal information we collect, how we use it, with whom we share it, and what rights you have regarding your data. By using the Service, you agree to the practices described in this Policy.

This Policy applies to all users of the Service worldwide. If you are located in the European Economic Area (EEA), United Kingdom, or California, additional rights and disclosures apply. See Sections 12, 13, and 14 respectively.

1. Information We Collect

1.1 Information you provide directly:

  • Account registration data: your email address when you create an account. We use email-based login links, so we do not collect a password.
  • Profile information: the username you choose when setting up your account, which identifies you within the Service and attributes Matrices you share, plus any optional details you add to your profile, such as a display name.
  • User-generated content: word Matrices and other content you create or submit to the Service, including Matrices contributed to the public Library.
  • Communications: messages or inquiries you send to us via email or support channels.

1.2 Information collected automatically:

  • Usage data: pages visited, features used, session duration, clicks, and interactions within the Service.
  • Device and technical data: IP address, browser type, operating system, device identifiers, and referring URLs.
  • Log data: server logs recording how you access and use the Service.
  • Cookies and similar technologies: see Section 6 for details.

1.3 Payment information: We do not directly collect or store payment card information. All payment processing is handled by Stripe, Inc. Stripe may collect and store your billing name, card details, and billing address in accordance with its own Privacy Policy. We receive only limited transaction metadata from Stripe (e.g., subscription status, last-four card digits).

1.4 Information from third parties: We may receive information about you from third-party services you connect to the Service, or from analytics and marketing tools we use, as described in Section 5.

2. How We Use Your Information

We use the information we collect to:

  • Create and manage your account and provide the Service;
  • Process subscription payments through Stripe;
  • Personalize your experience and remember your preferences;
  • Analyze how users interact with the Service to improve performance and features (via PostHog);
  • Send transactional emails such as receipts, login links, and account notices;
  • Send marketing and promotional communications if you have opted in (via Flodesk), which you may opt out of at any time;
  • Respond to your support requests and inquiries;
  • Enforce our Terms & Conditions and protect the safety and security of the Service;
  • Comply with applicable legal obligations;
  • Conduct internal research and develop new features.

3. Legal Bases for Processing (EEA & UK Users)

If you are located in the EEA or UK, we process your personal data only where we have a lawful basis to do so:

  • Contract performance: processing necessary to provide the Service you signed up for (account management, payment processing, delivering features).
  • Legitimate interests: analytics, security, fraud prevention, and improving the Service, where those interests are not overridden by your rights.
  • Consent: marketing emails and non-essential cookies. You may withdraw consent at any time without affecting the lawfulness of prior processing.
  • Legal obligation: processing required to comply with applicable law.

4. How We Share Your Information

We do not sell your personal information. We share data only in the following circumstances:

4.1 Service providers: We share data with trusted third-party vendors who help us operate the Service, including:

We also use service providers for email delivery, application performance and error monitoring, and cloud hosting, storage, and backups. All of these providers are contractually bound to use your data only as directed by us and in accordance with this Policy.

4.2 Public Library content: Matrices you contribute to the public Conifer Library are visible to all users of the Service worldwide. Do not include personal information in Matrices you publish to the Library.

4.3 Legal requirements: We may disclose your information when required by law, court order, or government authority, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

4.4 Business transfers: If Conifer is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have.

4.5 With your consent: We may share information for any other purpose with your explicit consent.

5. Analytics

With your consent, we use PostHog to collect and analyze usage data so we can understand how users interact with the Service and improve it. PostHog may collect your IP address, device information, and behavioral data within the Service. This data is used only for internal analytics purposes and is not used to advertise to you. Analytics runs only after you accept analytics cookies. See Section 6.

Analytics may include session replay: a reconstruction of how you interact with pages (clicks, scrolling, and navigation). Anything you type into form fields is masked and not recorded, and we exclude email addresses from these recordings; content visible on your screen, such as matrices you view or edit, may appear in them.

PostHog offers an opt-out mechanism. For more information, visit posthog.com/privacy. You can also withdraw your consent at any time via cookie preferences. See Section 6.

6. Cookies & Tracking Technologies

The Service uses cookies and similar tracking technologies. Cookies are small data files stored on your device. We use:

  • Essential cookies: required for the Service to function (e.g., keeping you logged in). These cannot be disabled.
  • Analytics cookies: used by PostHog to collect usage data. You can opt out of these.
  • Payment cookies: set by Stripe to process transactions securely.

All visitors are presented with a cookie consent banner before any non-essential cookies are set, and analytics cookies are used only if you accept them. You can update your cookie preferences yourself at any time through the “Cookie preferences” link in the site footer or the Service's settings, or by deleting cookies in your browser.

Most browsers also allow you to refuse or delete cookies through browser settings, though doing so may affect your ability to use certain features of the Service.

Browser storage in the demo: If you try the Service without an account, the matrix you build is saved in your own browser’s local storage so it is still there when you come back. It is not sent to us and we cannot read it. Nothing about it leaves your device unless you choose to bring it into an account you create. Clearing your browsing data removes it.

7. Email Communications

7.1 Transactional emails: We send emails necessary to operate the Service, such as account confirmations, receipts, and login links. These are sent regardless of marketing preferences.

7.2 Marketing emails: With your consent, we may send newsletters, product updates, and promotional communications via Flodesk. You can opt out at any time by clicking "Unsubscribe" in any marketing email or by contacting us at support@conifermatrix.com.

We comply with applicable anti-spam laws, including the US CAN-SPAM Act and Canada's CASL.

8. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. When you close your account:

  • Your account data (name, email, preferences) will be deleted within 30 days of account closure, except where retention is required by law.
  • Matrices you contributed to the public Library remain in the Library per the Terms & Conditions (Section 9.2), as those become the property of Conifer upon publication.
  • Payment records may be retained for up to 7 years for tax and accounting compliance.

Residual copies of deleted data may persist in our routine encrypted backups for a limited period beyond the timeframes above, until those backups are cycled out.

We may retain anonymized or aggregated data (which cannot identify you) indefinitely for research and analytics purposes.

9. Data Security

We implement industry-standard technical and organizational measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction. These include encryption in transit (TLS), access controls, and regular security reviews.

No method of transmission over the internet is completely secure. While we strive to protect your data, we cannot guarantee absolute security. If you become aware of a security issue, please contact us promptly at support@conifermatrix.com.

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and relevant authorities as required by applicable law.

10. International Data Transfers

Conifer operates globally. Your personal information may be transferred to, stored, and processed in the United States and other countries where our service providers operate, including countries that may not provide the same level of data protection as your home country.

For transfers of personal data from the EEA or UK to countries not recognized as providing adequate protection, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission, or other lawful transfer mechanisms.

By using the Service, you acknowledge that your data may be transferred internationally as described in this Policy.

11. Children's Privacy

The Service is intended for users 13 years of age and older. We do not knowingly collect personal information from children under 13 without verifiable parental consent as required by the US Children's Online Privacy Protection Act (COPPA) and similar laws.

If we learn that we have collected personal information from a child under 13 without parental consent, we will delete that information promptly. If you believe we may have collected information from a child under 13, please contact us at support@conifermatrix.com.

Because the public Library contains user-generated content that may not be appropriate for all ages, we strongly recommend that parents and guardians supervise minor users' access to the Library. Conifer does not pre-screen Library content.

For users between 13 and 18, we recommend parental involvement. Some jurisdictions may require parental or guardian consent for users under 16. Please ensure compliance with the laws applicable in your jurisdiction.

12. Your Rights: EEA & UK Users (GDPR)

If you are located in the European Economic Area or the United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR) and UK GDPR:

  • Right of access: request a copy of the personal data we hold about you.
  • Right to rectification: request correction of inaccurate or incomplete data.
  • Right to erasure ("right to be forgotten"): request deletion of your personal data, subject to certain exceptions (e.g., legal obligations, Library content per Terms Section 9.2).
  • Right to restriction: request that we limit how we use your data in certain circumstances.
  • Right to data portability: receive your data in a structured, machine-readable format.
  • Right to object: object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent: where processing is based on consent, withdraw it at any time without affecting prior lawful processing.

To exercise any of these rights, contact us at support@conifermatrix.com. We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority.

EU Representative: As Conifer does not yet have an establishment in the EEA, [EU Representative details to be added prior to full launch, required under GDPR Article 27 if Conifer systematically processes EEA personal data].

13. Your Rights: California Users (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you the following rights:

  • Right to know: request disclosure of the categories and specific pieces of personal information we collect, use, disclose, and sell (we do not sell personal information).
  • Right to delete: request deletion of personal information we have collected, subject to certain exceptions.
  • Right to correct: request correction of inaccurate personal information.
  • Right to opt out of sale or sharing: we do not sell or share personal information for cross-context behavioral advertising.
  • Right to limit use of sensitive personal information: to the extent we collect sensitive personal information, you have the right to limit its use to what is necessary to provide the Service.
  • Right to non-discrimination: we will not discriminate against you for exercising your privacy rights.

To submit a request, contact us at support@conifermatrix.com. We will respond within 45 days. You may designate an authorized agent to make requests on your behalf.

14. Other Jurisdictions

Conifer is committed to complying with applicable privacy laws in all jurisdictions where we operate. If you are located outside the US, EEA, or UK and have questions about how your local privacy laws apply to your use of the Service, please contact us at support@conifermatrix.com.

Australian users: We comply with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs). You have the right to access and correct your personal information and to make a complaint to the Office of the Australian Information Commissioner (OAIC) if you believe we have breached your privacy.

15. Third-Party Links

The Service may contain links to third-party websites or services. This Privacy Policy does not apply to those third parties. We encourage you to review the privacy policies of any third-party site you visit.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by posting the updated Policy within the Service and, where required, by email. The "Effective Date" at the top of this Policy indicates when it was last revised. Your continued use of the Service after changes are posted constitutes acceptance of the updated Policy.

17. Contact Us

For questions, requests, or concerns about this Privacy Policy or our data practices, please contact:

Conifer LLC
support@conifermatrix.com

© 2026 Conifer LLC. All rights reserved. This Privacy Policy is preliminary and subject to revision by legal counsel.