Privacy Policy
What we collect when you sign in, get in touch or contribute a radar result, why we collect it, and what we will never do with it.
Effective 13 August 2026
1. Overview
This policy explains how Foundational Intelligence™ Labs ("we", "us") handles personal information collected through fi-labs.ai (the "Site"). It covers the Site's contact forms, the private resource library at /resources, which uses Google Sign-In, and the self-assessment at /radar.
We are a small studio. We do not run advertising, we do not use analytics or tracking pixels, and we do not sell personal information to anyone, ever.
2. Information from Google Sign-In
Access to /resources is limited to invited people. To check whether you are on that list, we ask Google to confirm who you are. We request only the basic sign-in scopes — openid, email and profile — and from them we receive:
- Your email address — matched against our list of approved addresses. This is the only thing that decides whether you are let in.
- Your name — shown on the page so you can see which account you are signed in as, and recorded alongside sign-in events.
- Your profile picture — displayed in the page header while you are signed in. We do not copy or store the image; your browser loads it from Google directly.
What signing in does not give us. We never receive your Google password. We have no access to your Gmail, Drive, Calendar, Photos or contacts, and we cannot send anything or post anything on your behalf. The permission you grant is limited to confirming your identity, and you can revoke it at any time at myaccount.google.com/permissions.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
3. Other information you give us
- Contact and enquiry forms — the name, email address and message you type in, used to reply to you.
- Access requests — if you sign in with an address that is not on the approved list, you may ask for access. We record the email address Google verified, plus the name, organisation and reason you supply.
- Sign-in records — the date, time and email address of each successful sign-in, kept as a security and audit record.
Our hosting provider also keeps standard server logs, including IP addresses, for a short period for security and reliability. We do not use those logs to build any profile of you.
4. Radar self-assessment responses
The self-assessment at /radar runs entirely in your browser. Your answers are not sent anywhere while you take it, and if you close the tab they are gone.
When your profile is shown you may choose to add your scores to an anonymous record we keep. If you do, we receive your twelve scores, your second reading if you took it, and the date. If you arrived through a workshop link, we also record that workshop's label so the group's results can be read together.
We do not receive your name, your email address or your IP address, and the submission is not connected to your sign-in even if you are signed in to the resource library in the same browser. We use it to understand how these patterns distribute across leaders, and may describe those patterns in aggregate in workshops, writing and talks.
A submission cannot be withdrawn. Because it contains nothing that identifies you, we cannot find it again afterwards, and so we cannot retrieve, correct or delete an individual response on request. This is a consequence of it being genuinely anonymous rather than a limitation of our systems.
If you would rather not contribute, choose "No thanks" — your profile still appears in full and still saves as a PDF.
6. How we use your information
- To confirm your identity and decide whether you may access the library.
- To show you which account you are signed in as.
- To keep a security record of who signed in and when.
- To answer your enquiries and consider your access requests.
- To protect the Site against misuse, and to meet legal obligations.
7. Communications and marketing
If you are a member of the library or have contacted us, we may send you messages about the material you have access to and about related programmes, workshops and publications.
Consent, and how to withdraw it. Where the law requires your consent before we send promotional messages, we will ask for it separately and plainly — signing in with Google is not treated as agreement to receive marketing. Every promotional message carries an unsubscribe link, and you can opt out at any time by writing to privacy@fi-labs.ai. Opting out never affects your access to the library.
We will always send you messages that are necessary to operate the service — for example, telling you that access has been granted. These are not marketing and cannot be opted out of while you hold an account.
We do not sell, rent or trade your personal information, and we do not share it with third parties for their own marketing.
9. How long we keep it
- Session cookies — 7 days at most, less if you sign out.
- Approved-address list — for as long as you are a member, and until you ask to be removed.
- Sign-in records — 24 months, then deleted.
- Access requests and enquiries — for as long as needed to deal with them and keep a reasonable record.
- Radar responses — kept indefinitely as an anonymous dataset. There is nothing in them to expire.
10. Your rights
Depending on where you live, you may have the right to ask for a copy of the personal information we hold about you, to have it corrected or deleted, to object to or restrict how we use it, to receive it in a portable form, and to withdraw consent at any time. Residents of the EU, UK, California and several other jurisdictions have these rights by statute.
Write to privacy@fi-labs.ai and we will respond within the period the law allows. We will not treat you differently for exercising a right. You may also complain to your local data protection authority.
These rights apply to personal information — anything by which you can be identified. They cannot apply to an anonymous radar response, because there is nothing in one that would let us find yours; see section 4.
11. Security
The Site is served over HTTPS. Sign-in cookies are HttpOnly, signed, and scoped to this site. Library files are never public: they are released only after a valid session is confirmed on the server. Credentials for our service providers are held as encrypted environment variables and are not present in anything sent to your browser.
No system is perfectly secure, and we cannot guarantee absolute security. Tell us promptly if you believe your account has been misused.
12. International transfers
We operate from the United States, and our providers may process information there and elsewhere. Where information is transferred out of the EEA or the UK, we rely on the safeguards those providers put in place, including standard contractual clauses.
13. Children
The Site is intended for professional adults and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, contact us and we will delete it.
14. Changes to this policy
We may update this policy from time to time. The effective date at the top of the page shows when it last changed materially. Significant changes affecting how we use your information will be brought to your attention.
15. Contact
Questions about this policy, or about information we hold, go to privacy@fi-labs.ai, or use the contact form.
See also our Terms of Service.