Last updated · October 9, 2026
Portal privacy
This notice describes how Hatching Point LLC handles information in the Hatching Point portal at app.hatchingpoint.com. It covers applications to join, the portal, the Hatch member workspace in our mobile app, and connected studio support. Other products have their own notices.
Information we use
When you sign in with Google, we receive your verified email address and Google account identifier. We use these to recognize your account and check the access granted to you. This sign-in requests identity and email access only; it does not request access to Gmail messages, Google Drive files, contacts, or calendars.
Portal records may include your name, role, project associations, agreement drafts and revisions, private agreement PDFs submitted for review, responses to those drafts, source-document fingerprints, statement and Mercury cash review references, and ledger activity. A provider statement file selected for hash comparison stays on your computer; the portal sends its fingerprint, not the file. If electronic signing is enabled, we will also record the exact PDF fingerprint, your typed signature, verified account identity and email, consent version, signing time, and the resulting execution record. We record who makes supported changes and when. Records may include sandbox entries and actual financial records; their displayed status determines whether funds are available.
How information is used and shared
We use this information to authenticate users, enforce access permissions, display project and ledger records, maintain change history, and operate and support the portal. Authorized studio administrators can view financial records across portal members; Hatchers can view the records permitted for their own account.
Google provides optional Google sign-in. Resend delivers email sign-in links. Vercel hosts the portal, and Railway hosts the cloud API and PostgreSQL database. These providers process information needed to deliver their services, including technical information such as IP addresses and request metadata. Information may be processed outside your country.
Where enabled, Mercury provides recipient setup and payment services. Bank details entered on Mercury are handled by Mercury; we retain recipient references, status, transaction and reconciliation records needed to manage earnings and payment requests. A request does not itself guarantee a payment. We do not sell portal personal information or use Google sign-in data for advertising.
If you connect Discord, we use your Discord identifier to link access and project discussions. Hatch is an AI assistant. Questions and relevant, permission-checked discussion or project context may be sent to OpenAI to answer you; support questions, answers and tool activity are recorded. Do not submit passwords, bank details or sensitive personal information in chat. Configured studio channels may also be processed for project intake and summaries. Referrals record who introduced an applicant and allow the referrer to see limited referral progress.
In the Hatch mobile app, visitor profiles and unfinished drafts are stored on your device. Submitted applications, ideas and support feedback are sent to the studio; legacy submission and catalog services use Convex. Member sign-in stores its session credential in your device Keychain. Optional product analytics uses PostHog for bounded feature and reliability events, without your submitted content. Apple handles App Store purchases. Advertising measurement through Meta or TikTok is separate and subject to Apple tracking permission. You can change optional usage sharing in Privacy choices.
Cookies and security
The portal uses essential cookies to complete sign-in and maintain a session. Production session cookies use HTTPS, are inaccessible to browser scripts, and last up to 30 days. Sessions expire after 7 days without activity, and sensitive actions require a recent sign-in. Signing out revokes the current server session and clears its cookie. Sign-in & devices lets you revoke other sessions or sign out everywhere. We store session-token hashes, browser descriptions, sign-in and activity times, and account-security events. Email links expire in 15 minutes and work once. Rate-limit records use hashed email and network identifiers. The web portal does not use marketing pixels or session replay. Optional native product analytics requires a separate usage-sharing choice; it does not include application text, agreement contents, bank details, or support conversations.
We use access controls and encrypted connections to protect information. No service can guarantee absolute security. Contact us if you believe your account has been accessed without authorization.
Retention and your choices
We retain account and project records while needed to operate the portal and maintain an accurate history. Agreement and ledger history is designed to be append-only. Some records may need to be retained to meet legal obligations or resolve disputes, even if access is closed. We have not yet established a fixed retention schedule.
You can disconnect Hatching Point in your Google Account's third-party connections settings. Disconnecting Google does not itself delete portal records. Contact us to request access to, correction of, or deletion of your personal information, or to close portal access. We will assess requests subject to applicable obligations; historical accounting records may require a correction entry instead of deletion.
Children
Hatch is a studio collaboration service, not a service intended for children under 13. If you believe a child has submitted personal information, contact us so we can review and remove it where appropriate. Do not send additional personal information about a child in a public discussion.
Service providers · Copyright concerns
Contact and updates
Contact Hatching Point LLC at numbercutter@protonmail.com about portal privacy. Updates to this notice will be posted here with an updated date.