Privacy policy
Last updated August 20, 2026
Suppose is a place to think things through, made by a small team that would rather earn trust than harvest data. This page explains what Mostly Magic, Inc. collects, why, and what we will never do with it.
Mostly Magic, Inc. (“Suppose,” “we,” “us,” or “our”) is a Delaware corporation. We operate Suppose at letssuppose.com: a hosted visual thinking space for Boards, optional live collaboration, and AI that proposes without deciding. This Privacy Policy covers the website, the product, and related emails that link here.
If you live in California or another U.S. state with a privacy law that applies to us, see State privacy rights below.
Personal information we collect
Information you provide
Account data. To create an account you give us a name, an email address, and a password. Signup is invite-only. Two-factor authentication is optional; a Business workspace may require it. We do not ask for a street address, phone number, government ID, Social Security number, or income.
You sign in with email and password. Optional Google or Apple sign-in exists in the product but is not currently offered. A small number of older accounts may still use a previously linked GitHub login. We do not offer GitHub for new accounts. If a sign-in provider is later turned on, or if an older linked login is still in use, we may store the name, email, and avatar that provider shares. We do not overwrite your local profile from provider data on later sign-ins.
Some Business workspaces can use work SSO through an identity provider that workspace configures. In that case the provider processes the sign-in.
Board content. Everything you put on a Board is stored so it can be saved, synced, and shared: nodes and notes, attachments, comments, reactions, Purpose, Pages, Inbox items, Projects, and version history. Boards live in Durable Object SQLite, with a D1 catalog and attachments in R2.
Communications. If you write to us, we keep what you send so we can reply. If you submit an Enterprise inquiry when that form is published, we collect the name, work email, company, and details you enter. Mention emails can include the comment text, node title, Board title, and author name. Invite emails include the inviter’s name and, for a Board invite, the Board title and role.
Preferences. Settings stores things you choose: mention and share email, lifecycle email, session-replay opt-out, theme, and similar product controls. Lifecycle email is an unchecked box at signup. You can turn it off in Settings.
We do not currently collect payment cards or charge for Suppose. If paid plans are turned on later, Stripe would process payments under stripe.com/privacy. We would then see billing contact and subscription status from Stripe, not your full card number.
Information from other sources
We combine account details with what service providers return while they do their job: Cloudflare for hosting and email, PostHog when analytics capture is enabled, and an AI or search provider when you use that feature. We do not buy personal information from data brokers or marketing partners.
Data about others. If you invite someone to Suppose or to a Board, we collect the email address you enter so we can deliver the invitation. Please do not invite someone unless you have their permission.
Information collected automatically
Technical logs. Like almost every web service, our servers see IP addresses and browser details. We use them for security, rate limiting, and debugging, and keep them only as long as those jobs need. We send PostHog bounded request-completion records containing a safe route template, method, status, duration, release, service, and opaque correlation IDs. They contain no request or response content. An authenticated request may carry our internal account ID for diagnosis; an anonymous request stays unlinked.
Product-improvement data. When analytics capture is enabled, we collect a small, content-free set of events about safe route groups, feature use, outcomes, performance, and errors. Capture is designed to stay off unless a production environment has the required PostHog token and host. We do not treat analytics as currently on just because the code exists. Events use opaque identifiers, safe route templates, counts, timing, feature names, and bounded outcomes. They do not include Board titles, node text, notes, comments, Purpose, Brief content, prompts, AI responses, filenames, attachments, invitation secrets, payment details, campaign parameters, or referrers. Marketing pages never build a person profile.
Session replay. During the U.S. invitation beta, an eligible authenticated account may have a private product session recorded under the rules below. Replay is gated. It stays off unless a U.S. request, an invited-beta account, a release flag, an eligible private surface, and no Settings opt-out all hold. We explain that program before invitation enrollment. Do not read this as a claim that replay is currently capturing.
For an eligible replay, all text, inputs, and images are masked before the recording leaves the browser. Board content, AI conversations, Pages, attachments, identity fields, and secret-bearing components are blocked. We never replay marketing, signup, sign-in, recovery, invitation acceptance, public-link, guest, shared or collaborative Board, payment, billing, admin, support, or other sensitive surfaces. We do not record full URLs or query strings, request or response bodies, network headers, clipboard content, canvas pixels, or console output. Replays help us see interaction problems without reading what you are thinking about.
Presence. While you are on a shared Board, your name, cursor, and selection are relayed live to the other people on that Board. That is the product working, not tracking. Presence is not stored once you leave.
The homepage playground. The live Map on our homepage runs in your browser. Edits stay in session storage. Nothing you type there is sent to our servers or saved as Board content, and we do not capture session replay on the marketing site.
Device storage. The product may keep first-party preferences on your device, such as theme, last workspace, a guest name on a shared Board, and a local replay opt-out latch. Marketing pages stay in light mode and do not store a theme.
Cookies and similar technologies
Suppose uses the cookie that keeps you signed in, plus other essential cookies needed to run and protect the site. Minimal PostHog measurement is designed to be cookieless: it does not set a PostHog cookie or keep a persistent anonymous analytics identity in browser storage. When capture is enabled, PostHog may transiently process an ingestion request IP with browser and host data to calculate a rotating anonymous hash, then discard the IP instead of storing or enriching it.
We do not use advertising cookies or build advertising audiences. We do not show a cookie banner or a generic PostHog privacy popup. See the Cookie notice for the short list of what we actually use.
How we use your personal information
We use personal information to:
- provide Suppose: accounts, Boards, sharing, export, and support;
- keep the service secure, including rate limits, abuse prevention, and optional two-factor authentication;
- send transactional email for verification, password reset, invitations, mentions, security, and material service notices;
- send optional lifecycle email only if you opt in at signup or later, and stop when you withdraw that choice;
- run AI features only when you ask or turn the companion on;
- understand product use, when analytics capture is enabled, without reading Board content;
- respond to your requests and inquiries;
- comply with law, enforce our terms, and protect Suppose, you, or others;
- create aggregated or de-identified statistics that no longer identify a person or reconstruct a Board.
AI features
Most AI on Suppose runs when you ask: expanding a branch, chatting about a Board, building a Board from your sources. Your request and the relevant parts of that Board are sent to a model provider solely to generate the response. The default text path uses OpenRouter (Luna or Sol, pinned to OpenAI). Depending on the feature and configuration, a request may also go to OpenAI, Anthropic, Groq, Cerebras, or Cloudflare Workers AI. Web research may use OpenAI Responses, OpenRouter, Tavily, or Brave. Transcription uses Whisper. Realtime voice is a labs feature and stays off until you turn it on.
One feature works alongside you: the companion. While it is on, it reviews your latest edits as you work, which can mean sending those parts of your Board to a model provider so it can prepare a suggestion. It runs only for you while you are editing, never for anonymous visitors. It only ever proposes. You can turn it off for any Board; it stays off until you turn it back on.
Whether AI runs on request or alongside you, nothing lands on a Board unless you apply it. We do not use your Boards to train models. We do not claim a contractual no-training clause with every provider. Providers receive your content to produce that response.
When analytics capture is enabled, PostHog may receive metadata-only AI observability: the feature used, model and provider, latency, token counts, a safe error category, and whether a proposal was accepted, dismissed, edited, or reverted. It does not receive prompts, model responses, reasoning, tool inputs or outputs, files, transcripts, or audio. PostHog may derive an estimated cost when it recognizes the model and provider.
Sharing and guests
Your Boards are private until you decide otherwise. Suppose is not a social network, and Boards are not public by default. Other people see what you share on a Board: collaborators you invite, roles you assign, or anyone with a link (and the password, if you set one). Visitors without accounts get a random guest name. We do not know who they are, and neither does anyone else on the Board.
How long we keep it
We keep account and Board data while your account exists and you have not asked us to delete it. Presence is not stored after you leave a Board. Homepage playground edits stay in the browser and go away when that session storage is cleared.
We keep session replays for 30 days when replay has run. We keep other identifiable analytics, error, log, survey, lifecycle, and metadata-only AI data only while it is needed for the purposes described here, and we review it for deletion at least quarterly. We may keep aggregate statistics longer when they no longer identify a person or reconstruct a Board. After an account deletion we may retain the minimum suppression record needed to honor an unsubscribe, bounce, or complaint.
How we share your personal information
We share personal information with:
- Service providers that run Suppose: Cloudflare (Workers, D1, Durable Objects, R2, Queues, Email, AI Gateway, and Workers AI), PostHog Cloud US for the bounded product-improvement uses described here when capture is enabled, and the AI and search providers named above when you use those features. They receive only what their specific job requires.
- People you share with on a Board, including comment and mention recipients. Mention emails can include comment text, node title, Board title, and author name.
- MCP hosts you choose, such as ChatGPT or Claude, when you connect them at letssuppose.com/mcp. Those hosts are not Suppose subprocessors. You authorize what they can see, and you can disconnect them in Settings.
- Stripe, only if we later turn on paid plans. Stripe would process payments under its own privacy policy.
- Professional advisors such as lawyers or accountants, when they need it to advise us.
- Authorities and others when we believe in good faith it is necessary to comply with law, protect rights or safety, or investigate abuse.
- A buyer or successor if Suppose is involved in a merger, investment, or sale of assets. We would require the recipient to honor this policy or give you notice.
We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not have advertising partners, marketing partners, or event co-sponsors. We do not operate public profile pages.
Your choices
You can review and update your name and email in Settings. You can export a Board as OPML or Markdown whenever you like. Printable PDF reports are also available.
There is no in-app account deletion button. Write to support@letssuppose.com and we will delete your account and its data, including linked PostHog events, recordings, survey responses, AI metadata, and lifecycle profiles, subject to the minimum suppression record above. We may need to verify that the request comes from the account holder.
You can turn replay off in Settings without losing the core product. You can decline lifecycle email at signup or withdraw it in Settings. Optional emails include an unsubscribe path. We honor bounces and complaints. We never put private Board content into lifecycle messages or targeting rules.
You can ask us to explain the personal information connected to your account, provide a copy, correct it, or delete it. Contact support@letssuppose.com. We will not treat you differently for making a privacy request.
For cookies and device storage, see the Cookie notice. You can block cookies in your browser. Signing out and clearing site data removes local preferences. The product needs the sign-in cookie to stay signed in.
Our analytics configuration honors Do Not Track. We do not run ads, so there is no separate advertising opt-out, industry opt-out list, or Global Privacy Control theater for sale or sharing. We simply do not sell or share.
If you do not provide the account details needed to create or use an account, we cannot provide the hosted product.
Other sites and services
Suppose may link to other sites, and you may connect MCP hosts or follow sources returned by web research. We do not control those services. Their privacy practices are their own. Marketing pages load the Fraunces typeface from Google Fonts, which means Google may see that request.
Security
We use technical and organizational safeguards designed to protect the personal information we collect, including encryption in transit. No internet service is perfectly secure, and we cannot guarantee that yours will never be accessed without authorization.
International data transfer
We are a U.S. company. Suppose runs on Cloudflare’s network. Your information may be processed in the United States and in other countries where Cloudflare or a provider you invoke operates. Those places may not have the same privacy laws as yours.
Children
Suppose is not directed at children under 13, and they may not use it. You must be at least 13. We do not sell or share personal information of anyone, including people under 16.
Changes
If this policy changes in a way that matters, we will say so plainly: here and, for significant changes, by email or in the product. The updated date at the top will change. Using Suppose after a change means the new policy applies to that later use.
How to contact us
Write to support@letssuppose.com. A person reads it. That is also the address for privacy and state-rights requests. We do not publish a street address or phone number for these requests.
State privacy rights
This section applies to residents of U.S. states whose privacy laws apply to us and grant the rights below. Not every right exists in every state. We may decline a request as the law allows, including when we cannot verify who you are.
Depending on where you live, you may be able to:
- ask what categories of personal information we collect, where they come from, why we use them, and whom we disclose them to;
- ask for a copy of the personal information we have collected about you;
- ask us to correct inaccurate personal information;
- ask us to delete personal information we have collected from you;
- appeal a denial of a valid request;
- use an authorized agent, if we can verify the agent’s authority.
Targeted advertising. We do not process personal information for targeted advertising.
Sale. We do not sell personal information within the meaning of state privacy laws.
Sharing for cross-context behavioral advertising. We do not share personal information for that purpose.
Profiling. We do not use personal information for profiling or automated decisions that produce significant legal or similarly significant effects, such as housing, employment, or lending decisions. AI on Suppose proposes Board edits. You decide whether to apply them.
Sensitive personal information. Account credentials and optional two-factor secrets are sensitive. Board content is whatever you choose to put there and may include sensitive details you type. We use that information to provide Suppose, not to infer characteristics about you for advertising or similar purposes.
Nondiscrimination. We will not deny the core product, charge a different price, or provide a different quality of service because you exercised a privacy right.
To make a request, email support@letssuppose.com. We typically verify by confirming control of the email address on the account. We do not offer a toll-free number or a webform. Because we do not sell or share, there is no “Do Not Sell or Share” link and no advertising use of a Global Privacy Control signal.
We do not attempt to reidentify de-identified information except to test whether our deidentification still works.
Categories we collect
The following describes our practices now and during the past 12 months. We do not sell or share any of these categories. Free-form Board content or a support message may include other details you choose to type.
| What we collect | CCPA category | Why | Who we disclose it to |
|---|---|---|---|
| Name, email, internal account ID | Identifiers | Create and run your account, send email you requested or opted into | Cloudflare; people you invite or mention; an identity provider if work SSO is used |
| Password and optional two-factor data | Account credentials (sensitive) | Sign-in and account security | Stored by us on Cloudflare; not sent to analytics or AI providers |
| Optional avatar from a linked sign-in provider | Identifiers; visual information | Show your account on Boards you share | Cloudflare; other people on those Boards |
| Board content, attachments, comments, Purpose, Pages, Inbox, Projects, history | User-generated content; may include sensitive details you type | Provide the product you asked for | Cloudflare; people you share with; AI or search providers when you use those features; MCP hosts you authorize |
| Invitee email addresses | Identifiers | Deliver invitations you send | Cloudflare Email |
| IP address, browser, and device details | Internet or network activity; identifiers | Security, rate limiting, debugging | Cloudflare; PostHog for bounded logs when capture is enabled |
| Content-free product events, eligible masked replays, metadata-only AI traces | Internet or network activity | Improve the product, when those programs are enabled | PostHog Cloud US |
| Support and inquiry messages | Identifiers; communications | Respond to you | Cloudflare Email |
| Lifecycle email choice | Inferences from preferences, not advertising profiles | Send or suppress optional product email | Cloudflare; PostHog if a lifecycle profile is later used |
California Shine the Light. We do not disclose personal information to third parties for their own direct marketing. If you are a California resident and want to confirm that, email support@letssuppose.com with the subject “Shine the Light Request,” your name, and a statement that you are a California resident.
Nevada. We do not sell personal information as Nevada law describes that term. Nevada residents may still email support@letssuppose.com to register a preference.