Privacy Policy
What we collect, why, and who can see it. The short version: your contact email is shared with an Organization only after you both match and the Organization unlocks you.
Last updated July 22, 2026.
This policy explains how Ichabod (“Ichabod”, “we”) handles personal information when you use the marketplace, this website, and our documentation. For the mechanics of retention and access controls, see also our Data Handling page.
What we collect
- Account data. Your signup email and, for Organizations, the declared Organization domain used for verification.
- Profile content. What you publish — for Seekers: name, tagline, website link, your experience, and your “what’s next” blob; for Organizations: name, description, website, and roles. Your contact email is stored but treated as restricted (see below).
- Marketplace activity. Interests, matches, unlocks, credit transactions, and rate-limit counters.
- Operational data. API-key metadata (such as last-used time), and standard request and telemetry events we use to run and improve the service. These telemetry events carry identifiers and scalar values only — never emails, names, or profile text.
- Payment data. Card details are handled by Stripe, not stored by us. We retain a reference to each transaction. During Early Access, payments run in Stripe’s sandbox, so no real card data is processed.
The two-email model
Your signup email is private. It is used for sign-in, receipts, and account recovery, and is never shown to a counterparty or exposed through MCP or the web. Your contact email is the address a counterparty reaches you at — and it is the one field that is gated. Setting or changing it sends a one-time confirmation link to that address before it takes effect.
When your contact email is shared
For Seekers, your contact email is disclosed to an Organization only after both of the following are true:
- You and the Organization have a mutual match on at least one role; and
- The Organization pays the one-time unlock for you.
After that, the unlock is permanent for that Organization. We do not separately notify you of an unlock — you experience it as inbound outreach. An Organization can always trace a Seeker through public channels; the unlock buys the in-band channel, not your identity.
Separately, your contact email is disclosed to another Seeker when the two of you form a mutual connection through peer networking — you each expressed interest and it was reciprocated. When that happens, Ichabod introduces you by email to each other’s contact addresses. This path is free and involves no unlock. It only ever happens for a peer you yourself signaled interest in: if you never express interest in another Seeker, your contact email is never shared this way. Withdrawing interest dissolves the connection going forward, but an introduction already emailed cannot be recalled.
What is public
Every Seeker has a public profile at the handle they choose, showing your name, tagline, website link, and experience — but never your contact email and never your “what’s next” blob, which stay off the public web. Roles Organizations post are public. If you do not want to be listed, edit your profile from your agent or delete your account from the account dashboard.
How we use information
- To operate the marketplace — matching, search, unlocks, and billing.
- To secure accounts, enforce rate limits, and prevent abuse.
- To send transactional email (welcome, receipts, payment failures, expiry notices).
- To measure and improve the service through aggregate telemetry.
We do not sell your personal information.
Service providers
We share data with the processors that run the service: Supabase (database and auth), Stripe (payments), Resend (transactional email), and Railway (hosting). Each processes data only to provide its service to us.
Cookies
Ichabod uses only strictly necessary cookies — the kind required to run the features you ask for. We set no advertising cookies and no cross-site trackers, and we do not currently use analytics cookies.
- Authentication. When you sign in, Supabase sets session cookies that keep you logged in. Without them you could not hold a session.
- Signup handoff. A single-use, short-lived cookie carries your newly created API key across the redirect to your account, then clears itself.
Because these cookies are essential to a service you have requested, they do not require a consent banner under EU/UK cookie rules. If we later add analytics or any non-essential cookies, we will update this policy and, where the law requires it, ask for your consent first.
Your choices and rights
- Edit your profile content at any time through MCP. Delete your account from the account dashboard — deletion removes your public listing.
- Rotate or revoke API keys from your account dashboard.
- Peer networking shares your contact email only with Seekers you expressed interest in who then reciprocated. To avoid that disclosure entirely, don’t express interest in other Seekers.
- Depending on where you live, you may have rights to access, correct, export, or delete your personal data. Email [email protected] to exercise them.
Retention
We keep account and marketplace records for as long as your account is active and as needed to operate the service, meet legal and tax obligations, and resolve disputes. Note that some records persist by design: an unlock and its associated contact disclosure survive role closure, a peer introduction already emailed cannot be un-sent, and transaction records are retained for accounting. See Data Handling for specifics.
Contact
Privacy questions or requests go to [email protected], or use our contact page.