Baby Quest

Privacy Policy

What we collect, why, who we share it with, and your rights over it.

Mekable — operating https://baby-quest.com

Version1.0.0
EffectiveAugust 3, 2026

1. The short version

We collect what we need to run a membership community and no more. We do not sell your personal information, we do not share it for advertising, and we do not run ad trackers.

The things worth knowing before you read the rest: your application is read by people outside our staff; parts of your profile are visible to other members; we use AI tools to help review submissions; and we keep records indefinitely unless you ask us to delete them, which you can do at any time by writing to support@baby-quest.com.

This summary is not the policy. The rest of the document is.

2. Who is responsible for your data

Mekable is the controller of the personal data described here. We decide what is collected and why.

Postal address: Mekable, 100 Ralston Road, San Gregorio, CA 94074, United States. Privacy contact: support@baby-quest.com.

We have not appointed a representative in the European Union or the United Kingdom. If you are in either and want to exercise a right or make a complaint, write to the address above — we handle these ourselves and we answer them.

3. What we collect

When you apply for membership

Your name, email address, company, LinkedIn URL, and the pitch you write about yourself and your work. We also record which guild you applied to and the status of your application.

The application form contains a hidden field that real people never see. If it is filled in, we treat the submission as automated and discard it. Nothing from a discarded submission is stored.

When you contact us or offer support

Through our contact, partner, sponsor, and in-kind service forms we collect your name, email, organization, and your message, plus, depending on the form, your role, phone number, the sponsorship tier you are interested in, your years of experience, the hours per week you can offer, and your areas of expertise.

When you have an account

Your name, email, the roles and guild affiliations we assign you, and authentication data. If you sign in with Google we receive your Google account identifier, email, whether that email is verified, and your name. We store the identifier, email, and name. We do not store your Google profile picture and we never receive your Google password.

If you set a password we store a salted hash of it, never the password itself, along with failed-attempt counts and lockout timestamps used to stop brute-force attacks.

Your profile

Whatever you choose to add: headline, biography, avatar image, company, job title, website, LinkedIn, X, the guilds you are interested in, and your visibility setting. If you opt in to text messages we store your phone number and a record of that consent — when you gave it and where.

Payments and donations

For dues we store your Stripe customer and subscription identifiers, the price you are on, your membership status, and your renewal date. For donations we store the amount, currency, donor name and email, and Stripe transaction identifiers.

We never receive or store your card number, expiry date, or security code. Card details go directly to Stripe and are handled entirely by Stripe.

What you post

Investor reviews (rating, written review, your stage at the time, and whether you asked to be anonymous), term sheets and documents you upload, event proposals, and any other content you submit. For anonymous reviews we still store the link between you and your review — see the Anonymity & Takedown Policy for exactly what that means.

Technical and legal records

When you agree to our Terms we record which version, when, in what context, and the IP address you did it from. We keep that because it is what makes the agreement provable, and we use it for nothing else.

We read your IP address to rate-limit form submissions and to block abusive traffic at our firewall. Rate-limiting does not store it. Our firewall logs it.

Our error-monitoring records diagnostic information when something breaks. It is configured to strip cookies, authorization headers, request bodies, and query strings before anything leaves our servers, and to redact anything shaped like an email address, phone number, or token. We do not record your screen.

What we do not collect

We do not collect government identifiers, health data, biometric data, precise geolocation, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, or trade-union membership. We have no reason to and we do not ask. If you volunteer any of it in free text, we would rather you did not.

4. Why we use it, and our legal basis

If you are in the European Economic Area or the United Kingdom, the GDPR requires us to have a legal basis for each use. This is ours.

What we doWhyLegal basis
Review your application and decide on itTo decide whether to offer you membershipSteps taken at your request before entering a contract; our legitimate interest in curating the community
Run your membership, take dues, give you accessTo deliver what you signed up forPerformance of our contract with you
Process donations and issue receiptsTo take the gift and acknowledge itPerformance of a contract; legal obligation for tax records
Answer your enquiryBecause you contacted usOur legitimate interest in responding to people who write to us
Show your profile to other membersTo make the community usablePerformance of our contract, subject to the visibility setting you control
Send you newsletters and event invitationsTo tell you what is happeningYour consent where you subscribed; our legitimate interest in emailing our own members, and you can stop it at any time
Send you text messagesUrgent or time-sensitive announcementsYour consent, given separately and revocable by replying STOP
Keep "Baby Quest" secure and stop abuseRate limiting, firewall blocking, fraud preventionOur legitimate interest in protecting the service and its members
Record your agreement to our TermsTo be able to show what you agreed to and whenOur legitimate interest in establishing and defending legal claims
Understand how the site is usedProduct analyticsYour consent, given through the cookie banner
Comply with law and defend claimsTax records, charitable reporting, litigationLegal obligation; our legitimate interest in defending ourselves

Where we rely on legitimate interests, we have weighed them against your rights and concluded they do not override yours. You can object — see section 11 — and we will stop unless we have compelling grounds to continue.

5. How we use AI

Our staff use third-party AI assistants to help review, summarize, and draft responses to applications, enquiries, and other submissions. Text you send us may be entered into those tools.

We use them under business or enterprise terms that prohibit the provider from training its models on our inputs, and we do not paste more than the task requires. We do not use AI tools that retain our submissions to improve a public model.

No decision about your application, your membership, or your content is made by a machine. A person makes every one of them. You are not subject to automated decision-making producing legal or similarly significant effects.

We do not train any model of our own on your content, and we do not license your content to anyone else for training.

6. What other people can see

Your application

Applications are read by our staff and, where relevant to the decision, by reviewers, mentors, partner organizations, and investors associated with "Baby Quest" who are not our employees. We share what is needed to evaluate you: your name, company, role, links, and your pitch. Say so in your application if there is something you do not want shown, and we will respect it or tell you we cannot proceed.

Your profile and the member directory

Members can find each other. Your profile has a visibility setting with three values — public (anyone on the internet), members (signed-in members only), and hidden (nobody but staff). You control it and you can change it at any time.

One exception you should know about: an avatar image you upload is stored at a public web address. Anyone who has that address can view the image, whether or not your profile is set to “members” or “hidden”. The address is not published or indexed, but it is not secret. Do not use an image you need to keep private.

What you post

Investor reviews and term sheets are visible to signed-in members of "Baby Quest". They are not public and we exclude them from search engines. Other members are bound by the confidentiality obligation in our Terms, but we cannot guarantee that every member will honor it. Post accordingly.

7. Who we share it with

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We disclose it to service providers who process it on our instructions, and only for the purposes below.

ProviderWhat it doesWhat it receives
Google Cloud PlatformHosting, database, file storage, CDN, firewallAll stored data; server and firewall logs
GoogleSign in with GoogleAuthentication exchange only
StripePayments for dues and donationsName, email, amount, and your payment details, which go to Stripe directly
ResendTransactional email, receipts, newslettersName, email, and the content of the message
AttioOur CRM and system of recordName, email, job title. Never your phone number or SMS consent
SlackInternal staff notifications of new submissionsName, email, phone, and the message you sent
CircleCommunity platform, currently being replacedName, email
LumaEvent listings and RSVPsWhatever you give Luma when you RSVP. We do not send it your data, and we do not copy attendee lists back
Cal.comOffice-hours booking, embedded in the member areaWhatever you enter when booking. Loads only after you accept cookies
SentryError monitoringScrubbed diagnostics. Cookies, bodies, and headers are stripped before sending
PostHogProduct analyticsTwo events with no personal information. Loads only with your consent
BufferPublishing our own posts to social mediaOur content only, never member data
TwilioText messages, not yet activePhone number and message, only if you opt in
Anthropic / OpenAIAI assistance for staff review and draftingText from submissions, under terms that forbid training on it

We also disclose personal data:

8. Cookies and analytics

Strictly necessary

Two cookies are required for the site to work and are set without asking, because you cannot sign in without them:

CookiePurposeLifetime
payload-tokenKeeps you signed inExpires after 2 hours
fg-oauth-stateProtects the Google sign-in flow against cross-site request forgery10 minutes, deleted as soon as sign-in completes

Both are HttpOnly, meaning no script on the page can read them, and both are sent only over HTTPS in production.

Analytics and embedded services

Product analytics and the embedded booking calendar set their own cookies. Neither loads until you accept them in the cookie banner. If you decline, or ignore the banner, they never run, and the site works exactly the same.

Our analytics is configured not to record your screen, not to capture clicks automatically, and to strip names, emails, phone numbers, and addresses from anything it does send. It respects your browser’s Do Not Track setting, and we treat a Global Privacy Control signal as a refusal of consent.

You can change your mind at any time from the cookie settings link in the footer, or by clearing cookies in your browser.

9. International transfers

We are based in the United States and our infrastructure runs there. If you are outside the United States, using "Baby Quest" means your personal data is transferred there and to the other countries where our service providers operate.

The United States has not been found to provide a level of data protection equivalent to the European Economic Area or the United Kingdom in all respects. Where we transfer personal data out of those regions, we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, which our major providers — Google, Stripe, Sentry, Resend — incorporate into their terms with us.

You may ask us for details of the safeguards that apply to a particular transfer by writing to support@baby-quest.com.

10. How long we keep it

We keep records indefinitely unless you ask us to delete them. We do not run an automatic deletion schedule.

We are a small organization with a long memory, and institutional history has real value to us — knowing who applied three years ago and what they were building genuinely helps us serve the community. That is our legitimate interest, and we are telling you plainly rather than burying it.

The other side of that is a real deletion right. Ask us to erase your data and we will, within 30 days, whoever you are and wherever you live — you do not need to be in Europe or California to ask, and you do not need to give a reason. Write to support@baby-quest.com. This is not a formality; it is the thing that makes indefinite retention fair.

Some things we cannot delete on request, and you should know which:

11. Your rights

Wherever you live, you may ask us to: give you a copy of your data; correct it; delete it; give it to you in a portable format; stop or limit a particular use; or object to a use based on our legitimate interests. Where we rely on your consent — analytics, texts, the newsletter — you may withdraw it at any time, and doing so does not affect what we did before.

How to ask: email support@baby-quest.com from the address on your account, or tell us enough to find you. We respond within 30 days. If a request is complicated we may take up to 60, and we will tell you why before the first 30 are up. It is free; we will only charge for a request that is manifestly excessive or repetitive, and we will tell you before we do.

We may need to verify your identity before we act, because handing your data to someone pretending to be you would be the worse failure. We will ask for the least we can get away with.

We will not retaliate for exercising a privacy right. Your membership, your dues, and your standing in "Baby Quest" are unaffected.

If you are in the EEA or UK you may complain to your local supervisory authority, and if you are in the UK that is the Information Commissioner’s Office. We would rather you came to us first, but it is your right and we will not think less of you for it.

12. United States state privacy rights

California, Colorado, Connecticut, Virginia, and a growing number of other states give residents specific rights. The rights in section 11 are offered to everyone, so you already have them. This section adds the disclosures those laws require.

In the twelve months before the date at the top of this page, we collected the categories of personal information described in section 3 — identifiers, commercial information, internet activity, professional and employment information, and audio or visual information from events — from you, from your browser, and from our service providers. We used it for the purposes in section 4 and disclosed it to the providers in section 7.

We have not sold personal information, and we have not shared it for cross-context behavioral advertising, in the preceding twelve months. We do not do either of these things, and we do not knowingly sell or share the personal information of anyone under 16.

We do not use or disclose sensitive personal information for any purpose beyond what is necessary to provide the service, so the right to limit its use does not arise. We do not use your data for profiling that produces legal or similarly significant effects.

You may use an authorized agent to make a request; we will ask for proof that you authorized them. If we refuse a request you may appeal by replying to our decision, and we will review it and answer within 45 days; if we still refuse, your state attorney general’s office can hear a complaint.

13. Security

Traffic is encrypted in transit with TLS. Data is encrypted at rest by our cloud provider. Passwords are salted and hashed, never stored in readable form. Session cookies cannot be read by scripts. Repeated failed sign-ins lock an account. A web application firewall sits in front of the site and rate-limits abusive traffic. Uploaded documents in restricted areas are access-checked when the file itself is served, not only when the page is rendered.

No system is perfectly secure and we will not pretend otherwise. If a breach affects your personal data and creates a real risk to you, we will tell you and the relevant regulator as quickly as the law requires and as clearly as we can.

14. Children

"Baby Quest" is for adults. You must be 18 or older to use it. We do not knowingly collect personal data from anyone under 18, and if we discover we have, we delete it. If you believe a child has given us information, write to support@baby-quest.com.

15. Changes to this policy

We will update this policy as what we do changes. The version and effective date are at the top, and the full history is public in our source repository.

If a change materially affects your rights or introduces a use you would not expect, we will tell you by email or in the product at least 30 days beforehand, and where the law requires your consent we will ask for it rather than assume it.

16. How to reach us

Privacy questions, data requests, and complaints: support@baby-quest.com

By post: Mekable, 100 Ralston Road, San Gregorio, CA 94074, United States

A real person reads that inbox. If you do not hear back within 30 days, write again and say it is a second request — something has gone wrong on our end.