Privacy Policy
What we collect, why, who we share it with, and your rights over it.
Mekable — operating https://baby-quest.com
| Version | 1.0.0 |
| Effective | August 3, 2026 |
1. The short version
We collect what we need to run a membership community and no more. We do not sell your personal information, we do not share it for advertising, and we do not run ad trackers.
The things worth knowing before you read the rest: your application is read by people outside our staff; parts of your profile are visible to other members; we use AI tools to help review submissions; and we keep records indefinitely unless you ask us to delete them, which you can do at any time by writing to support@baby-quest.com.
This summary is not the policy. The rest of the document is.
2. Who is responsible for your data
Mekable is the controller of the personal data described here. We decide what is collected and why.
Postal address: Mekable, 100 Ralston Road, San Gregorio, CA 94074, United States. Privacy contact: support@baby-quest.com.
We have not appointed a representative in the European Union or the United Kingdom. If you are in either and want to exercise a right or make a complaint, write to the address above — we handle these ourselves and we answer them.
3. What we collect
When you apply for membership
Your name, email address, company, LinkedIn URL, and the pitch you write about yourself and your work. We also record which guild you applied to and the status of your application.
The application form contains a hidden field that real people never see. If it is filled in, we treat the submission as automated and discard it. Nothing from a discarded submission is stored.
When you contact us or offer support
Through our contact, partner, sponsor, and in-kind service forms we collect your name, email, organization, and your message, plus, depending on the form, your role, phone number, the sponsorship tier you are interested in, your years of experience, the hours per week you can offer, and your areas of expertise.
When you have an account
Your name, email, the roles and guild affiliations we assign you, and authentication data. If you sign in with Google we receive your Google account identifier, email, whether that email is verified, and your name. We store the identifier, email, and name. We do not store your Google profile picture and we never receive your Google password.
If you set a password we store a salted hash of it, never the password itself, along with failed-attempt counts and lockout timestamps used to stop brute-force attacks.
Your profile
Whatever you choose to add: headline, biography, avatar image, company, job title, website, LinkedIn, X, the guilds you are interested in, and your visibility setting. If you opt in to text messages we store your phone number and a record of that consent — when you gave it and where.
Payments and donations
For dues we store your Stripe customer and subscription identifiers, the price you are on, your membership status, and your renewal date. For donations we store the amount, currency, donor name and email, and Stripe transaction identifiers.
We never receive or store your card number, expiry date, or security code. Card details go directly to Stripe and are handled entirely by Stripe.
What you post
Investor reviews (rating, written review, your stage at the time, and whether you asked to be anonymous), term sheets and documents you upload, event proposals, and any other content you submit. For anonymous reviews we still store the link between you and your review — see the Anonymity & Takedown Policy for exactly what that means.
Technical and legal records
When you agree to our Terms we record which version, when, in what context, and the IP address you did it from. We keep that because it is what makes the agreement provable, and we use it for nothing else.
We read your IP address to rate-limit form submissions and to block abusive traffic at our firewall. Rate-limiting does not store it. Our firewall logs it.
Our error-monitoring records diagnostic information when something breaks. It is configured to strip cookies, authorization headers, request bodies, and query strings before anything leaves our servers, and to redact anything shaped like an email address, phone number, or token. We do not record your screen.
What we do not collect
We do not collect government identifiers, health data, biometric data, precise geolocation, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, or trade-union membership. We have no reason to and we do not ask. If you volunteer any of it in free text, we would rather you did not.
4. Why we use it, and our legal basis
If you are in the European Economic Area or the United Kingdom, the GDPR requires us to have a legal basis for each use. This is ours.
| What we do | Why | Legal basis |
|---|---|---|
| Review your application and decide on it | To decide whether to offer you membership | Steps taken at your request before entering a contract; our legitimate interest in curating the community |
| Run your membership, take dues, give you access | To deliver what you signed up for | Performance of our contract with you |
| Process donations and issue receipts | To take the gift and acknowledge it | Performance of a contract; legal obligation for tax records |
| Answer your enquiry | Because you contacted us | Our legitimate interest in responding to people who write to us |
| Show your profile to other members | To make the community usable | Performance of our contract, subject to the visibility setting you control |
| Send you newsletters and event invitations | To tell you what is happening | Your consent where you subscribed; our legitimate interest in emailing our own members, and you can stop it at any time |
| Send you text messages | Urgent or time-sensitive announcements | Your consent, given separately and revocable by replying STOP |
| Keep "Baby Quest" secure and stop abuse | Rate limiting, firewall blocking, fraud prevention | Our legitimate interest in protecting the service and its members |
| Record your agreement to our Terms | To be able to show what you agreed to and when | Our legitimate interest in establishing and defending legal claims |
| Understand how the site is used | Product analytics | Your consent, given through the cookie banner |
| Comply with law and defend claims | Tax records, charitable reporting, litigation | Legal obligation; our legitimate interest in defending ourselves |
Where we rely on legitimate interests, we have weighed them against your rights and concluded they do not override yours. You can object — see section 11 — and we will stop unless we have compelling grounds to continue.
5. How we use AI
Our staff use third-party AI assistants to help review, summarize, and draft responses to applications, enquiries, and other submissions. Text you send us may be entered into those tools.
We use them under business or enterprise terms that prohibit the provider from training its models on our inputs, and we do not paste more than the task requires. We do not use AI tools that retain our submissions to improve a public model.
No decision about your application, your membership, or your content is made by a machine. A person makes every one of them. You are not subject to automated decision-making producing legal or similarly significant effects.
We do not train any model of our own on your content, and we do not license your content to anyone else for training.
6. What other people can see
Your application
Applications are read by our staff and, where relevant to the decision, by reviewers, mentors, partner organizations, and investors associated with "Baby Quest" who are not our employees. We share what is needed to evaluate you: your name, company, role, links, and your pitch. Say so in your application if there is something you do not want shown, and we will respect it or tell you we cannot proceed.
Your profile and the member directory
Members can find each other. Your profile has a visibility setting with three values — public (anyone on the internet), members (signed-in members only), and hidden (nobody but staff). You control it and you can change it at any time.
One exception you should know about: an avatar image you upload is stored at a public web address. Anyone who has that address can view the image, whether or not your profile is set to “members” or “hidden”. The address is not published or indexed, but it is not secret. Do not use an image you need to keep private.
What you post
Investor reviews and term sheets are visible to signed-in members of "Baby Quest". They are not public and we exclude them from search engines. Other members are bound by the confidentiality obligation in our Terms, but we cannot guarantee that every member will honor it. Post accordingly.
7. Who we share it with
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We disclose it to service providers who process it on our instructions, and only for the purposes below.
| Provider | What it does | What it receives |
|---|---|---|
| Google Cloud Platform | Hosting, database, file storage, CDN, firewall | All stored data; server and firewall logs |
| Sign in with Google | Authentication exchange only | |
| Stripe | Payments for dues and donations | Name, email, amount, and your payment details, which go to Stripe directly |
| Resend | Transactional email, receipts, newsletters | Name, email, and the content of the message |
| Attio | Our CRM and system of record | Name, email, job title. Never your phone number or SMS consent |
| Slack | Internal staff notifications of new submissions | Name, email, phone, and the message you sent |
| Circle | Community platform, currently being replaced | Name, email |
| Luma | Event listings and RSVPs | Whatever you give Luma when you RSVP. We do not send it your data, and we do not copy attendee lists back |
| Cal.com | Office-hours booking, embedded in the member area | Whatever you enter when booking. Loads only after you accept cookies |
| Sentry | Error monitoring | Scrubbed diagnostics. Cookies, bodies, and headers are stripped before sending |
| PostHog | Product analytics | Two events with no personal information. Loads only with your consent |
| Buffer | Publishing our own posts to social media | Our content only, never member data |
| Twilio | Text messages, not yet active | Phone number and message, only if you opt in |
| Anthropic / OpenAI | AI assistance for staff review and drafting | Text from submissions, under terms that forbid training on it |
We also disclose personal data:
- To reviewers and partners evaluating applications, as described in section 6.
- When the law requires it — a subpoena, court order, or valid legal demand. We tell you when we are permitted to, so you have the chance to object.
- To protect people — where we believe in good faith it is necessary to prevent serious harm, fraud, or a threat to someone’s safety.
- To our professional advisors — lawyers, accountants, auditors, under confidentiality.
- In a merger, acquisition, or wind-down — to a successor that takes on our activities. We will tell you, and the data stays subject to a policy at least as protective as this one.
8. Cookies and analytics
Strictly necessary
Two cookies are required for the site to work and are set without asking, because you cannot sign in without them:
| Cookie | Purpose | Lifetime |
|---|---|---|
| payload-token | Keeps you signed in | Expires after 2 hours |
| fg-oauth-state | Protects the Google sign-in flow against cross-site request forgery | 10 minutes, deleted as soon as sign-in completes |
Both are HttpOnly, meaning no script on the page can read them, and both are sent only over HTTPS in production.
Analytics and embedded services
Product analytics and the embedded booking calendar set their own cookies. Neither loads until you accept them in the cookie banner. If you decline, or ignore the banner, they never run, and the site works exactly the same.
Our analytics is configured not to record your screen, not to capture clicks automatically, and to strip names, emails, phone numbers, and addresses from anything it does send. It respects your browser’s Do Not Track setting, and we treat a Global Privacy Control signal as a refusal of consent.
You can change your mind at any time from the cookie settings link in the footer, or by clearing cookies in your browser.
9. International transfers
We are based in the United States and our infrastructure runs there. If you are outside the United States, using "Baby Quest" means your personal data is transferred there and to the other countries where our service providers operate.
The United States has not been found to provide a level of data protection equivalent to the European Economic Area or the United Kingdom in all respects. Where we transfer personal data out of those regions, we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, which our major providers — Google, Stripe, Sentry, Resend — incorporate into their terms with us.
You may ask us for details of the safeguards that apply to a particular transfer by writing to support@baby-quest.com.
10. How long we keep it
We keep records indefinitely unless you ask us to delete them. We do not run an automatic deletion schedule.
We are a small organization with a long memory, and institutional history has real value to us — knowing who applied three years ago and what they were building genuinely helps us serve the community. That is our legitimate interest, and we are telling you plainly rather than burying it.
The other side of that is a real deletion right. Ask us to erase your data and we will, within 30 days, whoever you are and wherever you live — you do not need to be in Europe or California to ask, and you do not need to give a reason. Write to support@baby-quest.com. This is not a formality; it is the thing that makes indefinite retention fair.
Some things we cannot delete on request, and you should know which:
- Donation and payment records. Tax and charitable-reporting law requires us to keep them. We keep them for as long as the law requires and no longer.
- Records needed for a live legal claim. If there is an active dispute or investigation, we keep what is relevant until it ends.
- Content others rely on. A published investor review may stay up with your authorship severed, so the record other members acted on is not silently rewritten.
- A suppression record. If you unsubscribe or ask us to delete you, we keep the minimum needed — usually a one-way hash of your email — so we do not contact you again by accident.
- Backups. Deleted data persists in encrypted backups for up to 35 days before those rotate out.
11. Your rights
Wherever you live, you may ask us to: give you a copy of your data; correct it; delete it; give it to you in a portable format; stop or limit a particular use; or object to a use based on our legitimate interests. Where we rely on your consent — analytics, texts, the newsletter — you may withdraw it at any time, and doing so does not affect what we did before.
How to ask: email support@baby-quest.com from the address on your account, or tell us enough to find you. We respond within 30 days. If a request is complicated we may take up to 60, and we will tell you why before the first 30 are up. It is free; we will only charge for a request that is manifestly excessive or repetitive, and we will tell you before we do.
We may need to verify your identity before we act, because handing your data to someone pretending to be you would be the worse failure. We will ask for the least we can get away with.
We will not retaliate for exercising a privacy right. Your membership, your dues, and your standing in "Baby Quest" are unaffected.
If you are in the EEA or UK you may complain to your local supervisory authority, and if you are in the UK that is the Information Commissioner’s Office. We would rather you came to us first, but it is your right and we will not think less of you for it.
12. United States state privacy rights
California, Colorado, Connecticut, Virginia, and a growing number of other states give residents specific rights. The rights in section 11 are offered to everyone, so you already have them. This section adds the disclosures those laws require.
In the twelve months before the date at the top of this page, we collected the categories of personal information described in section 3 — identifiers, commercial information, internet activity, professional and employment information, and audio or visual information from events — from you, from your browser, and from our service providers. We used it for the purposes in section 4 and disclosed it to the providers in section 7.
We have not sold personal information, and we have not shared it for cross-context behavioral advertising, in the preceding twelve months. We do not do either of these things, and we do not knowingly sell or share the personal information of anyone under 16.
We do not use or disclose sensitive personal information for any purpose beyond what is necessary to provide the service, so the right to limit its use does not arise. We do not use your data for profiling that produces legal or similarly significant effects.
You may use an authorized agent to make a request; we will ask for proof that you authorized them. If we refuse a request you may appeal by replying to our decision, and we will review it and answer within 45 days; if we still refuse, your state attorney general’s office can hear a complaint.
13. Security
Traffic is encrypted in transit with TLS. Data is encrypted at rest by our cloud provider. Passwords are salted and hashed, never stored in readable form. Session cookies cannot be read by scripts. Repeated failed sign-ins lock an account. A web application firewall sits in front of the site and rate-limits abusive traffic. Uploaded documents in restricted areas are access-checked when the file itself is served, not only when the page is rendered.
No system is perfectly secure and we will not pretend otherwise. If a breach affects your personal data and creates a real risk to you, we will tell you and the relevant regulator as quickly as the law requires and as clearly as we can.
14. Children
"Baby Quest" is for adults. You must be 18 or older to use it. We do not knowingly collect personal data from anyone under 18, and if we discover we have, we delete it. If you believe a child has given us information, write to support@baby-quest.com.
15. Changes to this policy
We will update this policy as what we do changes. The version and effective date are at the top, and the full history is public in our source repository.
If a change materially affects your rights or introduces a use you would not expect, we will tell you by email or in the product at least 30 days beforehand, and where the law requires your consent we will ask for it rather than assume it.
16. How to reach us
Privacy questions, data requests, and complaints: support@baby-quest.com
By post: Mekable, 100 Ralston Road, San Gregorio, CA 94074, United States
A real person reads that inbox. If you do not hear back within 30 days, write again and say it is a second request — something has gone wrong on our end.