How we handle the information you share.
What we collect
When you submit an application, we receive your answers to the screening questions and the contact details you provide (name, email, and an optional note). To prevent spam and abuse, our systems also automatically process your IP address — it is sent to our bot-protection provider (Cloudflare) to confirm you are human, and used briefly as a rate-limit key. These anti-abuse records expire automatically (typically within an hour). We do not use your IP address to identify you or for marketing.
The referral check
Applying requires a personal introduction. When you enter the name of the person who referred you (or who on our team reached out) and the short referral code they gave you, those two fields are sent over an encrypted (HTTPS) connection to our server and checked against an internal list of people who work with us. Referral codes change regularly. These two fields are used only to decide how your application is routed: they are never shown to other visitors and are not used for marketing. Submissions that do not pass this check are kept separately for security review and are not treated as applications. If your application proceeds, the same name and code are also included inside your encrypted application like your other answers.
How your data is protected
Your application answers and contact details are encrypted in your own browser, using public-key encryption, before they are sent. Our website and our queue provider only ever handle the encrypted package — they cannot read it. (The one exception is the referral check described above: the referrer name and referral code are checked by the server, in memory, to route your application.) It is decrypted and reviewed only on a separate, off-cloud computer we control. A breach of the website or the queue would expose only unreadable, encrypted data.
Where it goes
The encrypted submission is placed on a secure queue and retrieved by our off-cloud computer for review. We do not send your application by email, and we do not store readable applications on this website or in any cloud database. After you submit, you see an on-screen confirmation; we do not send an automated confirmation email.
The launch waitlist
If you join our launch waitlist, we collect the email address you provide. If you arrived through a referral link, the short referral code from that link is sealed inside the same encrypted package alongside your email — it identifies the person who introduced you, not you, and is used only to credit that introduction. It is all encrypted in your browser the same way and held briefly in our queue. We use your address to send our launch announcement and occasional product updates; every email we send includes an unsubscribe link, and you can also ask us to remove your address entirely at any time. We do not sell or share it.
Email, meetings & documents
Once we are in contact, our support and correspondence happen over email, and meetings happen over video call (currently Zoom). Documents — including any agreements — are sent as email attachments. Email between major providers is encrypted in transit, but it is not end-to-end encrypted the way our application form is, so please do not email us passwords, account credentials, or other sensitive information we have not asked for.
How long it is kept
Encrypted submissions stay on the queue only until our computer retrieves them (typically minutes). Retention of a reviewed application after that is governed by the operator's own policy. Anti-abuse (IP) records expire automatically. If you ask us to delete your information, we will do so within fourteen (14) days of your request.
Service providers we use
We do not sell or rent your information, and we do not share it with third parties for marketing. We rely on a few providers to run the site: Vercel (hosting and aggregate, privacy-friendly analytics), Cloudflare (the “Turnstile” anti-bot check on our forms, which processes your IP address and may set a short-lived cookie to verify you are human), and Upstash (the secure queue that briefly holds your encrypted submission). Each handles only limited technical data on our behalf, and never your application in readable form. Once we are corresponding with you directly, two more providers are involved: Microsoft (our email host) stores and transmits our email correspondence, including any documents we send you, and our video-meeting provider (currently Zoom) processes the usual participant data — name, email, connection information — when you join a meeting with us.
Identity verification
When you use a personal invitation, we process the email address you enter to check it against the intended recipient. WorkOS provides the hosted sign-in and verification service and processes your email address and authentication information. Our access records link the verified identity to the invitation. A short-lived functional cookie binds the verification to your browser for up to ten minutes; after successful verification, a separate functional access cookie lasts up to twelve hours. Access can be revoked before that cookie expires. We do not run Vercel Analytics or Speed Insights on these invitation and access pages.
Cookies & analytics
We use Vercel Analytics and Speed Insights to measure aggregate, privacy-friendly traffic and performance; they are configured for anonymized, aggregate data and do not use advertising or cross-site tracking. We do not run third-party advertising or marketing pixels, and we set no advertising, profiling, or cross-site tracking cookies. We set strictly functional cookies for site access and authentication, including the invitation-verification cookies described above. A site-access cookie records which referral opened the site for you and is kept for up to 180 days. A sign-in cookie holds your client portal session, is kept for 12 hours, and is cleared when you sign out. A short-lived security token from Cloudflare Turnstile may also be set when you reach a form, used solely for the bot check.
Do Not Track & cross-site tracking
We do not track you across other websites, and no third parties collect personal information about your activities across different websites over time through this site. Because there is no cross-site tracking to disable, the site behaves the same whether or not your browser sends a “Do Not Track” or Global Privacy Control signal.
Your rights
If you are a California resident (CCPA/CPRA) or located in the European Economic Area (GDPR), you have the right to request access to, correction of, or deletion of your information. To exercise any of these rights, email us at Support@eleventhhoursolutions.com.
Updates
If this policy changes materially, we post the updated version here and revise the effective date below. The version posted here is always the one that applies.
Data & Security
Your application and contact details are encrypted in your own browser — using public-key encryption — before they ever leave your device, and travel over a secure (HTTPS) connection. The website and our queue provider only ever handle the encrypted package; they cannot read it. It is decrypted and reviewed only on a separate, off-cloud computer we control. No method of transmission or storage is ever perfectly secure, but a breach of the site or the queue would expose only unreadable, encrypted data.
Encrypted submissions sit on the queue only until our computer retrieves them — typically minutes. Anti-abuse (IP) records expire automatically. If you ask us to delete your information, we do so within fourteen (14) days of your request.
Never — your details are not sold, rented, or shared for marketing. A few service providers (Vercel, Cloudflare, and Upstash) handle only limited technical data on our behalf to run the site, and never your application in readable form. Once we are in touch directly, Microsoft (our email host) carries our correspondence and any documents we send you, and Zoom handles our video meetings.
Email Support@eleventhhoursolutions.com any time — with a question or to have your information deleted. Email is the channel for privacy requests; we answer them ourselves.
Effective date: 2026-07-30 · Last updated: 2026-09-18