Privacy Policy
Version 2, published 2026-09-16. This is a permanent copy — its wording will not change.
| Version | Date | Key Updates |
|---|---|---|
| 1.0 | 01-Jan-2026 | Initial Release |
| 1.1 | 25-Jan-2026 | Enhanced Security Infrastructure & GDPR Opt-in Alignment |
| 2.0 | 16-Sep-2026 | PostHog and Google analytics, browser storage, session replay and consent disclosures |
1. Introduction
This policy explains how Hextra collects and uses information when you use our coaching platform, create an account, or visit our services.
2. Information Collection
To provide personalized coaching, we collect information through our intake process. This includes your professional background, personal assets and interests, availability, and contact information in your User Context File. We also process account and technical information to operate the Service. Collection can occur before sign-in or completion of intake.
Product analytics and session replay
We use PostHog to understand how people use the Service and to investigate technical problems. When analytics is active, collection includes:
- Before sign-in, a browser identifier that is not yet linked to a signed-in account, page views, clicks and other interactions, and device and browser information.
- Technical events, including API endpoint paths, response status codes, and trace identifiers used to investigate errors.
- Error reports, including exception types, messages, stack traces, and application version, to diagnose failures. We filter common identifiers and credentials from these reports, but error messages can still contain personal information.
- After sign-in, your user identifier (UUID), email address, and Partner identifier (UUID), which can associate activity with your account and Partner.
PostHog stores analytics identifiers in browser local storage. These identifiers and events should not be treated as anonymous merely because you have not signed in.
For selected authenticated users associated with a Partner, session replay captures page layout and interactions so that we can investigate how the Service behaves. Our integration masks text and inputs in recordings and excludes console logs, network request and response headers, and network bodies. It strips query strings and fragments from collected page URLs. Replay masking does not apply to analytics event text and attributes. These measures reduce exposure of personal information; they do not guarantee that every event or recording is free of personal information.
Google Analytics
We also use Google Analytics 4, and it behaves differently on our public website than in the application.
- On our public website it runs through Google Tag Manager with Google Consent Mode storage defaults set to denied. It therefore stores no cookie or other identifier in your browser and reports measurements that Google aggregates and models. It collects page addresses and titles, the pages you arrive from, interactions such as which buttons you select, and device and browser information. Your IP address reaches Google as part of each request.
- In the application it runs with Google’s default storage, which writes Google Analytics cookies to your browser. It collects the pages you open, their titles and addresses, and interactions such as which dashboard tab you view. After you sign in it also sends your user identifier (UUID) to Google as the analytics user identifier, together with whether you are signed in.
Cookies and consent
Authentication cookies (hx_access, hx_session, and hx_csrf) maintain your session and protect it from cross-site request forgery. We also store settings such as language preferences. Google Analytics writes its own cookies in the application, as described above. These functions are separate from optional product analytics and replay, including analytics that uses local storage rather than cookies.
Accepting the Terms of Service, acknowledging this policy, or signing in does not give separate consent to optional analytics or session replay. Where applicable law requires consent, we must obtain it before collection. Contact support@hextra.ai to ask about your rights or withdraw consent. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.
3. How We Use Your Information
We use the information in your User Context File to facilitate the Hextra User Journey and help you become a successful micro-entrepreneur. Specific uses include:
- Income Idea Generation: Analyzing your background to suggest personalized income streams.
- Service Refinement: Helping you focus ideas into specific, marketable niches.
- Action Plan Development: Generating comprehensive business plans covering pricing, marketing strategies, legal considerations, and client interaction protocols.
- Digital Identity (DI) Creation: Utilizing your data to build a transparent digital footprint that aids in your marketing, messaging, and service showcasing.
- Internal Improvement: Improving our AI models and coaching algorithms to provide better recommendations.
- Product Improvement and Troubleshooting: Using analytics and session replay to understand usage, identify failures, and improve the Service.
4. Data Sharing and Disclosure
We do not sell your personal data to third parties for marketing purposes. However, we may share your information in the following circumstances:
- Workforce Centers and Corporate Partners: If you are accessing Hextra through a workforce center or a corporate transition program, we may share progress reports or high-level data with those organizations as part of our service agreement with them.
- Cloud Infrastructure: We use Amazon Web Services (AWS) for data storage and processing.
- Product Analytics: PostHog processes analytics and session replay information on our behalf as a service provider. See PostHog’s privacy policy and data processing agreement for information about its processing terms.
- Website and Application Analytics: Google processes the measurement information described above through Google Analytics and Google Tag Manager. See Google’s privacy policy and how Google uses information from sites that use its services.
5. Data Security Standards
To protect personal information, we implement a management system aligned with ISO 27001:
- Encryption: All data is encrypted at rest (AES-256) and in transit (TLS 1.2+).
- Access Control: We enforce strict Identity and Access Management (IAM) and Multi-Factor Authentication (MFA) for all internal systems.
- Staff Readiness: All technical personnel complete mandatory security training annually to ensure a continuous culture of awareness.
6. Risk, Resilience & Rights
- Resilience: We conduct regular Risk Assessments, Disaster Recovery (DR), and Business Continuity (BCP) testing to ensure system integrity.
- Privacy Rights: Depending on the law that applies to you, you may have the right to:
- Access, rectify, or delete your personal information.
- Object to or restrict certain processing activities.
- Withdraw consent at any time.
7. Contact Us
For any questions regarding this policy or to exercise your data rights, please contact:
- Hextra Support Team: support@hextra.ai
- Website: https://hextra.ai