Privacy policy

How Standard Practice handles your information.

Effective September 24, 2026. Last updated September 24, 2026.

Standard Practice runs the AI Workplace Exposure Assessment at aiworkplaceexposure.com and the company website at standardpracticeus.com. This policy says what information we collect through them, what we do with it, who else sees it, and what you can ask of us. It is written to be read.

The short version: we collect what the assessment needs to produce your report, we never learn which employee gave which survey answer, we do not sell or advertise with anyone’s information, and everything stays in the United States.

  1. 01What we collect, and from whom

    Different parts of the service collect different things.

    • The assessment. The business details you enter (company name, website, industry, size, the states where people work, how the team works), your answers to the interview, and the name and email address you give us to receive your report or to set up the employee pulse. From these we generate your estimate, your report and your PDF, which we also store.
    • The employee pulse. Each employee’s answers to eight questions, and nothing else: no name, no email address, no IP address, no device details and no precise time. There is no way for us or for the employer to tell which employee answered what. Results are shown only as totals, and only once the minimum number of responses set for the pulse has been reached.
    • Policy documents. If you buy a written policy, the details you give us to prepare it (the person who will own the policy and their title, the tools you approve, the states you operate in, headcount) and the documents we deliver.
    • Payments. Stripe collects your card details on its own pages. We receive the outcome of the payment, the amount, Stripe’s reference numbers and the email address used, and we keep a record of the order. We never see or store your full card number.
    • The company website. What you type into the contact, partner and Employer Brief forms: your name, email address, company, headcount, states and message.
    • Technical records. Our hosting provider keeps standard server logs (IP address, browser type, pages requested, times) for a short period for security and troubleshooting. We do not use advertising cookies or analytics trackers. The only cookie we set is the sign-in cookie for our own staff’s administration area.
  2. 02What we use it for

    We use your information to run the service and for nothing unrelated to it.

    • To produce and deliver your estimate, your full report, your dashboard and any policy documents you buy.
    • To send the emails the service needs: your report link, receipts, notices that a pulse has closed, delivery of documents, and replies to your messages. If you sign up for the Employer Brief we send you that; ask us to stop at any time and we will.
    • To draft your business profile. We send the text of your public website and the business details you entered to Anthropic’s AI service, which returns a draft that you correct. For policy documents we send the details you gave us so that wording can be drafted for a partner to review. We do not send any employee’s survey answers to an AI service, and no AI service sets any score.
    • To improve the service, using totals and de-identified data that cannot identify your company or any person.
    • To keep the service secure, to prevent misuse, and to meet legal and accounting obligations.
  3. 03Who else sees it

    We do not sell personal information and we do not share it with advertisers. The companies that help us run the service see only what their job requires.

    • Fly.io hosts the application and its database on servers in Ashburn, Virginia.
    • Postmark delivers our email.
    • Stripe processes payments and holds the card details.
    • Anthropic provides the AI service described above and receives your website text and business details, not your employees’ answers.
    • We may also disclose information when the law requires it, to protect the rights and safety of employees, customers or the public, or as part of a sale or reorganisation of the business, in which case this policy continues to apply.
  4. 04If you answered an employee pulse

    Your employer sent you a link. Your answers are stored without anything that identifies you, and they are never shown to your employer or to us as individual answers, only as totals across everyone who responded, and only once enough people have responded that no one can be singled out. We do not record your IP address, your device or the time you answered. If you have a concern about how the pulse was presented to you, contact us through the form named below; we will not tell your employer that you did.

  5. 05How long we keep it

    We keep information for as long as the service needs it and then delete it.

    • Assessments, reports and pulse answers: while your report link is in use, and for up to three years after the last activity on it, unless you ask us to delete them sooner.
    • Messages sent through the company website: up to two years.
    • Orders and payment records: as long as accounting and tax law require. These are kept even if the assessment they belong to is deleted.
    • Server logs: a short period, measured in weeks.
  6. 06Your choices and rights

    You can ask us for a copy of the information we hold about you or your company, ask us to correct it, or ask us to delete it. Deleting an assessment deletes its report, its PDF and its pulse answers; order records stay as described above. We confirm requests through the email address on the assessment or message and answer within 45 days.

    Depending on where you live you may have further rights under state privacy law, including the right not to be treated differently for exercising them. Use the same form; we honour those rights for everyone, wherever they live.

  7. 07Security

    Every page is served over HTTPS. Reports, surveys and policy pages are reached through long, unguessable links rather than passwords; anyone who has your link can open your report, so keep it private and tell us if you think it has been shared. Our staff reach the administration area only through single-use sign-in links sent to approved addresses. No system is perfectly secure; if we learn of a breach affecting your information we will tell you.

  8. 08Where your information lives

    The service is operated from Georgia and hosted in Virginia. If you use it from outside the United States, your information is transferred to and processed in the United States.

  9. 09Children

    The service is for businesses and the people who run and work in them. It is not directed to anyone under 18 and we do not knowingly collect information from them.

  10. 10Changes to this policy

    When we change this policy we post the new version here with a new date. If a change matters to people who have an open report or an open order, we email the address on file.

  11. 11How to reach us

    Use the contact form at standardpracticeus.com/contact. Messages reach a person at Standard Practice, Georgia, USA.