Legal - Privacy policy

What the site and the private client area collect, who else sees it, and how long it is kept. It describes what they do today rather than what a template says they might.

Privacy policy · legal

Privacy policy

William Belle LLC · support@williambelle.co · Last updated August 15, 2026

This covers both williambelle.co and the private client area at portal.williambelle.co. One policy, because it is one business.

It describes what they do today. Where something is a deliberate limit, it says so.


Who I am

William Belle LLC, an Ohio limited liability company. I am Will Pickeral and I run it. Write to support@williambelle.co with anything on this page.

What I collect on williambelle.co

The contact form. Your name, your email address, and whatever you write in the box. Which service you clicked through from is recorded with it.

Most of the forms ask a few more questions, and one is worth naming: what kind of protected data your app handles — health records, financial records, legal records, or none of those. I ask because the answer changes what the work involves and what it costs, and it is better asked before a call than during one. Answer it or leave it blank. Some forms also ask for a link to your app.

None of that is a place for your own clients' records. Please do not paste records, account numbers, or credentials into the box.

Submissions go two places: to my inbox by email, and into the client area's database as an inquiry so I can follow it up without losing it in a thread.

Your IP address, briefly, to limit how many times the form can be submitted per minute. It is not stored.

Booking a call. The booking page shows a scheduler run by Cal.com. Your name, email, and anything you type into it go to Cal.com directly. That page is the only one on the site that loads anything from another company.

Nothing else. There is no analytics service on this site, no advertising, and no tracking script.

What I collect in the client area

The client area is invitation only. There is no sign-up page.

  • Your name and email address, because I was given them and added them.
  • Sign-in records: when a session started, when it was last used, and when it expires.
  • A record of activity: signing in, opening or downloading a document, accepting or declining a quote, sending a file in, and being refused something. Each entry carries who, when, and the address it came from.
  • Acceptance of a quote: the name typed on the form, the time, the address it came from, the browser it came from, and a fingerprint of the exact terms. That is the signature record, and it is what proves later what was agreed.
  • What you send in: source code archives, documents, and the note attached to them.
  • Reports on your app, if you are having it checked, including what it is running and what the checks found.

What I deliberately do not hold

Your project covers the infrastructure your app runs on, not the records inside it. Database exports are refused when you try to send one, by file type, including inside a compressed archive. The message says why.

That boundary is the point. It keeps your clients' records — patient records, tax records, client files — out of my systems entirely, so the obligations attached to them stay where they already sit.

Payment card details never reach either system. Invoices are paid on the payment provider's own pages.

No AI service processes any of this. Neither the site nor the client area sends anything to a language model or any other AI provider. Not your inquiry, not your documents, not your code.

Who else processes it

Company Where What it gets
Postmark Both Names, email addresses, and the contents of messages, quotes, and reports I send
Cal.com The booking page only Your name, email, and notes, entered directly into their scheduler
WorkOS Client area Your email address, name, IP address, browser, and sign-in events
Stripe Client area Your name and email as a billing contact, and invoice records
Microsoft Both Hosting, the database, document storage, and staff sign-in

Each of these is a company I pay to do one job. None of them is given your material to use for their own purposes, and none of them sells it.

WorkOS proves you can read your own inbox and tells me the address. Your documents never reach them.

Cookies

Neither site sets a tracking cookie, and there is nothing here to consent to or turn off.

The client area sets cookies that are required for it to work at all: one that keeps you signed in, and a short-lived one used during sign-in itself. Turning them off means you cannot sign in.

The scheduler on the booking page sets its own cookies, inside its own frame. Those are Cal.com's, governed by Cal.com's privacy policy.

How long I keep things

Inquiries from the contact form 24 months, then deleted, whether or not they became work
What your app reported to the checks 180 days
Documents you send in For the life of the project. Deleted copies are recoverable for 30 days
Findings, reports, and the activity record Kept, because they are the record of the work
Sign-in sessions About a month idle, never longer than three

The 24-month deletion runs on a schedule rather than when someone remembers. An inquiry that became a client is deleted on the same clock; what carries the relationship forward is the client record, not the form you first filled in.

What you can ask for

A copy of everything I hold about you, or its deletion. Write to support@williambelle.co. I will answer within thirty days, and usually the same week.

Deletion has one limit worth stating in advance: the activity record cannot be edited or deleted. The database refuses it, for every account including mine, and that is what makes the record worth anything to your compliance people. If you ask me to delete your data I will say plainly what remains and why.

A full export of every access to your material, for any period you name, at no charge. That export carries fingerprints your own people can check.

If you are in a state or country that gives you specific rights over your personal information, exercise them by writing to the same address. I do not sell personal information, and I do not share it for advertising.

Security

How access to your material is controlled is a document of its own: how access to your work is controlled. It names what has not been independently reviewed, as well as what has been built.

Children

Neither site is for children, and I do not knowingly collect anything about anyone under 18.

Changes

If this changes in a way that affects what I collect or who gets it, I will change the date at the top and email current clients. Ohio law governs it.

Questions go to support@williambelle.co. Questions from a client's IT or compliance people are answered directly.

Twenty minutes, and no pitch.

I'll tell you what I'd fix first in what you've built, and why. No pitch.