Privacy
Last updated September 28, 2026
This describes what elonpope.com actually does, checked against the source code rather than adapted from a template. Where the site does not do something, it does not claim to.
Who this covers
elonpope.com, operated by Elon Pope trading as Project EP. It applies to anyone who visits the site, runs the audit, asks for its report, books a call, buys the Finish It kit or buys a build, or signs up for The Weekly Wire.
What is collected, and when
The audit's Google lookup. When you type your business name and start, the name goes through this site to Google's business listings (the Places API) as one search. To find the right listing, the search is centred on where your connection appears to be: a city-level estimate that the site's host, Vercel, makes from your IP address. Google receives that estimate with the name. If you add a city, the city is used instead. What Google sends back (the listing, its rating, review count and website) is shown to you and is not stored.
The speed test. Your website's address, from your listing or as you typed it, goes to Google's PageSpeed Insights, which loads the site on a simulated phone and returns a score.
Your answers stay on the page. They are not sent anywhere unless you ask for the report.
Asking for your report sends your name and email, the business name you typed, your website address, your answers, the audit's results and the ID Google uses for your listing. They are stored so the report can be sent and so I can follow up. Your listing's rating, review count and address are not stored.
The Weekly Wire signup stores the email address you submit from the footer as a separate newsletter opt-in. It does not use audit answers or add audit-report recipients to the newsletter. A one-way hash of your connection address is counted to limit abuse, but is not linked to the signup row.
Booking a call happens in a Cal.com calendar, shown at the end of the audit to businesses it fits, or on Cal.com itself.
Buying the Finish It kit happens on Stripe's checkout page too. When Stripe sends you back to this site, the site reads that checkout from Stripe to confirm you paid: whether it is paid, the amount, and the email and name Stripe collected, which fill in where your plan goes.
The kit's questions and plan. Your answers go to this site's server when you ask for your plan. To write it, your project answers go to Google's Gemini: never your name or email, and with any email addresses, phone numbers and links taken out first. This site uses Gemini's free tier, on which Google may use what it receives to improve its products and people at Google may read it, so do not put anything private in your answers. If Gemini is not used, the plan is built from a fixed template instead, and nothing goes to Google. Your name, email, answers, the plan, whether it was emailed and the Stripe checkout's ID are stored so the plan can be sent, shown again and matched to a later build.
Your plan's address works like a receipt: anyone with it can see your plan, so keep it to yourself.
Buying a build. If you choose to buy through a Stripe link, Stripe collects your payment details, email and billing address to work out sales tax, and shares the purchase with me so I can send your statement of work. This site never sees your card details.
This site itself never asks for a password or a card number, and there is no account to create.
Browser storage
The site sets no cookies of its own and keeps nothing in your browser's storage, so there is no cookie banner: there is nothing of its own to consent to.
Earlier versions of the audit kept answers in local storage, under ep-audit-progress-v1 (which could hold a name, email and phone) and ep-audit-progress-v2 (answers only). The homepage deletes both from your browser the next time you open it.
The Cal.com calendar and Stripe's checkout page are run by those companies and set their own cookies when you load them. Clearing site data in your browser removes all of this.
Your IP address
To stop the Google lookup and the report being abused, the number of uses from one connection is counted. Your IP address is put through a one-way SHA-256 hash and only that hash is stored, alongside a count and a date. The speed test keeps its count in memory for an hour and stores nothing. The address itself is never written down, and the hash is not linked to your name, email or answers.
The city-level estimate used to centre the Google search is not stored.
Analytics
Vercel Analytics counts page views and a few named steps: starting the audit, whether the Google lookup found a listing, finishing it (whether a call was offered and whether the report went out), viewing a package, following a kit checkout link, and opening the calendar in a new tab. It never receives your business name, your website, your answers or your contact details. It is cookieless, it does not build a profile of you, and it does not follow you to other sites.
If your browser sends Global Privacy Control or Do Not Track, nothing is counted at all, page views included. No other analytics or advertising service is used.
What it is used for
To show you your audit, to send your report and follow up if you ask for it, to record your separate newsletter subscription, to deliver your build if you buy one, and to improve the site. Your details are not sold, and they are not passed to anyone for their own marketing.
Asking for your report sends you one email with it, from this site through Resend, and emails me a notification with what you sent. It does not add you to a newsletter or to any automated sequence.
Signing up for The Weekly Wire in the footer is a separate opt-in for a free weekly email. The signup stores your address but sends no confirmation email; to leave the list before an issue arrives, email me using the address in the footer. Future issues will need an unsubscribe option.
Buying the Finish It kit sends you one email with your plan, from this site through Resend.
Buying a build means I email you your statement of work and your start date.
If you finished the previous version of the audit before September 26, 2026, you may be in the short follow-up sequence it started. Every message in it carries an unsubscribe link, and using it stops the sequence immediately with no login or confirmation step.
If you asked for the guide PDF before that form was retired, your email address is on a Buttondown list. The form is closed. To be removed, use the unsubscribe link in any email from that list, or ask me.
Who processes it
- Vercel, site hosting, error logs and analytics.
- Google, the audit's business lookup (the Places API) and its speed test (PageSpeed Insights), which receive the business name you typed, an approximate location or the city you typed, and your website's address; and Gemini, which writes the kit's plan from your project answers, as described above.
- Supabase, the database that holds the audits people asked to have sent, and the functions that send notification email.
- Resend, delivery of the report email, the kit's plan email, the notification emails and the older follow-up sequence.
- Cal.com, the booking calendar at the end of the audit. If you use it, they receive what you enter into it.
- Stripe, payments for the kit and any build bought through a Stripe link. They receive what you enter on their checkout page, and the site reads a kit checkout back from them to confirm it was paid.
- Buttondown, the list behind the retired guide PDF. They hold the email addresses given on that form.
Each of these handles data under its own privacy terms.
How long it is kept
Plainly: there is no automatic deletion. Audits people asked to have sent stay in the database until they are deleted by hand, which means until you ask. Rather than quote a retention period the code does not enforce, this page says what is true.
Asking for your data, or its removal
Email founder@elonpope.com and ask what is held about you, ask for it to be corrected, or ask for it to be deleted. Deletion is done by hand, and you get a reply confirming it. There is no form to fill in and no account to close.
Security, stated honestly
Data is held in a hosted database that is not reachable from the browser: every write goes through a server route holding a key that is never sent to your device, and the public key granted to the browser cannot read the table at all. Traffic to the site uses HTTPS.
What this page will not tell you is that your data is encrypted in a particular way or held to a particular standard, because those are properties of the providers above rather than promises this site is in a position to make.
Changes
This page changes when the site does. The date at the top is the last time it was checked against the code.