Privacy Policy
Last updated: June 2026
1. Who we are
CMO Rulebook is a decision engine for marketing leaders. Questions about this policy: support@cmorulebook.com.
2. What data we collect
Application data: All inputs you enter into the CMO Rulebook application (KPIs, financial figures, business model selections, named sessions, your current work, company profile, action memory, outcomes and follow-ups, measurement coverage, saved scenarios, and Data Roadmap tracking) are stored in your browser's localStorage. By default this data stays on your device and is never transmitted to any server we operate.
Optional cloud backup (opt-in): If you choose to sign in to cloud backup, a copy of that same application data is stored in Cloudflare D1 so it survives clearing your browser and can be restored on another device. This is used solely for backup and cross-device continuity — never for profiling, advertising, or sale. The cloud copy is linked to your authenticated account, but we do not store your raw email address against it: the record is keyed by a one-way cryptographic hash (HMAC) of your verified email, so the stored key cannot be reversed to your address. Even when a cloud copy exists, your data may still be retained locally in your browser until you clear it. Cloud backup is entirely optional — the application works fully without signing in.
Authentication: Sign-in uses Cloudflare Access with email one-time-passcodes. Cloudflare verifies your email and issues a secure session cookie; we receive only a validated identity token for the duration of each request. We never see or store your passcode.
Access form data: If you submit the access request form on this website, we collect your name, work email address, and role. This is used solely to process your access request and communicate with you about the product.
3. How we use your data
We use your access form data only to process your request and send you your access details. We do not sell your data, share it with third parties for marketing purposes, or use it for automated profiling.
4. Cookies and tracking
The application uses localStorage (not cookies) to persist your session data and preferences locally in your browser. The marketing website does not use third-party analytics or advertising cookies. If you sign in to optional cloud backup, Cloudflare Access sets a secure, HTTP-only session cookie to keep you signed in; this cookie is used only for authentication.
5. Data retention
Application data in localStorage persists until you clear your browser storage or use the hard reset function within the app. If you have enabled cloud backup, your cloud copy in Cloudflare D1 is retained until you delete it — use "Delete cloud data" in the app's Workspace to permanently remove the cloud record (this does not erase your local copy). Access form data is retained only for as long as necessary to process your request.
6. Your rights (UK GDPR)
Under UK GDPR, you have the right to access, rectify, or erase personal data we hold about you. Application data stored on your device is fully under your control (clear it in your browser or use the in-app hard reset). For an optional cloud-backup copy, use "Delete cloud data" in the app's Workspace to permanently delete the Cloudflare D1 record linked to your account; signing out stops further syncing without deleting anything. For access form data, contact us at support@cmorulebook.com.
7. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top reflects the most recent revision.