AI Transparency
Â
How The Lighthouse uses, governs and protects AI.
A note before you read: this page is written to be clear, not clever, and to hold up under the EU AI Act, which is exactly the standard I teach my clients to work to. It is an honest account of how we build, not a compliance certificate, and nothing here is legal advice. If your own business uses AI, take your version of this to a solicitor before you publish it.
Why this page exists
I teach AI governance for a living. It would be a poor look, and a worse principle, to build two AI operating systems and a whole AI team, then go quiet about how any of it actually works. So here is the plain version: what we use AI for, how we keep it in its lane, how your data is handled, what happens when you leave, and where we sit against the EU AI Act. If a line here raises a question, my inbox is hello@lighthouse.online and my WhatsApp is open.
How we use AI
AI is woven throughout The Lighthouse. We use it to support and speed up the work, never to replace the judgement behind it. In practice that means AI helps with content creation, research and idea generation, drafting and editing, internal admin and productivity, and the building and running of our two operating systems, LuminaryOS and LeverageOS, and the AI team and workflows inside them.
Here is the rule that sits over all of it: anything AI produces that reaches you, or reaches the public with our name on it, has passed through a human first. AI drafts, suggests, analyses and builds. A person reviews, corrects and approves. The speed is the machine's. The responsibility is ours, and it stays ours.
What powers LuminaryOS and LeverageOS
I believe in showing my working, so here is what the two operating systems are actually built on. They share the same architecture by design, built identically so they hold to one standard, so everything below applies to both.
Both were built with Claude Code, Anthropic's AI coding agent, directed by me. No dev team, no agency. I made every product decision, wrote the specifications and the canonical prompts, and tested it as user number one. Claude Code wrote the software itself under that direction. Founder-directed, AI-built, from handover document to a complete working product in under a week.
The thinking is done by Anthropic's Claude models, working as a team. One model does the analysis: the diagnostic that reads your intake answers, the quality gates that judge every asset before you see it, and the coherence checks that make sure your whole business tells one story. A second model does the writing: your positioning, your offers, your scripts and your emails, in your voice, from your words. LuminaryOS applies this to your authority and your Trust Ecosystem®; LeverageOS applies it to your AI team and your Conscious AI Method®. Every piece of writing passes automated quality checks before it reaches you, for voice consistency and for specificity, so nothing generic survives.
The applications themselves run on Next.js and TypeScript, the modern web framework used by the likes of Nike and OpenAI. Your data and sign-in run on Supabase, a Postgres database hosted in the EU (Ireland) for GDPR, with passwordless magic-link login and row-level security so every member's data is walled off to them alone. Hosting and deployment run on Vercel, and the code lives on GitHub with automated checks that stop anything broken ever reaching you. Designed outputs, such as your brand book, are compiled into a PDF in your brand by React-PDF.
And the part most people skip: discipline. Every change is tested by machine before a human sees it, with synthetic test members walking the whole journey against the live system and checking hundreds of criteria. The financial maths, your revenue targets, margins and lead numbers, is computed in code, never by AI, because your revenue plan deserves arithmetic, not vibes. There is a firm separation between what you see and what runs underneath.
How we govern it
Using AI well is a discipline, not a vibe, and we run it like one.
We work to a documented internal AI standard. Every AI use case, ours and our clients', is classified by risk: green for low-risk work like drafting and brainstorming, amber for client strategy and IP development, red for anything connected to CRMs, payments or automated actions, and black for anything touching regulated or sensitive territory, which we pause and take to a specialist before going near. Higher-risk work carries stronger controls: risk assessments, testing logs, defined human-approval points, and clear rules on what a tool must never do.
We keep humans in charge of the decisions that matter. AI in our systems assists and recommends; a person approves before anything meaningful happens. We test before we deploy, we document what we build, and we have an incident process for the day something goes wrong, because in any honest AI operation, one day something will.
How your data is protected
We handle personal data in line with UK GDPR, and we apply a few principles that go beyond the minimum.
We practise data minimisation: we ask for and process only what the work actually needs. We do not use your data, or your clients' data, to train AI models. Access is limited to the people who genuinely need it, data is encrypted in transit, and every member's data inside our systems is separated so it is visible only to them. We will never knowingly put sensitive or personally identifying client data into a public AI tool without a clear legal basis and the right safeguards in place.
Where we rely on third-party platforms to run our systems, those platforms process data under their own terms, and we choose them with data protection in mind rather than convenience. The full detail of what we collect and why lives in our Privacy Policy.
What happens when you leave
This is the bit most software companies bury, so I'll put it in plain sight.
Your data is yours. When you decide to leave, you can export all of it before you go. Once you cancel, your data is then removed from our systems entirely. We are not in the business of holding your work hostage, and we don't want a graveyard of ex-members' data sitting on a server either. You take what's yours, and we clear the rest.
Where we sit with the EU AI Act
We build to the EU AI Act's standards by design, and we go further than the minimum where we can. What that looks like in practice: every output is human-reviewed before it reaches you, it's always clear when you're working with an AI, and we keep pace with the Act as it changes rather than treating it as a box ticked once.
One point of honesty, because it protects you as much as us: we don't slap "EU AI Act-compliant" across our marketing as a badge, and you should be wary of anyone who does. Compliance under the Act is a legal conclusion about a specific system in a specific use, not a certificate you award yourself, and it depends partly on the platforms underneath us and on how tools are used once they leave our hands. So we do the work the Act asks for, hold ourselves to its standards, and describe that plainly, rather than making a claim we would then have to defend across every use case.
Two parts of the Act matter most for how we work with you. The AI literacy duty (Article 4), in force since February 2025, is about making sure the people using AI understand it, which is precisely what we train clients to do. The transparency duty (Article 50), applying from 2 August 2026, is about disclosure: telling people when they are interacting with AI, and marking AI-generated content. This page, and the way our systems make clear when you're working with an AI, are part of how we meet that. The Act's higher-risk obligations were pushed back to December 2027 under the 2025 reforms, and we're tracking those too.
None of this removes your own responsibility. If you build on what we teach, or use tools we hand you, you remain responsible for how they're used in your business, including reviewing outputs, handling data lawfully, and getting professional advice where a use case calls for it.
The limits
AI gets things wrong. It can be inaccurate, out of date, or confidently missing the point. We build in human review to catch it, and you should keep your own judgement switched on too. Nothing produced by our AI, or ours, is a substitute for regulated legal, financial, medical or therapeutic advice. Where a decision needs a qualified professional, see one.
Your choices
If you'd rather we didn't use AI in some part of your work with us, tell us when you engage, and we'll make reasonable efforts to accommodate it. Given that our two operating systems are AI at their core, there are places we can't strip it out and we might not be the right service provider for you. We'll tell you straight where that's the case rather than pretend otherwise.
This page will be updated as our tools, and the law, evolve. The current version always lives here.
If you would like your own AI Transparency page, and the policies, clauses and guidance to back it up, it's all coming as the AI Protection Kit. Join the waitlist for early access and the founder price.
Last Updated:Â July 2026