What we collect
- Account data: email address, password (hashed by Supabase Auth), and any optional profile info.
- Usage data: IP (hashed, 30-day retention) for rate-limiting and abuse prevention.
- Scanned data: publicly displayed testimonials and their attributions (name, title, company) from competitor websites you ask us to scan. We do not collect, store, or process email addresses or LinkedIn URLs of the people named in those testimonials.
Third parties we use
Supabase (database + auth), Vercel (hosting), Anthropic (AI — testimonial extraction), Resend (transactional email). Once payments go live we'll add our merchant-of-record processor here too.
Your rights
Request deletion or removal at any time via /deletion. We process within 30 days (typically 7).
Last updated: April 30, 2026. This is a v1 placeholder; a full, lawyer-reviewed policy will replace it before EU launch.