Privacy Policy

Effective date: May 1, 2026

1. What we collect

When you create an account, we store your email address and a unique user ID provided by our authentication provider (Clerk). When you run a validation, we store the quiz inputs you provide and the resulting report data so you can access your history.

We also collect standard server logs (IP address, browser type, timestamps) to maintain security and diagnose issues.

2. How we use your data

  • Generate and store your validation reports
  • Enforce usage limits based on your subscription tier
  • Process payments through Stripe (we never see your full card number)
  • Send transactional emails (welcome, weekly alerts if opted in)
  • Improve the product based on aggregate, anonymized usage patterns

3. Third-party services

We share data with these providers only as needed to operate the service:

  • Clerk — authentication and user management
  • Supabase — database hosting (Postgres)
  • Stripe — payment processing
  • Railway — application hosting
  • Cloudflare — DNS, CDN, and DDoS protection
  • Resend — transactional email delivery

Your quiz inputs are sent to the Anthropic API and various market-data APIs (Google search data, Reddit, Hacker News, GitHub) to generate reports. These API calls do not include your personal information.

4. Data retention

Your account data and validation history are retained as long as your account is active. Cached API responses are automatically deleted after 7 days. If you delete your account, we remove your personal data within 30 days.

5. Cookies

We use essential cookies for authentication sessions. We do not use third-party advertising or tracking cookies.

6. Security

All data is transmitted over HTTPS. Database access is restricted with row-level security policies. API keys and secrets are stored in encrypted environment variables, never in client-side code.

7. Your rights

You can export or delete your data at any time by contacting us. If you are in the EU, you have rights under GDPR including access, rectification, erasure, and data portability.

8. Changes to this policy

We may update this policy from time to time. Material changes will be communicated via email or an in-app notice.

9. Contact

Questions about this policy? Email us at support@saasradar.app.