Legal
Privacy Policy
Last updated: placeholder — replace before going live.
What we collect
- Email address (for account login and transactional emails)
- Hashed password (we never see it in plain text)
- Stripe customer ID + subscription status (we do not store card numbers — Stripe handles all payment data)
- Browser cookies set by Supabase for session management
- Server logs (IP, user agent, timestamp of requests) retained 30 days for abuse prevention
Why we collect it
- Authenticate your account
- Process your subscription via Stripe
- Provide and improve the prediction service
- Detect and prevent fraud or abuse
- Comply with legal obligations (tax, accounting)
Third parties we use
- Supabase — authentication and database hosting
- Vercel — application hosting
- Stripe — payment processing
Each of these providers has its own privacy policy and acts as a sub-processor of your data on our behalf.
Your rights (GDPR)
You have the right to access, correct, export, and delete your personal data. Email us and we will respond within 30 days.
Cookies
We use only essential cookies required for authentication (Supabase) and security. We do not use advertising or tracking cookies.
Data retention
Account data is retained as long as your account exists. Upon deletion, account data is removed within 30 days. Payment records may be retained longer where required by law (typically 5–10 years for tax purposes).
Contact
Privacy inquiries: /contact.