Legal
Privacy policy
What we collect, why we have it, who else touches it, how long we keep it, and how to get it back or have it deleted.
- Version
- 0.1-draft
- In effect from
- —
Draft — not yet in force. This text has not been reviewed by a lawyer and is published for transparency during the invite-only beta, not as a binding agreement. The following still have to be supplied before it can take effect: registered company name, company registration number, registered office address, governing law, jurisdiction for disputes, data-protection contact address, EU representative (where required). The operative terms during the beta are the ones issued on request — ask us.
1.Who controls your data
[not yet registered — see the notice at the top of this page] is the controller for the personal data described here. Questions and requests go to [not yet registered — see the notice at the top of this page], or through the data request form.
For customers in the European Union, our representative is [not yet registered — see the notice at the top of this page].
Where you enter information about other people — a colleague, an investor contact, a sales lead — you are the controller of that information and we process it on your behalf as described in the data processing note.
2.What we collect
Information you give us
- Account details — name, email address, country, and how you heard about us.
- Workspace content — everything you enter about your company: your plan, milestones, financial figures, hiring plans, sales contacts, and any files you choose to upload.
- Billing details — handled by our payment processor. We receive confirmation of a payment and the last four digits and card brand for display. We never receive or store full card numbers.
- Anything you send us — contact form messages, support email and bug reports.
Information we generate
- Derived figures — runway, burn, dates and dependencies, calculated from the numbers you entered.
- Audit and access records — who in your workspace did what, and when an investor link was opened.
- Operational logs — needed to run the service and investigate faults.
What we do not collect
We do not buy personal data, we do not run advertising trackers, and we do not build profiles for advertising. We do not ask for and do not want government identifiers, health data, or any other special-category data — please do not upload it.
3.Why we process it, and on what basis
- To provide the service — performing the contract you entered when you created a workspace. This covers your account, your workspace content and everything the product calculates from it.
- To take payment — performing the contract, and complying with tax and accounting law.
- To keep the service secure — our legitimate interest in preventing abuse, fraud and unauthorised access, including rate limiting and bot defences at sign-up.
- To send service email — performing the contract. These are transactional only: sign-in codes and security notifications. We do not currently send marketing email; if that changes, it will be on the basis of consent you give separately and can withdraw at any time without affecting your account.
- To meet legal obligations — where we are required to retain or disclose information.
4.Who else processes it
The complete set of third parties any part of the service can reach. Each acts on our instructions under a data processing agreement, and none of them is permitted to use your data for their own purposes.
- Supabase — the database, authentication and file storage that hold your workspace.
- Stripe — payments, subscriptions and invoices. Card details go directly to Stripe and never reach our servers.
- Resend — delivery of transactional email.
- Upstash — the queue that carries background jobs you have approved.
- Vercel — application hosting.
- Model providers — only when you approve a specific paid action, and only the portion of your content that action needs. Providers are contractually prohibited from training on it.
We will also disclose data where we are legally compelled to. Where we are permitted to tell you, we will.
5.Your data is not training material
Nothing you enter or upload is used to train any model, ours or anyone else’s. When you approve a paid action, only the context that action requires is sent to the provider performing it, under terms that prohibit training on it. Files you upload are read once to extract the plain facts you then confirm — they are not scored, and your idea is not evaluated.
6.How long we keep it
- Workspace content — for as long as the workspace exists. Company records are versioned, so an earlier version remains readable until the workspace is deleted; nothing is silently overwritten.
- Deleted files — recoverable for 30 days, then permanently purged.
- Closed accounts — deleted after the export window in clause 7, except where we must keep records for longer.
- Billing records — retained for the period tax and accounting law requires, regardless of account status.
- Security and audit logs — retained for a limited period proportionate to investigating abuse.
7.Your rights
Depending on where you live you have some or all of the following rights. We do not charge for exercising them, and we will not treat you differently for doing so.
- Access — a copy of the personal data we hold about you.
- Correction — to have inaccurate data fixed. Most of it you can edit directly.
- Export — your workspace data in a portable format. Available in the product, and after cancellation.
- Deletion — to have your data erased, subject to records we must keep.
- Restriction and objection — to limit or object to processing based on legitimate interests.
- Withdraw consent — where processing relies on consent, at any time.
- Complain — to your local supervisory authority. We would rather you came to us first, but you are not required to.
Use the data request form. We respond within 30 days. We will ask you to verify control of the account before acting, because acting on an unverified request is itself a data breach.
8.Where your data is processed
Our providers operate across the European Union, the United States and Israel. Where data leaves the region it was collected in, the transfer relies on an adequacy decision or on Standard Contractual Clauses with the processor concerned. The specific mechanism for any given provider is available on request.
9.Security
Every record is scoped to its workspace and that boundary is enforced in the database itself, not only in application code, so a bug in one screen cannot expose another customer’s data. Files live in private storage reached only through short-lived signed links. Share tokens are stored only as a hash, so revocation is immediate and a copy of our database does not yield working links. Sensitive operations require a fresh verification step even when you are already signed in.
No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant authority as required by law. More detail is on the security page.
10.Cookies
We set only cookies the service cannot run without. See the cookie notice.
11.Children
The service is for people aged 18 and over. We do not knowingly collect data from children. If you believe a child has given us data, tell us and we will delete it.
12.Changes
If we change this policy materially we will tell you before the change takes effect. Prior versions are available on request.
Questions about this document go to our contact form. To exercise a data-protection right, use the data request form.