[ Legal ]
Privacy Policy
Last updated: March 17, 2026
1. Information We Collect
We collect information in the following ways:
Account Information
When you create an account, we collect your email address and, optionally, a username. If you sign up via Google OAuth, we receive your Google email address and profile name from Google's authentication service. We do not store your Google password.
User-Generated Content
We store the ideas, problem descriptions, and chat messages you submit to the Service. This content is used to generate market research reports and is stored in your account for future reference.
Generated Reports
Market research reports, competitor analyses, build briefs, and other AI-generated outputs are stored in association with your account and projects.
Usage Data
We track the number of analyses you've used per billing period to enforce plan limits. We may collect basic analytics data such as page views and feature usage to improve the Service.
2. How We Use Your Information
We use your information to:
- Provide and operate the Service, including generating AI-powered market research
- Authenticate your identity and manage your account
- Process payments and manage subscriptions
- Enforce usage limits and rate limiting
- Send transactional emails (account verification, password resets, billing receipts)
- Improve the Service based on usage patterns
We do not sell your personal information to third parties. We do not use your submitted ideas or research data to train AI models.
3. Data Storage and Security
Your data is stored securely using Supabase, a hosted PostgreSQL database service with enterprise-grade security. Key security measures include:
- Row Level Security (RLS) policies ensuring users can only access their own data
- Encrypted connections (TLS/SSL) for all data in transit
- Server-side API authentication on all endpoints
- Rate limiting to prevent abuse
- Passwords hashed using bcrypt via Supabase Auth (we never store plain-text passwords)
Supabase infrastructure is hosted on AWS in the United States. For more information about Supabase's security practices, see supabase.com/security.
4. Third-Party Services
The Service integrates with the following third-party providers. Each processes data as necessary to provide the Service:
Google Gemini (AI)
Your idea descriptions and chat messages are sent to Google's Gemini AI API to generate market research analyses, competitor intelligence, and build briefs. Google's API data usage policies apply.
Privacy Policy →Serper (Search)
Search queries derived from your idea descriptions are sent to Serper to fetch real-time search results from Google, App Stores, Reddit, and ProductHunt. Serper does not receive your account information.
Privacy Policy →Stripe (Payments)
Credit purchases are processed by Stripe. We do not store credit card numbers or payment details on our servers. Stripe handles PCI-DSS compliance.
Privacy Policy →Supabase (Database & Auth)
Account data, project data, and chat history are stored in Supabase's hosted PostgreSQL database. Authentication is handled by Supabase Auth.
Privacy Policy →Vercel (Hosting)
The Service is hosted on Vercel's edge network. Vercel may collect standard web server logs including IP addresses and request metadata.
Privacy Policy →Upstash (Rate Limiting)
We use Upstash Redis to enforce rate limits. Only anonymized user identifiers are stored temporarily for rate tracking purposes.
Privacy Policy →5. Your Rights
You have the right to:
- Access your data — all your projects, messages, and reports are visible in the app
- Export your data — use the Export Brief feature to download your research
- Delete your data — delete individual projects or your entire account via Settings
- Correct your data — update your username and password via Settings
Account deletion is permanent and immediate. When you delete your account, all associated data (projects, messages, reports, profile, usage records) is permanently removed from our database. This action cannot be undone.
6. Data Retention
We retain your data for as long as your account is active. If you delete your account, all data is permanently deleted immediately. We do not maintain backups of deleted user data beyond standard database backup windows (typically 7 days), after which deleted data is permanently purged.
Anonymized, aggregated usage statistics (e.g., total number of analyses run across all users) may be retained indefinitely for internal analytics purposes.
7. Cookies
We use essential cookies only, required for authentication and session management. We do not use advertising cookies, tracking pixels, or third-party analytics cookies. The authentication cookies are httpOnly and secure, managed by Supabase Auth.
8. Children's Privacy
The Service is not intended for use by anyone under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected data from a child under 13, we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes via email. The "Last updated" date at the top of this page indicates when the policy was last revised.
10. Contact
If you have questions about this Privacy Policy or how we handle your data, contact us at privacy@skopple.io.