Know what the workspace keeps.
A practical description of the current early-access product’s data handling. Updated 17 September 2026.
Public pages and early-access requests
You can read the public site without an account. It does not include advertising trackers or a third-party analytics script. Optional first-party analytics are stored in our private Supabase database. Vercel hosts the site and may process request information as part of operating the hosting service.
If you join the early-access list, the app stores the name, email address, optional website and use-case description you submit, along with the submission time. Requests are visible to the workspace owner and are retained for up to 180 days unless removed earlier. Joining the list does not create a workspace account or start a subscription.
Request rate limits use a short-lived keyed hash of the request IP address. The raw IP is not saved in the application’s early-access record.
Website and product analytics
We count page visits with page paths, referring domains, campaign source labels and device categories, without tracking cookies, account IDs or visitor/session identifiers. Initial page requests are counted on the server; navigation between pages is counted in the browser. These counts do not identify unique people. With your permission, separate analytics link page visits and feature interactions within a temporary session and measure visible-page time and scroll milestones. URL queries, form contents and typed text are not collected. A random session identifier links activity within a browser session and expires after 30 minutes of inactivity. Your analytics preference is saved in your browser. You can change it using the preferences control on this page. We honor Do Not Track and Global Privacy Control for both anonymous page counts and optional browser analytics.
Signed-in actions, action outcomes, response times and AI or Reddit usage costs are recorded on the server for product operations and accounting, independently of optional browser analytics. These events are associated with your account ID; the owner can view them by member and campaign. Early-access submissions are counted without copying the submitted name, email or message into analytics. Analytics do not contain passwords, API keys, raw IP addresses, private draft text, keystrokes or session recordings.
Analytics events are visible only to the website owner and retained for up to 90 days, with expired records removed during collection or scheduled daily cleanup. Short-lived keyed IP hashes are used to limit analytics abuse and expire after a day. Long-term provider spending totals are retained for accounting. Payment analytics are not enabled; no card data is collected by this application.
Accounts and subscriptions
Public signup stores your name, email address, salted password hash and preferred plan. Each customer account has private campaigns, leads and usage allowances. Subscriptions currently provide individual access; other customers cannot access your account. A new account has no paid usage allowance until Stripe confirms an active subscription.
Stripe checkout is being connected. Once enabled, Stripe hosts checkout and payment-method management. We store Stripe customer/subscription identifiers and subscription status to apply your plan. Card information is handled by Stripe and is never collected in our application forms.
Workspace access and saved work
The private workspace requires sign-in. Campaign details, shared team notes, statuses and saved drafts are stored in a private Supabase database. Everyone granted access to a workspace can see its shared work; access requests and development controls are limited to the owner.
Sign-in uses a secure, HttpOnly session cookie. Passwords and API keys are not sent to the browser in workspace data. The owner controls membership and can revoke member access.
Third-party processing
Website or offer text and relevant Reddit source content are sent to OpenAI when needed for campaign assistance, assessment or drafting. The app requests that Responses API output is not stored by setting its storage option to false; provider-side handling remains subject to that provider’s own policies.
The redditapis.com service retrieves posts and community rules. Its API key is kept on the server. The app does not ask for your Reddit password and does not automatically post or send messages.
Source retention and deletion
Retained Reddit source text, authors, assessments and related replies expire after 48 hours unless fetched again. The app removes expired source content on subsequent access or scheduled cleanup. Detail caches last five minutes and community-rule caches last 24 hours.
When a source recheck returns explicit removed or deleted markers, it clears affected content and drafts. Uncertain provider errors do not establish that a source was deleted. Competitor briefs are invalidated when their retained sources expire or change.
Campaign settings remain until the campaign is removed. Original discussion drafts are retained with the campaign, subject to a workspace limit of the latest 30 drafts. Lead notes and statuses expire with the lead’s source content after 48 hours unless that source is fetched again. Removing a campaign removes its associated saved work. Financial usage totals stay recorded so deleting content does not reset spending controls.
Requests about your information
Workspace members can ask the owner who invited them to review or remove saved information. Early-access requesters can use the same form with their original email and write “data removal request” in the use-case field; this flags the request for owner review. It does not automatically verify identity or delete records.