WhittleOSWhittleOS

⚙ Template draft — adjust entity & contact before launch.

Privacy Policy

Last updated: [DATE] · [LEGAL ENTITY]

1. Our approach

Your ideas are sensitive. Reports are private by default — nothing is public unless you explicitly share it.

2. Data we collect

  • Account data (email) — via our auth provider
  • Founder profile (skills, goals, preferences)
  • Ideas & analysis inputs (idea text, pasted evidence, optional URLs)
  • Reports we generate for you
  • Billing metadata — via Paddle
  • Product analytics (IDs & counts only — never your idea text)

3. How we use it

To run analyses, deliver reports, operate your account and billing, and improve the product. We do not sell your data.

4. AI processing

To generate reports, your idea inputs are sent to our AI provider (OpenAI). They do not train on this data. Your email and billing data are never sent to the AI.

5. Service providers

  • Clerk — authentication
  • OpenAI — AI analysis
  • Paddle — payments (Merchant of Record)
  • PostHog — product analytics (no idea content)
  • Sentry — error monitoring
  • Neon — database hosting
  • Resend — transactional email

6. Sharing

Share links are opt-in, random-token, noindex, and revocable anytime. Recipients see the report only — never your profile, email, or other ideas.

7. Retention

Active data is kept until you delete it. Deleted projects, reports, and accounts are hard-deleted within 30 days.

8. Your rights

You can export all your data (ZIP) and delete your account at any time. For privacy requests: [privacy@yourdomain].

9. Cookies

We use essential cookies for sign-in and privacy-respecting product analytics. No ad-tracking.

10. Contact

[privacy@yourdomain]