Privacy policy
Last updated: 2026-06-11 · DRAFT — review with counsel before going live.
1. Who we are
Startup Brain ("we", "our") is the data controller for personal data processed through this service. Contact: [your registered company name and address], email [privacy@yourdomain].
2. What we collect, and why
- Account data: email, company name. Purpose: identification and access to the diagnosis. Lawful basis: contract (Art. 6(1)(b) GDPR).
- Financial inputs: cash, burn, revenue, growth, churn, CAC, channels. Purpose: running the deterministic engine to produce your diagnosis. Lawful basis: contract.
- Anonymous funnel events: page views, calculator completion, diagnosis viewing, checkout start. Stored against an anonymous session id. IP addresses are stored as a one-way salted SHA-256 hash, never raw. Lawful basis: legitimate interests (Art. 6(1)(f)) — measuring conversion. You can object via the cookie banner.
- Payment data: handled by Stripe (PCI-DSS compliant). We never see card numbers. Lawful basis: contract.
3. AI processing
When the AI explanation layer is enabled, the deterministic engine's output — plus your approximated and anonymized inputs — is sent to Anthropic (Claude) under commercial API terms. Before any AI call we strip your company name, your email, and channel names; we round monetary values into privacy buckets. We never send raw, unrounded figures. Anthropic does not train on data sent via the commercial API. The AI never produces a financial conclusion independent of the engine.
4. Retention
- Account & diagnosis data: kept for the lifetime of the account, plus 24 months after deletion request (legal/accounting retention).
- Funnel events: 18 months from creation, then aggregated and the row deleted.
- Stripe payment records: per Stripe's retention policy (typically 7 years for tax compliance).
5. Your rights (EEA/UK)
Access, rectification, erasure, restriction, portability, objection, withdrawal of consent. Email [privacy@yourdomain]; we respond within 30 days. You can also complain to your local data protection authority (e.g. the Data Protection Commission in Ireland).
6. Subprocessors
- Supabase (database & auth) — EU region, DPA available.
- Stripe (payments).
- Anthropic (Claude API, optional) — EU data transfer covered by SCCs.
- Your hosting provider (e.g. Vercel) — EU region recommended.
7. Security
TLS in transit, at-rest encryption on the database, row-level security isolating each tenant. Secrets in environment variables, not in source. We notify affected users within 72 hours of becoming aware of a breach.
8. Changes
We notify material changes by email; minor wording changes are reflected here.