gottogetthat.money

privacy policy

last updated · 2026-05-25

what we collect

where it lives

what we share

we don’t sell or rent your data. we share with the subprocessors listed above strictly to operate the service. share links you create are visible to anyone with the URL.

your rights

GDPR/CCPA: you can export, correct, or delete your data anytime via /app/settings or by emailing hi@gottogetthat.money. account deletion removes projects, clients, templates, chat history, and usage logs within 30 days. share links die immediately.

retention

active accounts: indefinitely while you use the service. cancelled accounts: 90 days then permanent deletion. audit logs are kept 12 months for security and dispute resolution.

security

TLS in transit. at-rest encryption on Neon. AUTH_SECRET held in Vercel only. webhooks signed by Stripe and verified before mutation. rate limits on share-link endpoints. magic-link tokens are one-time and expire.

cookies

session cookie (auth.js JWT) and basic Vercel analytics if enabled. no third-party trackers, no ad pixels.

contact

data questions: hi@gottogetthat.money. EU data protection issues can be escalated to your local supervisory authority.