privacy policy
last updated · 2026-05-25
what we collect
- account: your email and (optionally) your name + Google profile data when you sign in via Google
- profile: name, title, address, bank details, VAT — only if you fill them in
- content: briefs, deliverables, quotes, client names, chat with the advisor, file uploads
- billing: Stripe customer + subscription IDs (we don’t store card numbers)
- usage: per-request token counts so we can enforce monthly caps
- logs: IP + user agent on key actions (login, accept, reject)
where it lives
- postgres (Neon, EU/US region depending on your setup)
- Vercel for hosting + edge cache
- Stripe for payment processing
- Resend for transactional email (magic links, share notifications)
- Anthropic for AI requests — we send your inputs to their API but they don’t use them to train models per their terms
what we share
we don’t sell or rent your data. we share with the subprocessors listed above strictly to operate the service. share links you create are visible to anyone with the URL.
your rights
GDPR/CCPA: you can export, correct, or delete your data anytime via /app/settings or by emailing hi@gottogetthat.money. account deletion removes projects, clients, templates, chat history, and usage logs within 30 days. share links die immediately.
retention
active accounts: indefinitely while you use the service. cancelled accounts: 90 days then permanent deletion. audit logs are kept 12 months for security and dispute resolution.
security
TLS in transit. at-rest encryption on Neon. AUTH_SECRET held in Vercel only. webhooks signed by Stripe and verified before mutation. rate limits on share-link endpoints. magic-link tokens are one-time and expire.
cookies
session cookie (auth.js JWT) and basic Vercel analytics if enabled. no third-party trackers, no ad pixels.
contact
data questions: hi@gottogetthat.money. EU data protection issues can be escalated to your local supervisory authority.


