Privacy Policy
Last Updated: July 2026 — Effective immediately
This Privacy Policy explains how profits-compass ("we," "our," or "us") collects, uses, discloses, and safeguards your information when you visit our website, sign in, or use our AI consultation service. We comply with the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), and applicable local laws.
1. Information we collect
- Account data: email address, optional display name, authentication tokens, and (optionally) a password hash if you set one.
- Chat data: the messages you send and the AI responses you receive, plus the conversation metadata (timestamps, turn count, session id).
- Payment data: processed entirely by our PCI-DSS compliant payment processor (Stripe). We receive only the order id, amount, currency, plan, and last-4 / brand — never your full card number, CVC, or expiration.
- Voice data (optional): if you use the voice input feature, the audio is sent to our speech-to-text provider (OpenAI Whisper) for the sole purpose of transcription. Audio is not retained by the provider for model training (you are opted out by default).
- Device & usage data: IP address, user agent, referrer, and aggregated usage events (e.g. "page_view", "checkout_started") used for fraud prevention and product analytics.
- Cookies & local storage: a session cookie (httpOnly, signed) for authentication, a locale-preference cookie, and a few non-sensitive localStorage keys (e.g. session id, demo user id). We do not use third-party advertising cookies.
2. How we use your information
We process your personal data on the following legal bases under GDPR Article 6:
- Contract (Art. 6(1)(b)): to provide the AI consultation, generate and deliver your PDF report, and process payments.
- Legitimate interests (Art. 6(1)(f)): to prevent fraud, secure our service, debug issues, and improve product quality through aggregated, de-identified analytics.
- Consent (Art. 6(1)(a)): for non-essential cookies, marketing emails (if any), and optional integrations. You can withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)): to comply with tax, accounting, and law-enforcement requests where required.
3. AI training and your conversations
You are opted out by default. We do not train, fine-tune, or evaluate any AI model on your conversations. The model providers we use (OpenAI) have a zero-retention configuration for API traffic, meaning your prompts and responses are processed for the single request and not stored or used for training. You can find OpenAI's API data usage policy at openai.com/policies/api-data-usage.
4. How we share your information
We never sell your personal data. We share it only with:
- Stripe — payment processing (PCI-DSS Level 1).
- OpenAI — AI text generation and (if used) voice transcription. Zero-retention configuration; no training on your data.
- Resend — transactional email (login codes, receipts). We send the email; Resend stores the delivery log for 30 days.
- Hosting & storage providers — managed cloud infrastructure with encryption at rest and in transit. No provider has access to decrypted personal data outside the operational request path.
- Law enforcement — only when we receive a valid subpoena, court order, or other legally binding request.
5. International data transfers
We are a globally accessible service. If you are in the EU/UK and we transfer your data to a country without an adequacy decision (e.g. the United States), we rely on the European Commission's Standard Contractual Clauses (SCCs) and supplementary safeguards (encryption in transit and at rest, access controls, minimization).
6. Data retention
- Active account data: kept while your account is active.
- Deleted account data: anonymized immediately; hard-purged from backups within 30 days.
- Payment records: retained for 7 years to comply with tax / accounting law.
- Server logs: 30 days for security and debugging.
7. Your rights
Depending on where you live, you have some or all of the following rights. We honor all of them regardless of jurisdiction:
- Access — request a copy of the personal data we hold about you.
- Portability — receive your data in a structured, machine-readable format (JSON). You can do this instantly from Profile → Account & security → Export my data.
- Rectification — correct inaccurate data (email us).
- Erasure ("right to be forgotten") — close your account from the same Profile page; we'll anonymize immediately and hard-purge within 30 days.
- Restriction / Objection — email us to restrict or object to certain processing.
- Withdraw consent — at any time, where processing is based on consent.
- Lodge a complaint with your local data-protection authority (e.g. the ICO in the UK, a CNIL in France, the California AG for CCPA claims).
8. California-specific rights (CCPA/CPRA)
If you are a California resident, you have the right to know what categories of personal information we collect and share, the right to delete personal information we have collected, the right to correct inaccurate information, and the right to limit the use of sensitive personal information. We do not sell or share your personal information for cross-context behavioral advertising. To exercise these rights, email [email protected].
9. Children's privacy
Our service is not directed to children under 16 (or under 13 in the US), and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please email us so we can delete it.
10. Security
We use industry-standard technical and organizational safeguards to protect your data: TLS 1.2+ in transit, AES-256 encryption at rest, bcrypt-hashed passwords (never stored in plaintext), rate-limited admin endpoints, principle-of-least-privilege access controls, and continuous monitoring. No system is 100% secure; if we become aware of a breach affecting your data, we will notify you and the relevant authorities as required by law.
11. Cookies
We use only first-party, functional cookies (auth, locale, CSRF token). We do not use advertising or cross-site tracking cookies. Non-essential cookies are only set with your consent.
12. Changes to this policy
We may update this policy from time to time. When we do, we'll bump the "Last Updated" date at the top and, for material changes, notify signed-in users by email at least 14 days before the change takes effect.
13. Contact us
For any privacy question, data request, or complaint:
- Email: [email protected]
- Support: [email protected]
- Data Protection Officer (DPO) — reachable at the same privacy address; we typically respond within 5 business days.