Privacy Policy

Last updated: January 8, 2025

1. What We Collect

We collect the bare minimum needed to run our service and bill you. Unlike Facebook, we're not building a psychological profile of your deepest fears and desires.

Account Information

  • Email address (for login and billing)
  • Payment information (processed by Stripe, not stored by us)
  • API usage statistics (to prevent abuse)

Usage Data

  • API endpoints you call
  • Search queries (to improve our service)
  • Basic analytics via Vercel (page views, load times)

2. What We Don't Collect

We're not creeps. We don't collect:

  • Your browsing history outside our site
  • Social media profiles or contacts
  • Location data (unless you tell your browser to share it)
  • Biometric data (what would we even do with that?)
  • Your deepest startup fantasies (we have enough nightmares)

3. How We Use Your Data

Your data helps us:

  • Provide the service you're paying for
  • Send you bills and important service updates
  • Improve our market intelligence algorithms
  • Prevent API abuse and fraud
  • Occasionally email you about new features (you can opt out)

We DO NOT sell your data to advertisers, data brokers, or your competitors. We're not in the surveillance capitalism business.

4. Data Sharing

We share your data with exactly three types of entities:

Service Providers

  • Stripe (payment processing)
  • Vercel (hosting and analytics)
  • Email service (for transactional emails)

Legal Requirements

We'll share data if legally required (court orders, subpoenas, etc.). We're not going to jail for your startup queries.

Business Transfers

If we sell DontBuildThat (unlikely, but stranger things have happened), your data goes with it. We'll notify you first.

5. Data Security

We use industry-standard security measures:

  • HTTPS encryption for all data transmission
  • Secure database storage with encryption at rest
  • Regular security audits and updates
  • Limited employee access on a need-to-know basis

No system is 100% secure, but we're paranoid enough to keep your data safer than your domain portfolio.

6. Your Rights

You have the right to:

  • Access your data (just ask us)
  • Correct inaccurate data
  • Delete your account and data
  • Export your data (what little there is)
  • Opt out of marketing emails

To exercise these rights, email us at privacy@dontbuildthat.com. We'll respond within 30 days, probably faster.

7. Cookies and Tracking

We use minimal cookies:

  • Authentication cookies (so you don't have to log in constantly)
  • Preference cookies (dark mode, etc.)
  • Analytics cookies (only if you consent)

You can disable cookies in your browser, but the site might work weirdly. Your choice.

8. Data Retention

We keep your data as long as your account is active. After you delete your account:

  • Personal data: deleted within 30 days
  • Usage analytics: anonymized and kept for service improvement
  • Financial records: kept for 7 years (tax requirements)

9. Children's Privacy

DontBuildThat is not for children under 13. If you're under 13 and reading this, go outside and play instead of planning your startup empire.

We don't knowingly collect data from children. If we discover we have, we'll delete it immediately.

10. Changes to This Policy

We may update this policy occasionally. We'll email you about significant changes. Continued use means you accept the updated policy.

We're not going to turn into a data-harvesting monster overnight, but we reserve the right to improve our service and update our practices accordingly.

11. Contact Us

Questions about this Privacy Policy? Email us at privacy@dontbuildthat.com

We'll respond faster than most startups respond to customer support requests.