SectAnalyst
Billing

Privacy Policy

Last updated: July 16, 2026

Draft — pending legal review. This document is a working draft and has not yet been reviewed by an attorney. It will be finalized before paid subscriptions open.

1. What we collect

Account data: your name and email address, provided through our authentication provider when you sign up. Product data: the projects, section models, and analysis inputs you choose to save, plus per-run usage events (which tool ran, when — used for quotas, abuse prevention, and product statistics). Billing data: your payment card is collected and stored by Stripe, our payment processor — card numbers never touch our servers. Technical data: standard server logs and error reports (IP address, browser type) retained for security and debugging.

2. What we don’t do

We do not sell your data, use it for advertising, or use your engineering project data to train machine learning models. There are no third-party advertising or analytics trackers on the site.

3. Processors we rely on

We use a small set of infrastructure providers, each processing only what their role requires: Clerk (authentication and account management), Stripe (payments and invoicing), Neon (database hosting), Vercel (application hosting and logs), Sentry (error reporting), Upstash (rate limiting), Cloudflare (bot protection on public forms), and Resend (transactional email). Each is bound by its own data-processing terms. [DRAFT — attach/reference DPAs with counsel.]

4. Cookies

The Service uses only strictly necessary cookies: the session cookie set by our authentication provider so you stay signed in. There are no advertising or cross-site tracking cookies, which is why there is no cookie consent banner.

5. Data retention

Your account data and saved projects are kept for as long as your account exists. Usage events are retained for up to 24 months for abuse prevention and statistics. Server logs and error reports are retained on our providers’ standard rolling windows. [DRAFT — confirm retention periods with counsel.]

6. Your rights (GDPR / CCPA)

You can access your saved data in-app at any time, export your projects, and delete your account — deleting your account removes your projects, usage history, and personal data from our database, and cancels any active subscription. Depending on where you live, you may also have rights to rectification, restriction, portability, and objection; to exercise any of these, contact us at the address below. We do not discriminate against users who exercise privacy rights.

7. Security

Data is encrypted in transit (TLS) and at rest by our hosting providers. Passwords are handled entirely by our authentication provider and are never visible to us. API keys are stored as one-way hashes. Access to production systems is limited to the operator of the Service.

8. International transfers

Our providers host data primarily in the United States. [DRAFT — confirm transfer mechanisms (SCCs/DPF) with counsel for EU/UK users.]

9. Changes and contact

Material changes to this policy will be announced in the app or by email before they take effect. Privacy questions and requests: jd.pozo.raster@gmail.com [DRAFT — replace with the company support address].

Terms of ServicePrivacy Policy