Legal
Privacy Policy.
Last updated 1 March 2026
We collect the minimum needed to run the suite, understand what people find useful, and keep accounts secure. We never sell personal information.
What we collect
Account information you give us: username, email address, and optionally a company name. If you sign in with Google, we receive your name, email address and profile image from Google.
Product usage: pages viewed, buttons clicked, how far you scroll, how long you spend on a section, device category, and which product you looked at. Assessment answers and the recommendation produced are stored so you can return to them.
What we never collect
We never store passwords in readable form, card numbers, the contents of private notes or documents, or any secret keys inside analytics. Analytics records what was interacted with, never what was typed.
Why we collect it
To operate your account, to decide which product fits your company, to improve the site, to prevent abuse, and to meet legal obligations. We do not run advertising profiling.
How long we keep it
Account records are kept while your account is open and for up to 12 months after closure. Analytics events are retained for 24 months in aggregate form. Audit records of privileged administrative actions are retained for 24 months for security.
Who can see it
You, and authorised staff acting under a logged administrative role. Support staff may view an account in read-only mode with a recorded reason. Nobody can act as you, change your billing, or take any Founder Lock action on your behalf.
Your rights
You can request a copy of your data, correction of anything inaccurate, or full deletion of your account and its records. Contact us and we will action it. Deletion is permanent.
Security
Data is stored with row-level security so accounts can only read their own records. Administrative access is role-based, server-enforced and logged. Secret keys are held server-side and never exposed to your browser.