Legal

Privacy Policy

Last updated: draft, not yet published.

This is a structural starting draft, not a substitute for review by a lawyer — especially before real payments and ESP credentials are flowing through the product.

What we collect

  • Account info: your email address and, if you sign in with GitHub, your GitHub profile name and avatar.
  • Newsletter content you submit for a flight-check, and the resulting scores.
  • ESP API keys you provide to connect a newsletter — stored encrypted (AES-256-GCM), never stored in plaintext.
  • Subscriber count and open rate pulled from your connected ESP.
  • Billing information, handled entirely by Stripe — we never see or store your card number.

How we use it

To run the deliverability checks you request, to verify reach for swap matching, to send you sign-in links and account emails, and to process payment for paid plans. We don't sell your data, and we don't use your newsletter content for anything beyond the check you ran it for.

Who we share it with

Service providers that make the product work, and nobody else: Resend (email delivery), Stripe (payment processing), GitHub (OAuth sign-in, if you use it), and the ESP you connect (beehiiv, Kit, or Substack — read-only, to pull your stats).

Data security

ESP API keys are encrypted at rest. Sessions are secured with HttpOnly, Secure cookies. The database is not exposed to the public internet.

Your rights

You can delete a newsletter's connected ESP key, or your whole account, at any time from the dashboard. Deleting your account removes your data from our database.

Changes

We may update this policy as the Service changes. Material changes will be reflected here with an updated date.