Privacy

Your build data
stays yours

Last updated 23 July 2026. Written to be read, not to be survived. If anything here is unclear, that is our fault, tell us.

1. What we never collect

  • Your source code. It stays on your machine and in your repo.
  • Your API keys or environment secrets. We never ask for them and never store them.
  • Your customers' data. We have no access to the product you build.
  • Card numbers. Stripe handles payment details; they never touch our servers.
  • Tracking cookies. Our page counts use no cookie and no advertising identifier, so there is nothing to follow you between sites and no consent banner to dismiss.
  • Your visit as a record. Page counts are added to a total and thrown away; we keep no log of who went where.

2. What we do collect

Account. Your email address and password hash, so you can sign in. That is the whole account record.
Build progress. Which idea you are building, which phases you have marked done, and when. This is what lets your progress follow you across devices.
Saved ideas. The ideas you bookmark, so your list is there when you return.
Subscription state. Your plan, its status, and the renewal date, mirrored from Stripe so we can unlock the right things.
Reported numbers. Only if you connect an agent and choose to report progress or metrics. Numbers only, never code.
Page analytics. Counts only, and never a record of you. Which page was viewed, which site sent you, the country, whether the screen was a phone or a desktop, how far down the page people scrolled, and which areas of a page get clicked. It is added to a running total the moment it arrives and the visit itself is never stored, so there is no row here that is you, and no way to reconstruct one.

3. Why we collect it

To run your account, keep your build progress across devices, unlock what your plan pays for, deliver the email you asked for, and keep the service secure and working. We do not build advertising profiles, and we do not sell or rent your data to anyone, at any price at all.

4. Who processes it

We use a small set of processors to run the service. Each one only receives what it needs to do its job.

Supabase. Database and authentication. Hosts your account and build progress.
Vercel. Application hosting and delivery.
Stripe. Payments and subscription state. Card details stay with them.
Amazon SES. Transactional and subscribed email delivery.
Cloudflare. Network, asset storage, and abuse protection.

5. The agent connection

If you connect a coding agent, the connection is deliberately one-directional in what it can send us. Your agent can read the phase you are on and report that a phase is done, or report numbers you choose to send. It cannot send us your code, and our tools provide no way to do so. Your keys stay in your own environment throughout.

6. How long we keep it

Account and build data are kept while your account exists. Delete the account and they are removed. Billing records are kept as long as tax and accounting law requires, which is the one thing we cannot delete on request.

7. Your rights

Access. Ask for a copy of what we hold about you and we will send it.
Correction. Fix your email or preferences any time from Account settings.
Deletion. Delete your account from Account settings. It removes your data and cannot be undone.
Objection. Unsubscribe from any email with the link in it. Transactional mail about your own account still applies.

8. Security

Access to your rows is enforced at the database level, so one account cannot read another's data even if the application is wrong. Traffic is encrypted in transit. Secrets live only in environment configuration, and never in any of the code that we ship out to your browser.

9. Changes

If this policy changes in a way that affects you, we will say so in the changelog and by email. The date at the top of this page always reflects the current version.

10. Contact

Questions about your data, or a deletion request that the dashboard cannot handle, reach us at hello@upgradiq.com.