Legal
Privacy policy
Last updated: 17 September 2026
Who we are
Solofounders.help ("we") runs a website-analysis and sales-planning service at solofounders.help. We are the data controller for the personal data described here. Questions: privacy@solofounders.help.
What we collect
- Account data: your email address, and your name and avatar if you provide them or sign in with Google.
- URLs you submit and the public page text we read from them.
- Generated reports: the diagnosis and playbook produced for your product.
- Payment metadata from Stripe: the checkout session and payment identifiers, amount, currency and status. We never see or store your full card number.
- Technical data: a non-reversible hash derived from your IP address, used only to rate-limit scans and abuse.
- Email engagement: which of our emails were sent to you and their delivery status.
Why we use it
To create your account and let you sign in; to run scans and produce reports (the service you asked for); to take payment; to send transactional email about your account, scan and purchase; to prevent abuse; and to meet accounting and legal obligations. Marketing email is sent only while you are opted in and can be switched off in settings at any time.
Who processes your data
- Our hosting and database provider stores your account, scans and reports.
- AI processors (OpenAI and/or Google): receive the URL you submitted and the public page text we read, in order to generate your report. We do not send them your email address or payment details.
- Stripe processes payments and holds card data under its own privacy policy.
- Our email provider delivers transactional and, if you opted in, marketing email.
We do not sell personal data, and we do not run advertising trackers.
How long we keep it
Account data: until you delete your account. Scans and reports: until you delete them, you delete your account, or 24 months of account inactivity. Payment records: kept as long as tax and accounting law requires, with personal identifiers removed once your account is deleted. Rate-limit hashes: rolling, short-lived.
Cookies and consent
Essential cookies and local storage run without consent because the service cannot work without them: the session that keeps you signed in, a short-lived record of an anonymous scan so it can be attached to your account when you sign up, and abuse prevention.
Everything else — analytics and marketing measurement — is off unless you switch it on. We ask on your first visit, we treat no answer as a refusal, and rejecting is one click. You can change or withdraw your choice at any time with in the footer. Your choice is stored locally with the date you made it. We do not use advertising trackers or sell personal data.
Your rights
You can access, correct, export or delete your data. Deleting your account from settings removes your profile details and scans; payment records are retained without personal identifiers where law requires. Under GDPR you may also object to processing, request restriction, and complain to your local supervisory authority. Under the CCPA you may request disclosure and deletion, and we do not sell or share personal information for cross-context behavioural advertising. Email privacy@solofounders.help and we respond within 30 days.
International transfers
Our providers may process data in the United States and the European Union. Where data leaves the EEA or UK, transfers rely on the standard contractual clauses offered by those providers.
Changes
If we change this policy materially we update the date above and, for account holders, send an email.