Privacy Policy
Effective Date: September 26, 2026 | Last Updated: September 26, 2026
1 Introduction & Data Controller
Linse AI (“we,” “our,” or “us”) operates https://linseai.com (the “Service”). We are committed to protecting your privacy and ensuring your personal data is handled transparently, securely, and in full compliance with applicable privacy regulations, including the European Union General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA).
For inquiries regarding data processing, the designated Data Protection contact is: supportlinseai@gmail.com.
2 Information We Collect
We only collect data necessary to provide and improve our competitive intelligence services:
- Account Identification Data: When you register via Google OAuth, we receive your email address, full name, and authenticated unique identifier provided by Supabase Auth.
- Intelligence Queries & Input: Competitor app URLs submitted for analysis, user-defined review volume parameters, rating filters, and custom analysis prompts.
- Transaction & Subscription Records: Payment transaction metadata, plan identifiers, credit quotas, and order confirmation IDs. Note: All credit card processing is handled via certified PCI-DSS compliant payment gateways. Linse AI never stores full credit card numbers or sensitive banking details on its servers.
- Technical & Usage Information: Anonymized server logs, browser type, device category, IP address, and timestamps to safeguard against denial-of-service and unauthorized API abuse.
3 Legal Basis for Processing (GDPR Article 6)
We process your personal information under the following legal frameworks:
- Performance of Contract: To generate AI competitor intelligence reports, maintain your account credits, and store reports in your private vault.
- Legitimate Interests: To monitor platform health, ensure server security, prevent fraud, and optimize application performance.
- Legal Compliance: To adhere to financial reporting, tax, and accounting standards.
4 AI Processing & Zero-Training Policy
Our platform synthesizes public store reviews using artificial intelligence APIs (e.g., Google Gemini, OpenAI, Anthropic). Linse AI strictly adheres to enterprise zero-training policies:
- Your custom prompts and internal queries are never sold, distributed, or utilized to train general-purpose public AI foundation models.
- All public store review processing is ephemeral and scoped strictly to generating your dedicated report.
5 Cookies & Local Storage
We prioritize clean, tracker-free operations. We do not employ invasive third-party cross-site advertising trackers or data-broker cookies. We only use functional browser storage:
- Essential Authentication Tokens: Stored securely to preserve your active session across page navigation.
- Client State LocalStorage: Temporary keys (such as pending analysis URLs) used to restore state after authentication redirects.
6 Third-Party Sub-Processors
We work with enterprise-grade infrastructure providers that uphold stringent data protection standards:
- Supabase Inc. — Encrypted PostgreSQL database hosting and OAuth identity management.
- Railway Corp. — Secure cloud infrastructure and application hosting.
- Payment Processors (e.g., Dodo Payments / Stripe / BMAC) — Tokenized, PCI-DSS Level 1 compliant billing.
7 Data Retention & Deletion Rights
We store your saved analysis reports in your private Intelligence Vault for as long as your account remains active. You maintain full ownership of your data.
You may request the permanent erasure of your account, profile history, and all stored intelligence reports at any time by emailing supportlinseai@gmail.com. Requests are completed within 30 days without fee.
8 Your Privacy Rights (GDPR & CCPA/CPRA)
Depending on your jurisdiction, you possess the following enforceable rights:
- Right of Access & Portability: Obtain a copy of your personal data and analysis records in a structured machine-readable format.
- Right to Rectification: Request correction of inaccurate profile data.
- Right to Erasure (“Right to be Forgotten”): Request complete deletion of personal records.
- Right to Restrict or Object: Limit or object to certain aspects of processing.
- Right to Non-Discrimination: We will never penalize, deny services, or alter pricing because you exercised your statutory privacy rights.
- Do Not Sell My Personal Information: Linse AI does not sell, rent, or lease personal information to third parties.
9 Data Security & Encryption
We enforce modern defense-in-depth protections: all web traffic is encrypted via TLS 1.3/HTTPS, server-to-database connections utilize strict SSL validation, and role-based row-level security (RLS) restricts access to your personal intelligence reports solely to your authenticated account.
10 Children’s Privacy (COPPA)
Linse AI is designed for commercial product managers, developers, and founders. Our service is not directed to individuals under the age of 18. We do not knowingly collect personal data from minors.
11 Contact Us & Regulatory Inquiries
If you have any questions, wish to exercise statutory privacy rights, or need assistance, reach our privacy desk directly:
Linse AI Privacy & Compliance Desk
Official Website: https://linseai.com
Email: supportlinseai@gmail.com
Response Time: Within 24–48 business hours