Last updated: September 2026
The platform may store product ideas submitted via public forms, admin actions, pipeline telemetry, and append-only marketing logs (page views, CTA clicks) on the server you operate. First-party request logs record the visitor's IP address, user-agent and the pages requested. LLM prompts and responses are written to local disk for debugging and cost accounting unless you disable logging.
An IP address is personal data under the GDPR and personal information under US state law, so we minimise it. In the traffic analytics pipeline, IP addresses are anonymised at ingest — truncated to their network (IPv4 a.b.c.0 /24, IPv6 /48) — so an individual device is no longer singled out, and those records are retained for at most 90 days. The full address is used only transiently to rate-limit submissions and in short-lived security/audit logs to prevent abuse (a legitimate interest). Country and network are derived before truncation, so analytics and abuse detection keep working.
We do not sell visitor data, and the storefront loads no Google Analytics or other third-party trackers — no cross-site or advertising cookies. Everything is first-party, on the host you operate. Self-hosted deployments control retention; delete data/ or change the log-retention window on your schedule.
On-chain payments expose wallet addresses and transaction hashes publicly on the blockchain. Payment verification reads chain data via RPC providers you configure — not through a centralized payment processor.
For GDPR, CCPA/CPRA or similar access and erasure requests on a public deployment, contact the site operator via the lead form. Self-hosted operators are the data controller for their instance. Which law applies depends on where visitors are located, not where the operator is incorporated.