Legal

Privacy Policy

Last updated: January 1, 2025

Stoptions.ai ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information. By using the Service, you agree to the practices described in this policy.

1. Information We Collect

1.1 Account Information

When you create an account or start a free trial, we collect your email address and any name you provide. This information is stored securely in our authentication system (Supabase) and is used to manage your account and deliver the Service.

1.2 Billing Information

If you subscribe to a paid plan, payment is processed by Stripe. We do not store your credit card number, CVV, or full payment details on our servers. Stripe may share limited billing metadata with us (last 4 digits, expiry date, billing country) for subscription management purposes.

1.3 Usage Data

We automatically collect information about how you use the Service, including pages visited, features used, time spent, and actions taken on the dashboard. This data is collected via server logs and analytics tools and is used to improve the Service.

1.4 Communication Preferences

If you opt in to SMS notifications, we collect your mobile phone number. This is stored securely and used only to deliver Service notifications. You may opt out at any time by texting STOP or updating your account settings.

1.5 Contact Form Submissions

If you contact us via the contact form or by email, we retain your name, email address, and message content to respond to your enquiry and for record-keeping.

2. How We Use Your Information

We use the information we collect to:

  • Create and manage your account
  • Deliver the Morning Brief and dashboard features
  • Process subscription payments and manage billing
  • Send transactional emails (account confirmation, password reset, subscription receipts)
  • Send SMS alerts if you have opted in
  • Respond to support and enquiry messages
  • Analyse usage to improve the Service
  • Enforce these Terms and prevent fraud or abuse
  • Comply with legal obligations

We do not sell your personal information to third parties. We do not use your information to train AI models. We do not share your email address with advertisers.

3. Third-Party Services

We work with a small number of trusted service providers who process data on our behalf:

Supabase

Authentication and database. Your email address and account data are stored in Supabase. Data is hosted on servers in the US. Privacy policy →

Stripe

Payment processing. Stripe handles all card data under PCI-DSS compliance. We never see or store raw card numbers. Privacy policy →

Resend

Transactional email delivery. Your email address is shared with Resend to deliver Morning Brief emails and account notifications. Privacy policy →

Twilio

SMS delivery for subscribers who have opted in to text notifications. Your phone number is shared with Twilio only if you enable SMS alerts. Privacy policy →

4. Cookies and Tracking

We use minimal cookies necessary for the Service to function, including session tokens for authentication. We do not use third-party advertising cookies or tracking pixels. We may use privacy-respecting analytics (such as server-side logging) to understand aggregate usage patterns without identifying individual users.

5. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we will delete or anonymise your personal information within 30 days, except where we are required to retain it for legal or financial compliance purposes (such as billing records, which we retain for up to 7 years).

6. Data Security

We implement industry-standard security measures including TLS encryption for data in transit, secure authentication via Supabase (including optional 2FA), and access controls that limit who can view user data. No system is perfectly secure; in the event of a breach affecting your data, we will notify you as required by applicable law.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access — request a copy of the personal data we hold about you
  • Correction — request correction of inaccurate data
  • Deletion — request deletion of your personal data
  • Portability — request your data in a portable format
  • Objection — object to certain uses of your data
  • Withdrawal of consent — withdraw consent for optional communications (e.g. SMS)

To exercise any of these rights, email us at support@stoptions.ai. We will respond within 30 days.

8. Children

The Service is not directed to children under the age of 18. We do not knowingly collect personal information from anyone under 18. If we become aware that we have collected data from a minor, we will delete it promptly.

9. International Transfers

Your data may be transferred to and processed in countries other than your country of residence, including the United States. We rely on standard contractual clauses and other appropriate safeguards to protect data transferred internationally.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email. Your continued use of the Service after the effective date of the updated policy constitutes your acceptance of the changes.

11. Contact

Privacy questions or requests? Email support@stoptions.ai or visit our contact page.