Legal

Privacy Policy

What MarketBrain collects, why, and who else handles it. Written against what the product actually does, not a template.

Draft. Not legal advice.

This document is an unreviewed draft. It was written to describe what MarketBrain actually does today, but it has not been reviewed by a lawyer, it is not legal advice, and it is not a finished agreement. A qualified attorney needs to review and approve it before MarketBrain relies on it or launches publicly. Some sections are still marked as open questions and do not yet reflect a decision.

Last updated September 14, 2026

1. What this policy covers

This policy explains what personal data MarketBrain collects when you use the site and the product, why we collect it, who processes it on our behalf, and what you can ask us to do with it.

It describes what the product actually does today rather than what a generic template would claim. Where a practice is not formally decided yet, this page says so instead of inventing a policy.

2. What we collect

This is the full list of what MarketBrain and the services it runs on receive about you.

Account information
Your email address, and a password if you choose to sign in with one. Passwords are stored as a hash by Supabase Auth, our authentication provider. We never see or store your password in readable form. If you sign in with Google instead, we receive the basic account identity Google returns, primarily your email address, and not your Google password.
Subscription information
If you subscribe, we store a Stripe customer identifier, a Stripe subscription identifier, your subscription status, and the date your current billing period ends. That is all of it. Your card number, expiry, and security code go directly to Stripe on Stripe's own hosted checkout page and never reach MarketBrain's servers or database.
Usage and analytics data
We use PostHog to understand how the site is used. Today the product explicitly records page views, meaning the page you visited and its query string. PostHog's own default behavior also records technical context alongside that, such as browser, device type, referring page, approximate location derived from IP address, and interactions with page elements. Analytics are recorded against a randomly generated identifier rather than being linked to your account. Analytics only run when a PostHog key is configured for the environment you are using.
Error and diagnostic data
We use Sentry to catch crashes and errors. When something breaks, Sentry receives the error message, a stack trace, the URL and browser or server context where it happened, and technical details about the request. We have not enabled Sentry's optional setting for attaching personally identifying request data, though an error report can still incidentally contain personal data if it appears in an error message or a URL. Sentry also samples about one in ten requests for performance timing. Error tracking only runs when a Sentry key is configured for the environment you are using.
Sign-in cookies
Supabase Auth sets cookies in your browser so you stay signed in between page loads and your session can be refreshed. These are necessary for the product to work at all. Without them you cannot stay logged in.

3. What we do not collect

We do not ask for or collect your name, your postal address, your phone number, your date of birth, your store's sales data, or any information about your customers. Nothing in the product requests it.

We never receive your card number, and we never receive your password in readable form.

4. Why we use it

We use the data above for these purposes and nothing else. We do not build advertising profiles, and there are no third-party advertising trackers on this site.

  • To create and run your account, sign you in, and let you reset your password.
  • To take payment, manage renewals and cancellations, and know whether your account has paid access to the full feed.
  • To send account and service emails, such as magic-link sign-in emails and password reset emails. These are sent by Supabase Auth.
  • To understand which parts of the site are used and where people drop off, so we can improve the product.
  • To find and fix crashes, bugs, and performance problems.
  • To keep the service secure, to enforce the paywall and our terms, and to investigate abuse.

5. Who processes your data

MarketBrain is a small operation and we rely on third-party services to run it. Each of these is a processor acting on our behalf, and each has its own privacy policy. This is the complete current list of services that can handle data about you.

Supabase
Authentication and database. Holds your account record, your hashed password, your session, and your subscription status. Also sends the magic-link and password-reset emails.
Stripe
Payments and billing. Receives your email address and an internal account identifier when you start checkout, and handles your card details directly. Stripe is the sole processor of your payment information. Cancellation and billing management happen on Stripe's hosted portal.
PostHog
Product analytics. Receives page views and the technical context described above, tied to a random identifier rather than your account.
Sentry
Error and performance monitoring. Receives crash reports and diagnostic context when something goes wrong.
Vercel
Hosting. The site and its server code run on Vercel, so requests to MarketBrain pass through Vercel's infrastructure and appear in its standard server logs, which include IP addresses.
Google
Only if you choose to sign in with Google. In that case Google handles the sign-in itself and returns your basic account identity to us. If you sign in with email instead, Google is not involved.

6. Services that do not touch your data

Two other services are part of how MarketBrain works, and neither receives anything about you. We mention them so the picture is complete.

Apify runs two scheduled jobs for us: the daily scrape of public TikTok Shop product listings, and a weekly scrape of Google Trends search-interest data for a fixed list of product categories (skincare, kitchen gadgets, phone accessories, and others) we use to spot seasonal buying patterns. Anthropic's Claude API generates the supplier links, marketing angles, and video scripts from those product listings, and also runs a monthly research pass that searches the web for published seasonal buying-guide lists to check which product categories are genuinely trending ahead of a season. Both only ever process public product-category data and public web search results. Nothing about you, your account, or your activity is sent to either one.

7. We do not sell your data

We do not sell, rent, or trade your personal data, and we do not share it with anyone for their own marketing purposes.

Beyond the processors listed above, we would only share personal data if the law required it, such as a valid legal request, if it were necessary to protect our rights or someone's safety, or if MarketBrain were involved in a merger or acquisition, in which case you would be told before your data moved to a new owner.

8. Cookies and local storage

MarketBrain uses cookies and browser local storage for two purposes only. Supabase Auth sets cookies to keep you signed in, which are strictly necessary for the product to function. PostHog stores an anonymous identifier in cookies or local storage so repeat visits from the same browser are recognized as the same anonymous visitor.

There are no advertising cookies, no third-party ad networks, and no cross-site tracking pixels on this site.

You can block or clear cookies in your browser, and you can use your browser's Do Not Track or tracking-protection settings. Blocking analytics cookies will not break the product. Blocking the sign-in cookies will prevent you from staying signed in.

Open question, needs a real decision

MarketBrain does not currently show a cookie consent banner. That is probably acceptable for a US-only audience with no advertising cookies, but a banner or a consent mechanism is generally expected once there are EU or UK visitors. This should be decided together with the GDPR question further down, once there is real data on where users actually are.

9. How long we keep it

Your account information and subscription record are kept for as long as your account exists, since we need them to keep the account working.

Analytics and error data are kept according to PostHog's and Sentry's own default retention settings for our plan. We have not overridden them.

Open question, needs a real decision

MarketBrain does not have a formal data retention policy yet, and no specific retention period is invented here. The Product Architect needs to decide how long to keep an account after it is closed, how long to keep analytics and error data, and whether to configure retention explicitly in PostHog and Sentry rather than relying on their defaults. This should be settled before launch, since a retention promise made here has to be one the product actually keeps.

10. Your rights and choices

You can see and change your email address and password from the account and password-reset flows in the product.

You can ask us for a copy of the personal data we hold about you, or ask us to correct it, by emailing getmarketbrain@gmail.com. We will act on those requests within a reasonable time.

You can delete your own account directly from the Account page while signed in, no email needed. Deleting your account also removes your subscription record and your dismissed-notice state, since the database is set up to cascade those deletions, and immediately cancels any active paid subscription as part of the same action, you will not be charged again.

Deleting your account does not delete Stripe's own billing records. Records Stripe is legally required to keep for tax and financial reporting stay with Stripe under their own policy, and we cannot delete those on your behalf.

You can opt out of analytics by using your browser's tracking protection or by blocking analytics cookies. This does not affect your access to the product.

11. Where your data is handled

MarketBrain is operated from the United States and the services listed above process data on infrastructure in the United States, including our PostHog instance, which is configured to the US region.

If you use MarketBrain from outside the United States, your data will be transferred to and processed there, where privacy laws may differ from your own.

Open question, needs a real decision

This policy does not currently include GDPR-specific or CCPA-specific sections, and that is a deliberate gap rather than an oversight. MarketBrain has not launched and has no real user base yet, so there is no evidence about where users are or whether either regime applies. Both need a real answer before launch: GDPR and UK GDPR bring a lawful-basis statement, data subject rights, and likely a consent banner, and CCPA and CPRA apply once California thresholds are met. The Product Architect should revisit this once there is actual usage data on user location, and a lawyer should confirm which regimes apply rather than adding boilerplate that claims compliance we have not verified.

12. Children

MarketBrain is a business tool and is not directed at children. It is not intended for anyone under 18, and our terms require account holders to be at least 18. We do not knowingly collect personal data from children under 13, or under 16 where that is the applicable threshold.

If you believe a child has given us personal data, email getmarketbrain@gmail.com and we will delete the account and the data.

13. Security

Passwords are hashed by Supabase Auth and never stored in readable form. Card details are handled entirely by Stripe and never reach us. Access to the database is restricted by row-level security policies, and the paywalled parts of the product feed are not readable directly from the browser at all.

No service can promise perfect security, and we do not claim to. If we ever discover a breach affecting your personal data, we will tell affected users and take the steps the law requires.

14. Changes to this policy

We will update this policy as MarketBrain changes, particularly if we add a new service that processes your data. When we do, we will change the date at the top of this page. If a change materially affects how we handle your personal data, we will tell you by email or in the app before it takes effect.

15. Contact

Questions about this policy, or requests to access or delete your data, should go to getmarketbrain@gmail.com.