Privacy Policy
Last updated: July 31, 2026
This policy explains what clownfish101 collects, why, where it is stored, how long it is kept, and what you can ask us to do about it. We handle personal information in line with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA).
1. What we collect
1.1 Identity (Google sign-in)
- Email address, name (if you provide one to Google), and your Google account identifier (sub).
- We have no password field at all. Sign-in goes through Google only, so password leaks, broken reset flows and credential stuffing are not risks we carry.
1.2 Payment information
- Payments are handled by Stripe. We never see or store your card or bank details —— Stripe, a PCI DSS Level 1 processor, holds them independently.
- On our side we store only: your Stripe customer ID, current tier and subscription status, credit balances, and the ledger of grants and deductions.
1.3 Operating data you submit
- Topics, source material and generation parameters; the drafts and readings produced from them.
- The metric snapshots you confirm (reads, likes, saves and other numbers from a platform’s creator dashboard).
1.4 Screenshots
- When you use screenshot capture, the image is sent to our server for one OCR pass. The image itself is never stored —— it is discarded once read. What is kept is the extracted numbers and the snapshot you confirm.
1.5 Technical logs
- Server access logs (IP address, timestamp, request path, user agent) and error logs, used for troubleshooting, billing reconciliation and abuse prevention.
1.6 What we do not collect
- Passwords or session cookies for your social media accounts. The browser extension is local-first: it talks only to the agent on your own machine, and platform cookies never leave your computer. We neither want nor have the ability to sign in to those platforms as you.
2. Cookies
- Session cookie: keeps you signed in. Same-site, strictly necessary, 30-day lifetime.
- We use no third-party analytics, advertising or cross-site tracking cookies. There is no Google Analytics and no ad pixel on this site. If that ever changes, we will update this policy first.
3. How we use it
- To provide the Service itself: generation, readings, dashboard and ledger.
- To meter and bill usage, handle subscriptions and top-ups, and issue receipts.
- To send necessary account notices: subscription changes, price changes, policy updates, outages and security incidents.
- To troubleshoot, prevent fraud and abuse, and keep the Service and its other users safe.
- To improve the product using de-identified aggregates (for example, success rates per action type).
We do not use your personal information or operating data for advertising, do not sell or rent it to third parties, and do not use it to train our own or anyone else’s models.
4. Who your content goes to
- Generation: the topics and material you submit are sent to Microsoft Azure OpenAI to produce the draft.
- Screenshot OCR: the image is sent to Microsoft Azure Document Intelligence for text extraction.
Both run under Microsoft’s enterprise terms as our data processor: your content is not used to train models, and the result is returned to us. Beyond these, we do not send your content to any third party except where legally required.
5. Where data lives and how it is protected
- Account, ledger and billing data live in a MongoDB instance we run ourselves, on servers located inside the EU (Hetzner, eu-central).
- All traffic is HTTPS/TLS. The database requires authentication and is not exposed to the public internet; the generation and billing services are not public-facing and accept only internal, token-authenticated calls from the site.
- Each account’s data is isolated by account ID and every read and write is ownership-checked —— holding someone else’s record ID still does not get you their data.
- We take reasonable technical and organisational measures to protect your data, but no internet transmission or electronic storage can be guaranteed 100% secure.
6. Third-party services
The Service relies on the following third parties, each with its own privacy policy:
| Service | Purpose | Data involved |
|---|---|---|
| Stripe | Payments, subscriptions, invoices | Email, payment method (held by Stripe), transaction records |
| Sign-in (OAuth) | Email, name, account identifier | |
| Microsoft Azure OpenAI | Draft generation | Topics and material you submit |
| Microsoft Azure Document Intelligence | Screenshot OCR | Uploaded screenshots (not retained after reading) |
| Hetzner | Server hosting (EU) | All hosted data above, access logs |
7. Cross-border transfers
Our servers are in the EU; Stripe, Google and Microsoft may process data in other countries, including the United States, where local law may apply to it. By using the Service you understand and consent to these transfers.
8. Retention
- Account and operating data: kept for as long as the account exists.
- Screenshot images: not kept at all (see §1.4).
- Transaction and billing records: kept for up to 7 years as required by tax and accounting rules —— including after an account is deleted.
- Technical logs: up to 90 days, then rotated out.
- Security and abuse records: kept as long as needed to handle disputes and protect the Service.
9. Deleting your account
- There is no self-serve delete button yet. Email support@clownfish101.com from your registered address with “delete my account”.
- We delete your account and all operating data (drafts, snapshots, ledger, readings) within 30 days of the request and confirm by email.
- If you still have an active subscription, we cancel it as part of the deletion; the current period is handled under the Refund Policy.
- What survives deletion: transaction and billing records (legal obligation, see §8) and any necessary security-incident records.
10. Your rights
Under PIPEDA and related law you have the right to:
- Access the personal information we hold about you.
- Correct information that is inaccurate.
- Delete your personal information (subject to the retention obligations above).
- Export a copy of your data in a common, readable format.
- Withdraw consent to processing —— which generally means you can no longer use the Service.
To exercise any of these, email support@clownfish101.com. We respond within 30 days. If you believe we have mishandled your personal information, you may also complain to the Office of the Privacy Commissioner of Canada (OPC).
11. Minors
The Service is built for businesses and independent operators and is not directed at anyone under 18. We do not knowingly collect personal information from minors; if we find that we have, we delete it.
12. Changes to this policy
We may update this policy from time to time. The updated version is published on this page with a new “last updated” date; material changes affecting your rights are announced by email to your registered address.
13. Contact
Any privacy question or request: support@clownfish101.com.