Privacy Policy
Effective date: July 20, 2026
Last updated: July 23, 2026
This policy explains what data Hot Takes (hottakes.app, operated by Gouliard Software LLC, “we,” “us”) collects, why, and what choices you have. It covers two different kinds of people who use Hot Takes:
- Account Holders — people with a hottakes.app account who create Projects and embed our SDK.
- Reviewers — people invited into a specific prototype who enroll with email + a one-time code and submit feedback captures, without ever creating a Hot Takes account.
If anything in this policy is unclear for your situation, use the support form.
1. Data We Collect
From Account Holders
- Account credentials: email address and password, handled by our authentication provider (Supabase Auth). We do not see or store your plaintext password.
- Display name and any profile fields you set.
- Project data: project names, project keys, widget accent color settings (Enterprise), teammate invite emails, and roles.
- Payment data: handled entirely by Stripe — we receive only plan status, subscription state, and billing metadata (e.g., customer ID, subscription ID), never your card number. See Stripe's privacy policy.
- Usage/operational data: things like rate-limit counters and webhook event logs used to keep the Service reliable and secure (see Section 5).
From Reviewers
- Email address, used solely to send the one-time enrollment code and to identify your submitted captures to the Account Holder's team.
- Display name, entered on first enrollment in a Project.
- Device token, a long-lived credential stored on your device (in the SDK's Keychain storage, not by us directly) that lets the prototype recognize you as an enrolled Reviewer on future launches without re-verifying your email.
- Captures you submit:
- Screenshots: the original screenshot, your annotations (drawing strokes, both as a flattened image and as raw stroke data), any typed note, and an optional voice clip up to 2 minutes long.
- Screen recordings: a video of whatever is visible on the prototype's screen while you record, with your microphone audio recorded into the video's audio track — anything you say while recording is captured. A poster-frame image is generated from the first frame.
- Device/app context: device model, OS version, the host prototype app's version/build number, and screen dimensions — attached automatically to every capture so the Account Holder's team can reproduce what you saw.
Reviewers should assume: a screen recording captures everything visible on the prototype's screen during recording, plus your voice if the microphone is live; a screenshot only captures what's on screen at the moment you snapshot it, plus anything you separately type or say into an optional note/voice clip.
Automatically
- Cookies: we use a strictly necessary authentication/session cookie (via Supabase Auth) to keep Account Holders signed in. We do not use advertising cookies.
- Analytics: on the live hottakes.app site (not on local development or preview deployments), we use Vercel Web Analytics to understand overall usage of the marketing site and web app (pages visited, general usage patterns). It is cookieless: it does not set cookies or store persistent identifiers in your browser. See Vercel's analytics privacy notice for details.
- Standard web server logs (IP address, request metadata) may be retained briefly by our hosting provider (Vercel) for operational/security purposes.
2. How We Use Data
- To operate the Service: authenticate you, deliver captures to the right Project and team, enforce plan caps, and send transactional email (OTP codes, password resets, billing notices).
- To process payments and manage subscriptions (Stripe).
- To enforce these policies and our Terms of Service, including rate-limiting and abuse prevention (see Section 5).
- To improve reliability — e.g., debugging failed uploads. We do not use capture content (screenshots, recordings, notes) for any purpose beyond delivering it to the Account Holder's team and operating the Service; we do not sell it, and we do not use it to train AI models.
3. Who We Share Data With (Service Providers / Processors)
We share data only with the vendors that help us run Hot Takes, each acting as a processor on our behalf:
| Provider | What it handles |
|---|---|
| Supabase | Database (Postgres), authentication, and file storage for all account data, project data, and capture media. |
| Stripe | Payment processing and subscription billing. Card data goes directly to Stripe; we never touch it. |
| Resend | Transactional email delivery (Reviewer OTP codes, and any other system email routed through this seam — password-reset email currently goes through Supabase Auth's own mailer, not Resend). |
| Vercel | Hosting for the web app and API; also runs our scheduled background jobs (e.g., data retention cleanup). |
| Vercel Web Analytics | Aggregate, cookieless usage analytics on the live hottakes.app site only (pages visited, general usage patterns). No cookies or persistent browser identifiers; not used for advertising. |
We do not sell personal data. We do not share capture content with anyone outside your Project's team and the service providers above.
We may disclose data if required by law, subpoena, or to protect the rights, safety, or property of Hot Takes, our users, or the public.
4. Where Media Lives and Who Can See It
- Capture media (screenshots, recordings, audio) is stored privately in Supabase Storage, scoped per Project. It is not publicly accessible.
- Only Account Holders and teammates who are members of a given Project can view that Project's captures, through short-lived signed URLs minted by our API on demand (each expires in under an hour; upload URLs are valid up to 2 hours).
- Reviewers cannot view other Reviewers' captures or any gallery — the mobile SDK is submit-only.
5. Data Retention
Retention windows depend on the Project owner's plan at the time a capture ages out, not the plan when it was created:
| Plan | Captures visible/retained for | After that |
|---|---|---|
| Free | 15 days | Soft-deleted (hidden from gallery); underlying files kept 30 more days, then permanently deleted |
| Starter | 30 days | Same 30-day grace window, then permanent deletion |
| Pro | 365 days | Same 30-day grace window, then permanent deletion |
| Enterprise | No expiry | N/A |
- The 30-day grace window exists so that if you upgrade shortly after captures age out, they can be automatically restored. After the grace window closes, deletion is permanent and we cannot recover the data.
- Operational logs: rate-limiting counters are kept about 2 days; billing-webhook event records are kept about 90 days (longer only for the single most recent event per customer, needed to prevent billing state from going out of order).
6. Your Choices and Rights
Account Holders
- Access/export: you can view all your Project and account data by signing in. As the owner of a Project, you can export that Project's captures, media, and metadata as a ZIP at any time from the Project page (the “Export project data” link). For an export of data beyond a single Project, use the support form.
- Deletion: you can permanently delete your account from account settings. This deletes every Project you own and all its captures/media; it removes (but does not delete) Projects you're merely a teammate on. You must cancel any active paid subscription first (via the billing portal) — we block self-serve deletion while a paid plan is active so cancellation happens deliberately through Stripe first.
- You can also use the support form to request deletion or correction of your data instead of using the self-serve flow.
Reviewers
- You can ask the Account Holder who invited you to remove you from a Project — this revokes your enrollment on that device going forward.
- To request deletion of your captures or enrollment data directly from us, email use the support form with the Project and email address you enrolled with. The mobile SDK has no self-serve deletion option for Reviewers, so this email request is currently the only way to delete your data.
GDPR / CCPA
Regardless of where you're located, you may request access to, an export of, or deletion of your personal information by contacting use the support form. We do not sell or share personal information, as those terms are defined under the CCPA.
If applicable law gives you rights to access, correct, delete, or port your personal data, or to object to or restrict our processing of it, use the support form and we will respond in good faith within a reasonable time. We do not currently have a Data Processing Agreement (DPA) template published; contact us if you need one for your organization.
7. Children's Privacy
Hot Takes is not directed at children under 13 (or the relevant age of digital consent in your jurisdiction), and we do not knowingly collect data from them.
8. Data Security
We rely on our providers' security practices (Supabase, Stripe, Vercel, Resend) plus our own access controls (row-level security scoping every Project's data to its members; short-lived signed URLs for media). No system is perfectly secure; we can't guarantee absolute security of your data.
9. International Data Transfers
We process and store data in the United States. If you access Hot Takes from outside the United States, your information will be transferred to, processed, and stored in the United States, and by using the Service you consent to this transfer.
10. Changes to This Policy
We may update this policy periodically. Material changes will be announced by email to Account Holders or an in-app notice before taking effect.
11. Contact
Questions or requests about this policy: use the support form.