Privacy Policy
effective date: [date — set when in force]
This is a working draft written to fit how Weightedly actually behaves. It is not legal advice and it is not in force — have counsel review it (including the controller/processor split in section 01) before launch.
01Who we are and what this covers
Weightedly ([legal entity name], [registered address]) is a service that reads publicly available community discussion and raises the threads that matter to the brands who subscribe. This policy covers three kinds of people: visitors to this website, customers (the teams with Weightedly workspaces), and community authors — people whose public posts and comments appear in the sources we read. For website, account, billing, and community-content data, Weightedly acts as the data controller. For material a customer brings into their own workspace (notes, voice profiles, edits), the customer is the controller and we process it on their behalf.
02What we collect directly
- Account data. When you sign in with Google we receive your name, email address, and avatar. We never see your password.
- Billing data. Payments run through Stripe. We keep subscription status and invoices; card numbers live with Stripe, never on our systems.
- Product telemetry. Error-level diagnostics via Sentry (what broke, not what you typed), and operational logs needed to run the service.
- Cookies. The application uses session cookies for sign-in only. This marketing site sets none. We use no advertising trackers anywhere, and we do not sell or share personal information for advertising.
03Community content we read — and what we refuse to do
The heart of the service is reading public conversation: posts, comments, and articles from forums, subreddits, video comment sections, and blogs. That content sometimes includes personal data — most commonly a username and whatever the author chose to say in public. Our lawful basis for this processing is legitimate interest (GDPR art. 6(1)(f)): helping brands understand and honestly answer public conversation about their products, using only what the authors made public, in ways they would reasonably expect public posts to be read.
We hold ourselves to lines that are narrower than the law requires:
- public sources only — no private messages, no logged-in-only content, no circumvention of platform protections;
- no profiling of individuals — the unit of analysis is the conversation, never the person;
- no deanonymization, and no enrichment of usernames with outside data;
- no sale of personal data, to anyone, for anything;
- no training of AI models on community content or customer data;
- content deleted at the source is dropped from our indexes when the source is refreshed.
If you wrote something in public and want it out of Weightedly, email [privacy contact email] with a link to the post. We will remove it from our indexes and from future briefs within 30 days — no account required, no questions that assume you owe us an explanation.
04How we use information
To run the service (classify and score conversations, generate briefs and drafts for the customer who subscribed), to operate accounts and billing, to secure the platform, to fix what breaks, and to talk to customers about the service. That’s the list. We do not use your data for advertising, and we do not use it to train models (see 03 and 05).
05AI processing, disclosed plainly
Briefs and drafts are generated with large language models from our AI providers (currently Anthropic and OpenAI — the current list is in 06). Conversation excerpts and workspace context are sent to those providers to produce each brief; our agreements with them bar the use of that data for model training. Every AI-generated brief and draft is working material reviewed by humans on the customer’s team; the service makes no automated decisions with legal or similarly significant effects about anyone.
06Who we share with (subprocessors)
We share personal data only with the vendors it takes to run the service:
- Supabase — database, authentication, storage
- Hetzner — application hosting
- Anthropic — brief/draft generation (LLM)
- OpenAI — embeddings for search and clustering
- Stripe — payments
- Google — sign-in
- Sentry — error monitoring
- Cal.com — demo scheduling, if you book one
Each is bound by a data-processing agreement. Beyond these: we disclose data if the law compels us to (and will tell you unless legally barred), and in a merger or acquisition your data moves with the service under this policy. There is no other sharing.
07International transfers
Our infrastructure is in [EU/US — confirm regions]; some subprocessors are in the United States. Where personal data leaves the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses (and the UK addendum) with the receiving vendor.
08How long we keep things
- Account and workspace data — for the life of the account, deleted within 30 days of account deletion (backups age out within 90).
- Community content — a rolling window refreshed from the source; posts deleted at the source drop out on refresh, and removal requests (03) are honored within 30 days.
- Billing records — as long as tax law requires (typically 7 years).
- Error diagnostics — 90 days.
09Your rights
Depending on where you live (GDPR, UK GDPR, CCPA/CPRA, and similar state laws), you can ask for access to, correction of, deletion of, or a copy of your personal data; object to or restrict processing based on legitimate interest; and complain to your supervisory authority. Community authors’ removal path is in 03 and does not require an account. We do not discriminate against anyone for exercising a privacy right, and we honor verifiable requests within 30 days at [privacy contact email]. For CCPA purposes: we do not sell or share personal information, and we collect only the categories described in 02 and 03.
10Security
Data is encrypted in transit and at rest. Workspaces are isolated with row-level security so no customer can reach another’s data. Access to production is limited and logged. If a breach affects your personal data, we will notify you and the relevant authorities within the timelines the law sets.
11Children
Weightedly is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16, and workspace accounts require you to be at least 16.
12Changes to this policy
When this policy changes materially we will email workspace owners at least 30 days before the change takes effect and note the change history here. The current version always lives at this address.
13Contact
Privacy questions and requests: [privacy contact email]. Postal: [legal entity name], [registered address]. [If required: EU/UK representative details here.]