Legal
Privacy Policy
Last updated: July 23, 2026
Short version
We collect the minimum we need to make the Service work: your email, the product details you give us (like your website URL), the channels you add, the work you log, and the handles and metrics you choose to enter. We don't sell your data. We don't read your DMs. We don't scrape other users.
1. What we collect
Account data.Your email address and, if you sign in with Google, a few profile fields Google sends us (name, picture). We don't store your Google password.
Product data.Your website URL and the brief we generate from it (what you make, who it's for, your goal), which you can edit. To build that brief, we send your public website content to OpenAI for analysis.
Channels and work. The channels you add to your map, the handles you enter, your goals, and the work you mark shipped.
Social account data. Account connections are not available during beta. We only store the public handles and metrics you enter yourself. We do not receive DMs, friend lists, passwords, or content from other users.
Companion extension data.If you install the optional browser extension, it can recognize supported actions you take while signed in to a platform and log those actions to your Control Output workspace. It does not post, read DMs, or collect other users' content.
Operational data. Standard server logs and analytics on the marketing site (page views, anonymized referrer) so we can tell what works.
2. What we don't collect
- Your private messages or DMs on any platform.
- Lists of other users you interact with.
- Content from other people's accounts.
- Your passwords for third-party platforms. We never see them.
3. How we use it
- To show you your map, your stats, and your goals.
- To process your subscription via Polar.
- To send transactional emails (sign-in confirmations, billing receipts, important account notices).
- To improve the product. We may look at aggregated, anonymized usage to decide what to build next.
4. Where it lives
We use a small number of trusted vendors to run the Service:
- Supabase: database, authentication, file storage.
- Vercel: hosting and request logs.
- Polar: payments and billing.
- OpenAI: analyzes your public website content to build your growth plan.
- Google: if you choose to sign in with Google.
- Resend (or our equivalent transactional email provider): account emails.
Each of these has its own privacy practices. We share only what they need to do their job.
5. Cookies
We use a small number of cookies for things that are required to make the app work, like keeping you logged in and remembering your last tab. We don't use third-party advertising cookies.
6. Your rights
You can:
- Delete your data anytime from Settings.
- Email us at hi@controloutput.com to request a copy of your data, correct it, or delete your account.
- Withdraw consent or object to processing where required by your local laws (e.g., GDPR/UK GDPR/CCPA).
When you delete your account, we delete your profile, workspaces, plans, daily logs, and uploaded feedback files from the live service immediately. Encrypted backups expire within 30 days, except where retention is required by law (for example billing records).
7. Children
The Service isn't intended for children under 13. If you believe a child is using the Service, contact us and we'll delete the account.
8. Security
We use industry-standard practices: encrypted connections, hashed credentials, scoped access. No system is perfectly secure, so if we're ever aware of a breach affecting your data, we'll notify you promptly.
9. International transfers
Our vendors operate globally; your data may be stored or processed in the United States or the European Union. By using the Service, you consent to those transfers.
10. Changes
We'll update this page when our practices change. Material changes will trigger an email or an in-app notice. The date at the top of this page tells you when it was last updated.
11. Contact
Privacy questions? Email hi@controloutput.com.
