Legal

Privacy Policy

Last updated: September 2026

01

Data We Collect


We collect information you provide directly to us: your name, email address, company, and anything you send us when you contact support. We collect usage data automatically when you use the product, including IP address, browser type, and pages visited. Payments are processed by Stripe; we receive billing status and invoice details but never see or store full card numbers. When you connect a third-party service to Supercurve, we collect the data described in the next section. We do not sell your personal data.

02

Connected Services & Google User Data


Supercurve accesses third-party services only when you explicitly authorize them: Google Analytics 4 (reporting data, read only), Google Search Console (search performance data, plus sitemap submission when you request it), Google Ads (reporting and campaign configuration, read only), Google Tag Manager (container configuration, read only), Meta Ads (Facebook and Instagram advertising reporting and campaign configuration, plus the list of Facebook Pages you manage and their follower counts; when an authorized admin uses the pause or resume control we send that one status change to Meta, and we never create ads, change budgets, edit creatives, or post to your Pages), ChatGPT Ads (OpenAI Ads reporting and campaign configuration, including each ad's review status, read only; you connect it by pasting an API key you issue in OpenAI Ads Manager, and disconnecting deletes the key from our servers), Bing Ads (Microsoft Advertising reporting and campaign configuration, read only: spend, impressions, clicks and conversions by campaign, ad group and keyword, the search terms people typed, and each campaign's budget and bidding settings), LinkedIn (posts and their performance; publishing only when you enable it), Webflow (site content), PostHog (product analytics for the one project you choose, read only: daily totals of events, pageviews, sessions and distinct visitors, plus the top pages, events, referrers, UTM values, countries, devices, browsers and operating systems; we receive aggregate counts only, never individual people, their properties, raw events, or session recordings), Salesforce (CRM data, read only: opportunities, accounts, leads, contacts, campaigns, stage history, and activity records), and Attio (CRM data for the one workspace you choose, read only: deals with their stage, value, owner and stage history; companies with their name, domains, description, categories, country, size and founding date; people with their name, primary email address, job title, country and company; workspace member names, used to show deal owners; and the titles, dates and status of notes, tasks and meetings. We never read Attio lists or list entries, and never write to Attio). From both CRMs we store the names, email addresses, job titles and countries of your contacts, leads and people, so your team can see who is on a deal and export a customer list (see How We Use It). We deliberately minimize the rest: we never store their phone numbers, and we never read the body of emails, notes or meeting descriptions, or any transcript or recording, only titles, subject lines, dates, and outcomes. We request the narrowest OAuth scopes each feature needs, read-only wherever possible. Access tokens are stored server-side, encrypted at rest, and are never exposed to your browser. Supercurve's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

03

How We Use It


Data from connected services is used for one purpose: showing you your own dashboards, reports, and recommendations inside Supercurve. Our AI features process this data to generate analysis and suggestions for you; we do not use your data, including Google user data, to train generalized AI or machine learning models. We do not sell connected-service data, do not use it to advertise Supercurve or anyone else, and do not share it with third parties except the service providers described below. Customer-list exports: on the page for a connected CRM (Salesforce or Attio), a signed-in member of your team can download a CSV of the people on accounts that have won a deal, with their email address plus whichever of name, country, company, job title and won value they choose, for example to upload to an advertising platform as a lookalike audience. That file is created only when your team member asks for it and goes only to their browser; we do not keep it, and we never send it, or any other connected-service data, to an advertising platform or other third party ourselves. Whether and where the file is uploaded is your decision as the controller of that data, and you are responsible for having the right to use those contacts for advertising under your own privacy notice, applicable law, and the destination platform's terms. Account and usage data is additionally used to operate the service, communicate with you, prevent abuse and fraud, and comply with legal obligations.

04

Sharing & Sub-Processors


We share data only with the service providers that run Supercurve: cloud infrastructure and database hosting (Supabase, Vercel, Google Cloud), payment processing (Stripe), and AI model providers that process data solely to deliver product features. These providers act on our instructions, access only what is necessary, and may not use your data for their own purposes. If you install our Slack app, the messages you exchange with it are processed to provide that feature; messages from the public channels the app is invited to are kept for up to 90 days so it can answer with context, follow edits and deletions made in Slack, can be cleared from the app at any time, and are deleted when the app is uninstalled or disconnected. We maintain a current list of sub-processors and will notify you of material changes. We disclose data where required by law.

05

Retention, Disconnection & Deletion


We retain your data for as long as your account is active. Disconnecting an integration immediately stops collection from that service and deletes the stored credentials; you can also revoke Supercurve's access at any time from the provider's own settings (for Google, at myaccount.google.com/connections; for Meta, under Facebook Settings, Business integrations; for Salesforce, under your personal Settings, Connections; for Attio, by removing the Supercurve app in your workspace settings). Data already collected is kept after you disconnect so your history stays readable, until you ask us to delete it or delete the website or account; connecting a different Attio workspace or Salesforce org to the same website deletes the data collected from the previous one. You can request deletion of previously collected data or your entire account by contacting privacy@supercurve.ai; we act on verified requests within 30 days, subject to legal obligations that may require us to retain certain records.

06

Your Rights


Depending on your jurisdiction, you may have rights including: access to the personal data we hold about you; correction of inaccurate data; deletion of your data; restriction of processing; data portability; and objection to processing based on legitimate interests. To exercise any of these rights, contact us at privacy@supercurve.ai. We will respond to requests within 30 days. We will not discriminate against you for exercising your privacy rights.

07

Cookies


We use cookies and similar technologies to operate our website, remember your preferences, and understand how visitors use our site. Essential cookies are required for the site to function and cannot be disabled. Analytics cookies help us understand traffic patterns; these can be disabled without affecting functionality. We do not use third-party advertising cookies on our website. You can manage cookie preferences through your browser settings.

08

Security


We protect your data with encryption in transit and at rest, least-privilege access controls, and continuous vulnerability scanning; the full picture is on our security page at supercurve.ai/security. No method of transmission or storage is 100% secure. In the event of a breach affecting your data, we will notify you in accordance with applicable law.

09

Contact


If you have questions, concerns, or requests related to this Privacy Policy or our data practices, please contact our privacy team at privacy@supercurve.ai. For EU/UK residents, if you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection authority. Our registered address and Data Protection Officer contact are available upon request.