Privacy Policy

Last updated 2026-08-27

This page lists everything SellSheet Studio collects, every service that touches it, and how to make all of it go away. No surprises is the whole policy.

We don't sell your data, don't run ads or ad trackers, and don't train AI models on your content.

What we collect

Only what the product needs to work:

  • Account: your email address and a securely hashed password (or a sign-in link — we never see or store a plain password).
  • Your content: campaigns, sell-sheet text, uploaded photos and logos, research targets, and tracker notes — we store them so the app can show them back to you.
  • Usage counts: how many searches, exports, and wording generations you've used, because the free tier and fair-use caps need them.
  • Payments: Stripe handles them entirely. We store a payment reference, never your card number.
  • Anti-abuse: the IP address a signup or password-reset request came from, kept for 7 days and then deleted. It's how one script is stopped from minting hundreds of free accounts without putting a CAPTCHA in your way.

What we don't do

  • No advertising and no ad trackers.
  • No selling or renting your data to anyone.
  • No cookies beyond the ones that keep you signed in.
  • No training AI models on your content. Not by us, and not by Anthropic — their published policy is that inputs and outputs from commercial products like their API are not used for training by default, and we never opt in to change that.

Services that process your data

SellSheet Studio runs on a small set of processors, each with one job:

  • Supabase — database, sign-in, and private file storage (where your data lives).
  • Stripe — payments. Card details go directly to Stripe and never touch our servers.
  • Anthropic — AI. Receives three things: the text you typed when you click for wording options, your product-category term (to suggest the trade words companies use for it), and the text of public company pages for classification. Per Anthropic's published policy, commercial API inputs and outputs are not used to train their models by default, and we never opt in to change that.
  • Firecrawl — web search and page fetching for company research. It receives your product-category search terms and the addresses of the public company pages we fetch for you, including the sites of companies you add to your tracker. It never receives your idea text.
  • Resend — sends the app's emails (sign-in links, follow-up digests).
  • Vercel — hosts the application.

Your images

Photos and logos upload to a private storage bucket that only your account can access; the app displays them through short-lived signed links. Background removal, when you use it, runs entirely in your browser — the photo never leaves your device during processing.

Emails we send

Transactional only: sign-in links and the follow-up digest — which you receive only because you set follow-up dates in your tracker. Every digest has a way to turn it off. We send no marketing email of any kind.

Retention and deletion

We keep your data for as long as your account exists. When you delete your account, we remove your rows from every application table and your files from storage, and we ask Stripe to delete your customer profile (name and email).

One record can't be removed that way: the anti-abuse log above is keyed to an IP address rather than to an account, so deleting your account can't find it by name. It clears itself on a 7-day cycle instead.

One honest limit: Stripe retains payment transaction records even after deletion, because payment processors must keep those records for accounting and dispute defense. We can't remove those, and we won't pretend otherwise.

To delete your account, use the delete section on your account page — it runs immediately. Or email support@sellsheetstudio.com from your account email and we'll complete it within 30 days.

Changes and contact

If this policy changes in a way that matters, account holders get an email first. Questions: support@sellsheetstudio.com