Legal

GDPR Notice

Startup Blueprint is committed to transparent, privacy-first product development. This notice outlines how we comply with the European Union's GDPR when processing your data as you explore customer discovery ideas through our platform.

Last updated: February 20, 2026

Data Controller

Startup Blueprint operates as the data controller for personal data processed through the platform. For all data protection inquiries, to exercise your rights, or to file a complaint, contact us at support@startupblueprint.dev.

Purpose and Legal Basis for Processing

We process your personal data under the following legal bases: (1) Article 6(1)(b) GDPR — Performance of contract: processing your account data, discovery session data, messaging data, and generated content to provide the Startup Blueprint service you have requested; (2) Article 6(1)(f) GDPR — Legitimate interests: sending drip campaign emails to help you use the platform, analytics to improve the service, security monitoring, and notifying solution owners of waitlist signups; (3) Article 6(1)(a) GDPR — Consent: where we rely on consent for optional data collection such as optional profile fields (bio, location, company, role, interests, social links). You may withdraw consent for optional data at any time by updating your profile or contacting us. Withdrawal does not affect the lawfulness of prior processing.

Data Categories and Minimization

We collect only data necessary for service provision. The categories are: (1) Account Data — email address, bcrypt password hash, Google OAuth provider ID and tokens, plan status and subscription identifiers (only if a paid plan is purchased), and email preferences; (2) Profile Data — display name (required), profile photo, and optionally bio, location, company, role, interests, website URL, LinkedIn URL, GitHub username; (3) Discovery & AI Session Data — 8-question interview responses, conversation history, AI-generated business solutions (title, summary, pain points, ICP, business model, TAM/SAM/SOM, go-to-market plan, feature lists), generated PRDs, landing page HTML in English and translated versions in over 200 languages, generated landing-page imagery, design configuration, visual style configuration, outreach messages, and AI token usage metrics; (4) Messaging Data — content of messages, replies, read receipts, and conversations between users; (5) CRM Data — outreach contact records you create (name, company, email, phone, social handles, outreach copy and stage); (6) Announcement Data — workspace and group announcements and their read status; (7) Waitlist Submission Data — email address, IP address, and browser user-agent of visitors who join a public solution's waitlist; (8) Feedback Data — bug reports and feature requests including description, page URL, email, and user-agent; (9) Contact Sales Data — email address, inquiry type and category, expected member count, and indicative budget; (10) Email Campaign Data — guided campaign records including send times, send status, and template metadata, plus message-digest tracking markers; (11) Technical Data — IP address, browser type, device information, session timestamps, and feature interaction patterns.

Sub-processors and Data Location

Startup Blueprint relies on the following sub-processors, each selected for GDPR compliance: (1) Supabase — database and authentication, EU-West region, AES-256 encryption at rest, TLS 1.2+ in transit, Row Level Security policies; (2) Google Cloud AI — Gemini and Imagen models for transient AI inference including discovery chat, solution generation, PRD generation, landing page generation, translation, image generation, and outreach message generation. Data is processed transiently and not retained by Google beyond the processing session per Google's API data processing terms; (3) OpenRouter — AI model routing for AI editing and image generation (including the FLUX image model and free-tier models). The content being edited (such as landing page HTML) and edit prompts are sent to OpenRouter for processing; (4) DeepSeek — AI inference for select generation and editing tasks; (5) OpenCode (opencode.ai) — agentic AI-assisted content editing; (6) Upstash — task scheduling (QStash) and caching (Redis); (7) Resend — email delivery, including welcome emails, the guided campaign, daily message digest, ecosystem announcements, and waitlist notification emails; (8) Vercel — hosting infrastructure with global CDN; (9) Google Analytics — anonymized usage analytics. All sub-processors maintain appropriate technical and organizational security measures.

International Data Transfers

Your primary data is stored in Supabase's EU-West region. However, data processing involves transfers to the United States through Google Cloud AI (Gemini), OpenRouter, Resend, Vercel, and Google Analytics. For transfers outside the European Economic Area, we rely on: Standard Contractual Clauses (SCCs) as approved by the European Commission; Transfer Impact Assessments (TIAs) where required; and contractual commitments with sub-processors to uphold GDPR standards. We continuously monitor legal developments regarding international data transfers.

Data Subject Rights (Articles 15–22 GDPR)

As an EU/EEA resident, you have the following rights: Right of Access (Article 15) — request a copy of your personal data we hold; Right to Rectification (Article 16) — correct inaccurate or incomplete data through your profile settings or by contacting us; Right to Erasure (Article 17) — request deletion of your data (right to be forgotten); Right to Restriction of Processing (Article 18) — limit how we process your data under certain circumstances; Right to Data Portability (Article 20) — receive your data in a structured, machine-readable format; Right to Object (Article 21) — object to processing based on legitimate interests, including the drip email campaign; Right to Withdraw Consent — for processing based on consent (optional profile fields), without affecting prior processing; Right to Lodge a Complaint — with your national supervisory authority. To exercise any of these rights, email support@startupblueprint.dev. We respond within 30 days (extendable by 60 days for complex requests). We do not charge for the first copy of your data. Many rights can be exercised directly through the platform (deleting sessions, solutions, messages; updating profile data).

Data Retention and Deletion

We retain personal data only as long as necessary for the stated purpose: Account data — retained while your account is active, deleted within 30 days of account deletion (backups retained for an additional 90 days); Discovery sessions, solutions, and all AI-generated content (PRDs, landing pages, translations, images, outreach messages) — retained until deleted by you or upon account deletion; Anonymous session data — retained only for a limited period to support session linking; Message history — retained until deleted by users or upon account closure; CRM contact records — retained until you delete them or close your account; Waitlist submissions — retained for the lifetime of the associated solution; Guided campaign email events — retained for the duration of the campaign sequence; Message-digest tracking markers — retained for 30 days; Bug reports and feature requests — retained for 2 years; Server and access logs — retained on a rolling basis for security monitoring; Aggregated and anonymized analytics data — may be retained indefinitely. You can delete specific content (sessions, solutions, CRM contacts, messages, generated documents) at any time through the platform.

Data Security Measures (Article 32 GDPR)

We implement appropriate technical and organizational measures pursuant to Article 32 GDPR: Encryption — TLS 1.2+ for all data in transit, AES-256 for data at rest via Supabase; Access Controls — Row Level Security (RLS) policies in PostgreSQL ensuring users can only access their own data, role-based access controls with a separate admin role; Authentication Security — bcrypt password hashing with salts for email/password accounts, secure OAuth 2.0 implementation via Supabase Auth for Google sign-in; Infrastructure Security — secure hosting via Vercel, regular security updates, firewall protection; Monitoring — security monitoring for intrusion attempts, audit logging; Data Minimization — anonymous session option, optional profile fields, minimal data collection per feature.

Automated Decision-Making and AI Processing (Article 22 GDPR)

Startup Blueprint uses AI extensively to generate content: Google Gemini models process your 8-question discovery interview to generate up to 4 business solution suggestions, PRDs, and landing pages. Google Gemini, DeepSeek, OpenRouter-hosted models, and OpenCode process your landing page HTML to apply AI-requested edits. Google-supported translation converts landing pages into over 200 languages. Google Imagen and a FLUX image model generate landing-page imagery. AI models generate outreach messages based on your solution data. This automated processing does not constitute automated decision-making with legal or similarly significant effects under Article 22 GDPR. All AI-generated content is informational and advisory only — you retain full control over whether to use, modify, or disregard any AI output. No automated profiling for marketing, creditworthiness, employment, or similar high-stakes purposes is performed. We do not use your data to train AI models.

Waitlist Data and Third-Party Visitors

When a visitor submits their email to join the waitlist for a publicly shared solution, we collect their email address, IP address, and browser user-agent under Article 6(1)(b) GDPR (performance of the waitlist service requested by the visitor). This data is stored in our EU-West database and associated with the relevant solution. The solution owner (a registered Startup Blueprint user) is notified and can view waitlist subscriber emails. Visitors who join a waitlist may exercise their right to erasure by contacting support@startupblueprint.dev. Solution owners who use waitlist data to contact subscribers are independently responsible for compliance with applicable email marketing laws (GDPR, CAN-SPAM, CASL) for those communications.

Email Marketing and Drip Campaigns

Upon account creation, we enroll registered users in a guided email campaign of up to 4 emails per stage across 5 stages (up to 20 emails total), paced by their progress in the platform, processed under Article 6(1)(f) GDPR (legitimate interests in helping users get value from the platform). When you have unread conversations, we may also send a daily message digest (maximum one per day, Article 6(1)(f) GDPR). You can withdraw from the campaign and the digest at any time from your profile under Email preferences; alternatively, you have the right to object to this processing by contacting support@startupblueprint.dev, and we will cease sending them. Transactional emails (welcome email, waitlist notifications, announcement emails) are processed under Article 6(1)(b) GDPR as part of the service. All emails are delivered via Resend.

Breach Notification (Articles 33–34 GDPR)

In the event of a personal data breach, we comply with Articles 33 and 34 GDPR: We will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to your rights and freedoms. If the breach poses a high risk to your rights and freedoms, we will notify affected individuals directly without undue delay. Notifications will include the nature of the breach, likely consequences, measures taken or proposed, and recommended steps for affected individuals. We maintain incident response procedures and conduct regular security assessments to minimize breach risks.

Children's Data

Startup Blueprint is not directed at children under 16 years of age (or the applicable age of digital consent in your EU member state). We do not knowingly collect or process personal data of children. If you believe we have inadvertently collected data from a child, contact us immediately at support@startupblueprint.dev, and we will delete such information without undue delay.

Data Protection Officer and Supervisory Authority

We do not currently have a designated Data Protection Officer, as we are not required to appoint one under Article 37 GDPR. All privacy and data protection inquiries are handled by our team at support@startupblueprint.dev. You have the right to lodge a complaint with your national data protection supervisory authority if you believe our processing of your personal data violates GDPR. A list of EU supervisory authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.

Need something else?

Email support@startupblueprint.dev