Legal

Privacy Policy

At Startup Blueprint, we are committed to protecting your privacy and being transparent about how we collect, use, and safeguard your information. This Privacy Policy explains our data practices for the Startup Blueprint platform.

Last updated: February 20, 2026

Information We Collect

We collect information in the following categories: (1) Account Data — email address, password hash (bcrypt), OAuth provider ID and tokens when you sign in with Google, plan status and subscription identifiers (only populated if you purchase a paid plan), and email preferences; (2) Profile Data — display name (required), profile photo, and optionally bio, location, company, role, interests, website URL, LinkedIn URL, and GitHub username; (3) Discovery & AI Session Data — your 8-question interview responses, conversation history, AI-generated business solutions (title, summary, pain points, ICP, business model, TAM/SAM/SOM, go-to-market plan, feature lists), generated PRDs, landing page HTML in English and translated versions in over 200 languages, generated landing-page imagery, design configuration, outreach messages, and AI token usage metrics (model, provider, token counts, latency); (4) Messaging Data — content of messages, replies, read receipts, and conversations between users; (5) CRM Data — contact records you create for outreach (name, company, email, phone, social handles, outreach copy and stage) for your solutions; (6) Announcement Data — workspace and group announcements, their senders, and read status; (7) Waitlist Submissions — email address, IP address, and browser user-agent of visitors who join a public solution's waitlist; (8) Feedback Data — bug reports and feature requests including description, page URL, email, and user-agent; (9) Contact Sales Data — email address, inquiry type and category, expected member count, and indicative budget; (10) Technical & Usage Data — IP address, browser type, device information, session timestamps, message-digest tracking markers, and feature interaction patterns collected via cookies and server logs.

How We Use Your Information

Your information is used to: (1) Power the AI-driven discovery chat, business solution generation (up to 4 solutions per session), PRD generation, and landing page generation using Google Gemini models — and, depending on the task and your selection, DeepSeek or OpenRouter-hosted models; (2) Enable AI editing of landing pages and other content via OpenRouter-hosted models (including DeepSeek and OpenCode, an agentic coding service); (3) Generate landing-page imagery using Google Imagen and a FLUX image model (black-forest-labs/flux.2-klein-4b); (4) Translate landing pages into over 200 languages using Google-supported translation; (5) Generate AI-powered outreach messages based on your solution data; (6) Manage your account, authentication, session continuity, and email preferences (including linking anonymous sessions to your permanent account when you sign up); (7) Enable direct messaging, collaboration, CRM outreach tracking, and ecosystem announcements; (8) Publish your public project landing pages and share solutions with collaborators; (9) Send transactional and product emails via Resend — welcome email, a guided email campaign (up to 4 emails per stage across 5 stages, paced by your progress in the product), waitlist sign-up notifications, ecosystem announcement emails, and a daily digest of unread conversations (maximum one digest per day); (10) Notify solution owners when someone joins their waitlist; (11) Notify administrators of bug reports, feature requests, and contact sales inquiries; (12) Analyze usage patterns to improve the platform; and (13) Comply with legal obligations.

AI Processing and Third-Party AI Services

Startup Blueprint uses multiple AI services to power its features. Google Gemini models (including the gemini-2.5 and gemini-3.x flash, flash-lite and pro families) via Google Cloud AI are used for the discovery chat interview, business solution generation, PRD generation, landing page HTML generation, landing page translation, and outreach message generation. Google Imagen is used to generate landing-page imagery. DeepSeek and OpenRouter-hosted models (including free-tier models from various providers and the FLUX image model black-forest-labs/flux.2-klein-4b) are used for AI editing and additional generation tasks, and OpenCode (an agentic coding service) is used for AI-assisted editing. Your discovery responses, solution data, and landing page HTML are sent to these services for processing. Google Cloud AI processes data transiently and does not retain it beyond the processing session per Google's API terms. OpenRouter, DeepSeek, and OpenCode requests include the content being generated or edited (such as landing page HTML and edit prompts). The mix of specific models may change over time. We do not use your data to train AI models. The AI-generated content is stored in our database and associated with your account.

Email Communications

When you create an account, we send a welcome email via Resend. We also enroll you in a guided email campaign that sends up to 4 emails per stage across 5 stages (up to 20 emails total), paced by your progress in the product — an automated scheduler sends these while you remain in a stage. If you have unread conversations, we may send a daily message digest (maximum one per day); ecosystem announcement emails and waitlist sign-up notifications are sent as events occur. All emails are sent from our domain via Resend. You can manage your email preferences (including the guided campaign and the daily digest) at any time from your profile under Email preferences, or by contacting us at support@startupblueprint.dev. Transactional emails related to your account (welcome, security, waitlist notifications) cannot be opted out of while your account is active.

Waitlist Data

When a visitor submits their email to join the waitlist for a publicly shared solution on a project landing page, we collect their email address, IP address, and browser user-agent. This data is stored in our database and associated with the relevant solution. The solution owner is notified of new waitlist signups and can view the list of subscriber emails in their dashboard. Waitlist data is retained for as long as the associated solution exists. Visitors who join a waitlist may contact us at support@startupblueprint.dev to request removal of their email from a waitlist.

Anonymous Users and Session Linking

When you visit Startup Blueprint without an account, we may create a temporary anonymous session via Supabase Auth. Anonymous users can complete the discovery chat and have their session data temporarily stored. If you sign up or log in during or after an anonymous session, your anonymous discovery sessions and solutions are automatically migrated and linked to your new permanent account. Anonymous session data that is never linked to an account is retained only for a limited period before removal. Once linked, the data is subject to the retention policies for registered accounts.

Data Sharing and Third-Party Services

We share your data with the following trusted service providers: (1) Supabase — authentication, database hosting in the EU-West region, with AES-256 encryption at rest and TLS 1.2+ in transit, and Row Level Security policies; (2) Google Cloud AI — Gemini and Imagen models for transient AI inference (discovery chat, solution generation, PRD generation, landing page generation, image generation, translation, outreach); (3) OpenRouter — AI inference for AI editing and image generation using various hosted models (including FLUX and free-tier models); (4) DeepSeek — AI inference for select generation and editing tasks; (5) OpenCode (opencode.ai) — agentic AI-assisted content editing; (6) Resend — transactional, campaign, digest, and notification email delivery; (7) Upstash — task scheduling (QStash) and caching (Redis); (8) Vercel — hosting infrastructure with global CDN; (9) Google Analytics — anonymized usage analytics. We do not sell your personal information to third parties. Administrators of Startup Blueprint have elevated access to all user data for support and moderation purposes.

Cookies and Local Storage

We use essential cookies for authentication (Supabase auth tokens) and session management. These are strictly necessary for the platform to function. We use browser local storage to save your pending chat input and user interface preferences. With your consent, we use Google Analytics to collect anonymized usage data including page views, session duration, and feature interactions. You can control cookies through your browser settings or our cookie banner, but disabling essential cookies will prevent you from using authenticated features. Disabling analytics cookies will not affect platform functionality.

Data Retention

We retain data as follows: Account data — retained while your account is active, deleted within 30 days of account deletion (backups retained for an additional 90 days); Discovery sessions and solutions (including generated HTML, PRDs, images, and all AI-generated content) — retained until deleted by you or until account deletion; Anonymous session data — retained only for a limited period to support session linking; Message history — retained until deleted by users or upon account closure; CRM contact records — retained until you delete them or close your account; Waitlist submissions — retained for the lifetime of the associated solution; Guided campaign email events — retained for the duration of the campaign sequence; Message-digest tracking markers — retained for 30 days; Bug reports and feature requests — retained for 2 years; Server and access logs — retained on a rolling basis for security monitoring; Aggregated and anonymized analytics data — may be retained indefinitely.

Your Rights and Choices

You have the right to access, update, or delete your personal information through your profile settings. You can delete individual discovery sessions, solutions, messages, and generated documents directly from the platform. You may request full account deletion by contacting support@startupblueprint.dev, which will remove your personal data within 30 days (backups retained for an additional 90 days). You can download your generated landing pages and documents at any time. Waitlist visitors may request removal of their email from a specific waitlist by contacting us. For EU residents, additional rights are detailed in our GDPR Notice.

Security

We implement industry-standard security measures including: TLS 1.2+ encryption for all data in transit; AES-256 encryption for data at rest via Supabase; bcrypt password hashing with salts for email/password accounts; Row Level Security (RLS) policies in our PostgreSQL database ensuring users can only access their own data; role-based access controls with a separate admin role; secure OAuth 2.0 implementation via Supabase Auth for Google sign-in; and regular security monitoring. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

Children's Privacy

Startup Blueprint is not intended for users under the age of 16. We do not knowingly collect personal information from children under 16. If you believe we have collected information from a child under 16, please contact us immediately at support@startupblueprint.dev, and we will delete such information without undue delay.

International Data Transfers

Your primary data is stored in Supabase's EU-West region. However, data processing may involve transfers to the United States through Google Cloud AI (Gemini), OpenRouter, Resend, and Vercel infrastructure. For transfers outside the European Economic Area, we rely on Standard Contractual Clauses (SCCs) as approved by the European Commission and contractual commitments with sub-processors to uphold applicable data protection standards.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the "Last Updated" date. For significant changes, we may also notify you by email. Your continued use of Startup Blueprint after changes are posted constitutes acceptance of the updated policy.

Questions or Concerns?

If you have any questions about this Privacy Policy or our data practices, please contact us at support@startupblueprint.dev