Privacy Policy

Last updated: September 1, 2026

1. Information We Collect

When you create an account, we collect your email address and a hashed password. When you use Leakage Finder, we process the CSV files you upload to perform billing reconciliation. We also collect basic usage data such as page views and product interaction events to improve the product. Public proof pages may also ask for an optional one-click answer about what is preventing the next self-serve step.

2. How We Use Your Data

  • Reconciliation — Your uploaded CSV files are parsed in the browser. Only the normalized client, product, quantity, and pricing fields needed for the audit are sent over TLS to our authenticated server for matching. Saved reconciliation results are stored in your account; the raw files are not retained as uploads.
  • Optional AI review — If you choose to run AI review, we send the client and product names from the flagged rows and candidate PSA lines to Google Gemini or the configured OpenAI-compatible model provider to generate suggested matches and short explanations. We do not include quantities, prices, dollar amounts, raw CSV files, passwords, or payment data in that AI request. AI output is guidance and should be reviewed before making a billing change.
  • Authentication — Your email and password are used solely to authenticate you. Passwords are hashed and never stored in plain text.
  • Billing — If you subscribe to a paid plan, payment is processed by Stripe. We do not store your credit card number. Stripe's privacy policy applies to payment data.
  • Product improvement — Privacy-filtered analytics on public marketing pages help us understand page flow and product interest. Anonymous blocker answers help prioritize export support, privacy explanations, setup guidance, proof, and missing features. We do not sell your data to third parties.

3. Data Storage & Security

Your data is stored in Supabase with row-level security (RLS) and restricted database grants. Audit data and canonical billing entitlements are accessed through authenticated server endpoints, and each query is scoped to the signed-in account. All connections use TLS encryption. Saved audit history is stored as structured results; the app does not retain raw uploaded CSV files as file uploads after processing.

If you create a read-only recovery-report link, the link can expose selected structured findings, quantities, recovery owners, and notes to anyone who has it. New links expire after 30 days and can be revoked from the account that created them. Do not share a link with anyone who should not see that report.

4. Data Sharing

We do not sell, rent, or share your personal data with third parties except as required to operate the service:

  • Supabase — Database and authentication provider
  • Stripe — Payment processing for paid plans
  • Vercel — Hosting, infrastructure, and product analytics delivery
  • Cloudflare Turnstile — Strictly necessary anti-abuse verification on sign-up, sign-in, and password-reset forms; Cloudflare may process IP, browser, and challenge telemetry to distinguish people from bots
  • AI model provider Google Gemini or the configured OpenAI-compatible model provider, only when you explicitly run the optional AI review described above

5. Your Rights

You may at any time:

  • Request a copy of your stored data
  • Request deletion of your account and all associated data
  • Update your email address or password

To exercise these rights, contact us at support@leakagefinder.com.

6. Cookies and Analytics

We use essential cookies for authentication session management. We do not use advertising cookies. We do use privacy-conscious analytics tools on public marketing pages to understand page views and non-sensitive product-interest milestones such as CTA clicks. A random browser identifier stored locally for up to 30 days lets us count distinct funnel steps without using an email, account ID, client name, or billing record. The server stores only a one-way hash of that random identifier with coarse event and campaign fields.

Automatic page-view and performance monitoring is disabled on authentication, dashboard, audit history, billing, growth, payment, recovery-report, and shared-audit routes. Explicit self-serve milestones on those routes may still be recorded with a strict allowlist of coarse fields so we can locate onboarding failures without recording account or audit contents.

We do not send uploaded CSV contents, client names, billing rows, filenames, email addresses, or other sensitive operational data to analytics tools or first-party conversion records.

7. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email to registered users. Continued use of the service after changes constitutes acceptance.

8. Contact

Questions about this policy? Email support@leakagefinder.com.