Privacy Policy
Last updated: July 30, 2026
1. What we collect
- Account data — your e-mail address (magic link) and, if you sign in with Google, your name and avatar as provided by Google.
- Subscription data — your plan, subscription status, and Stripe customer and subscription identifiers. Card numbers never touch our servers — payment data is handled entirely by Stripe.
- Technical logs — standard server logs (IP, user-agent, timestamps) kept briefly for security and debugging.
The public performance pages contain no personal data — only market metrics.
2. Cookies
We use authentication session cookies only. No advertising cookies, no third-party analytics trackers.
3. Processors
- Supabase (EU region, eu-west-1) — database and authentication.
- Stripe — payments and subscription management.
- Vercel — website hosting.
- Hetzner (Germany) — data-collection server.
4. Purpose and legal basis
We process your data to provide the service (contract), to secure it (legitimate interest), and to meet accounting obligations (legal obligation). We do not sell or share personal data for advertising.
5. Retention
Account data is kept while your account exists and deleted upon account deletion, except what invoicing law requires us to retain. Technical logs are short-lived.
6. Your rights
Where GDPR applies you may request access, rectification, erasure, portability, or restriction of your personal data, and object to processing. Write to contact@mispria.com — we answer within 30 days. You may also lodge a complaint with your local supervisory authority.
7. Controller
The service is currently in its test phase; the legal entity acting as data controller will be stated here before paid subscriptions open commercially. Contact: contact@mispria.com.