GapStudy / Service information

Privacy

Updated 19 September 2026. This operational notice requires owner and legal review before paid launch. It is not a certification or a negotiated data-processing agreement.

Public website studies

GapStudy reads the public URLs you submit, plus a bounded set of same-site pages and explicitly selected competitors. It stores extracted public text, page structure, timestamps, content hashes, findings and report settings in Supabase. It does not request a prospect's login or connect private analytics.

Access and sharing

Signed-in studies belong to the authenticated account. Guest studies are accessed using an HTTP-only browser cookie that lasts 30 days. Clearing the cookie removes guest access. Reports are private until the owner creates a share link. Anyone who receives that link can read the included report until it is revoked.

Deletion and retention

Delete a finished study from its report to remove the stored record, evidence and share link. A minimal usage entry, without the website or report, keeps the free-study allowance from resetting on deletion. Account usage entries remain until account deletion. Guest usage entries older than 30 days are cleared when a subsequent study is created. Study records otherwise remain stored without a promised automatic expiry. Account-wide deletion and waitlist removal can be requested through support. Provider backups and security logs may have separate retention.

Security and analytics

Hashed network and account/browser identifiers support rate limiting. Admission-ledger entries older than 30 days are cleared during a subsequent scan admission; this is activity-triggered cleanup, not a scheduled deletion job. Existing first-party analytics may record page views and product events, excluding private and shared study paths. Operational logs record scan IDs, outcomes and counts, not raw website text or IP addresses.

Waitlist and providers

The waitlist stores your email and selected plan so the operator can send plan-access updates. No payment is collected by joining. Vercel hosts the service and Supabase provides authentication and database storage. The new scanner does not transmit page text to a language-model provider.

Your requests

Contact support to request access, correction or deletion of account or waitlist data. Applicable rights, operator legal details and provider agreements must be reviewed by the owner before paid launch.

Questions or data requests: hello@clientflow.app