Effective 2026-05-17
Privacy Policy
This is the plain-English version. Every processor we share data with is named below — no “we may share with third parties” without telling you who.
Who we are
Unlock SaaS is operated by Maryan. You can reach a human at maryan@unlocksaas.com.
What we collect, and why
- Email address — when you take the free diagnostic, sign up for the newsletter, or purchase. Used to send you the thing you asked for (diagnosis, email sequence, receipt, deliverables) and to support your account.
- The URL you submitto the diagnostic — passed to Anthropic’s Claude API so the model can read it and label the diagnosis. Stored in our database alongside the resulting label so we can show you the result and so you can refer back to it.
- Payment information — handled entirely by Stripe. We never see or store your card number. We do see the last four digits, the country, and a Stripe customer ID.
- Product analytics — anonymous-by-default page views and feature usage via PostHog. Used to know which surfaces actually work. Identified to your account only after you sign in.
- A/B variant cookies —
usaas_ab_identityandusaas_ab_subject. First-party, no third-party tracking, used to keep your version of the page stable across visits. Expire after one year. - Server logs— IP address and user-agent, retained by Vercel for the platform’s standard window. Used for abuse prevention and debugging.
Who processes your data
We use the following sub-processors. Each one only sees the slice of data described.
- Vercel — application hosting and server logs.
- Supabase — authentication and our primary database (your email, diagnosis label, account state).
- Stripe — all payment processing and subscription state.
- Resend — outbound transactional and sequence email.
- PostHog — product analytics.
- Anthropic — Claude API processes the URL you submit to the diagnostic and the text it returns. Anthropic does not train on API data by default.
We do not sell your data, and we do not share it with advertising networks.
How long we keep it
- Diagnostic submissions and labels: retained as long as your account exists, so you can refer back to them.
- Account data: retained as long as your account exists. Deleted on request, subject to legal retention requirements (e.g. Stripe tax/payment records).
- Server logs: retained per Vercel’s standard window (typically 30 days for application logs).
Your rights
You can ask us to show you what we have on you, correct it, export it, or delete it. Email maryan@unlocksaas.com and we will respond within 30 days. If you’re in the EU/EEA or UK, GDPR/UK-GDPR rights apply; if you’re in California, CCPA rights apply. We honor those everywhere by default.
Cookies and similar storage
The only cookies we set ourselves are the two A/B identity cookies listed above. Stripe sets cookies on its checkout pages. PostHog uses its own first-party storage; if you do not want product analytics, you can opt out from within the product or by emailing us.
Changes
If we add a new sub-processor or substantively change what we collect, we update this page and the effective date at the top. Material changes that affect existing customers also get an email.
Related: Terms of Service · About · Contact