At Speedflow (“we”, “us”, or “our”), we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our website https://speedflow.cc (the “Website”) and our services (the “Services”). This Privacy Policy is issued in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation - “GDPR”) and applicable Polish data protection laws. It describes your data protection rights, including the right to object to some processing that we carry out. BETA/MVP NOTICE: As Speedflow is currently in beta/MVP stage, our data practices may evolve. We will notify you of any material changes to this Privacy Policy that affect how we handle your personal data. If you do not agree with this Privacy Policy, please do not use our Website or Services.
1. Data Controller
The data controller responsible for your personal data is an individual developer operating Speedflow, based in Poland. Contact information: Email: info@speedflow.cc
2. What Personal Data We Collect
“Personal Data” means any information relating to an identified or identifiable natural person. We collect and process the following categories of personal data:
2.1 Account and Authentication Data
When you create an account, we collect:
- (a) Email address - used for account creation, authentication, and communication;
- (b) Password - stored in hashed form by Supabase (our authentication provider), we never see or store your plain text password;
- (c) Name and profile information - if you sign in using Google OAuth, we receive your name and profile picture from Google. Legal basis: Performance of contract (Article 6(1)(b) GDPR) - necessary to provide you with access to our Services.
2.2 Website Analysis Data
When you use our Services to analyze websites:
- (d) Website URLs you submit for analysis - processed in real-time and NOT STORED on our servers. Analysis results are displayed to you but not retained after your session ends. Legal basis: Performance of contract (Article 6(1)(b) GDPR) - necessary to provide the analysis service you requested.
2.3 Payment and Billing Data
If you subscribe to a paid plan, payment processing is handled entirely by Paddle.com, our payment processor and Merchant of Record:
- (e) Billing information (name, address, tax ID if applicable) is collected and stored by Paddle, not by us;
- (f) Payment card information is processed directly by Paddle. We never have access to or store your card details;
- (g) Transaction records - we receive confirmation of successful payments from Paddle to activate your subscription. Legal basis: Performance of contract (Article 6(1)(b) GDPR) and compliance with legal obligations (Article 6(1)(c) GDPR) for tax and accounting purposes.
2.4 Usage and Technical Data
We automatically collect certain technical information when you use our Website:
- (h) Device information: IP address, browser type and version, operating system, device type;
- (i) Usage data: pages visited, features used, time spent, clicks, scrolling behavior (via Hotjar);
- (j) Session data: authentication tokens (stored as cookies) to keep you logged in. Legal basis: Legitimate interests (Article 6(1)(f) GDPR) - to understand how users interact with our Services, improve functionality, fix bugs, and enhance user experience.
3. How We Use Your Personal Data
We use your personal data for the following purposes:
- (k) Service Provision: To create and manage your account, authenticate you, and provide website analysis services;
- (l) Communication: To send you service-related emails (account verification, password resets, subscription confirmations, important updates to our Terms or Privacy Policy);
- (m)Product Improvement: To analyze usage patterns, identify bugs, and improve our Services (via analytics tools);
- (n) Security: To detect and prevent fraud, abuse, and security incidents;
- (o) Legal Compliance: To comply with applicable laws, regulations, and legal processes.
4. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to provide and improve our Services. A cookie is a small text file stored on your device that helps us remember your preferences and understand how you use our Website.
4.1 Types of Cookies We Use
| Cookie Type | Provider | Purpose |
|---|---|---|
| Essential Cookies | Supabase | Session management and authentication. Required for the Website to function. These cookies remember you’re logged in as you navigate between pages. |
| Analytics Cookies | Posthog | Product analytics to understand user behavior, feature usage, and conversion funnels. Helps us improve the product based on real usage data. |
| More info: https://posthog.com/privacy | ||
| Hotjar | Heatmaps and session recordings to visualize how users interact with pages (where they click, scroll, move their mouse). Helps identify UX issues. More info: https://www.hotjar.com/legal/policies/privacy/ | |
| Note: Essential cookies are necessary for the Website to function and cannot be disabled. Analytics cookies require your consent and can be controlled through your browser settings or our cookie banner. |
4.2 Managing Cookies
You can control and manage cookies through your browser settings. Most browsers allow you to:
- (p) View cookies stored on your device;
- (q) Delete cookies;
- (r) Block cookies from specific websites or all websites. Browser-specific cookie management:
- (s) Google Chrome: https://support.google.com/chrome/answer/95647
- (t) Mozilla Firefox: https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer
- (u) Safari: https://support.apple.com/guide/safari/manage-cookies-sfri11471/mac
- (v) Microsoft Edge: https://support.microsoft.com/en-us/microsoft-edge/delete-cookies-in-microsoft-edge-63947406-40ac-c3b8-57b9-2a946a29ae09 Important: Blocking essential cookies will prevent you from using core features of our Website, including logging in and using the analysis tools.
5. Sharing Your Personal Data with Third Parties
We do not sell, rent, or trade your personal data. However, we share your data with the following trusted third-party service providers who help us operate our Services:
5.1 Service Providers
- (w) Supabase (EU servers) - Authentication, database, and backend infrastructure. Stores your account credentials securely. Privacy Policy: https://supabase.com/privacy
- (x) Paddle.com - Payment processing and billing (Merchant of Record). Handles all payment transactions, billing information, and tax compliance. Based in the UK/USA. Privacy Policy: https://www.paddle.com/legal/privacy
- (y) Vercel / GitHub - Website hosting and content delivery. Privacy Policy: https://vercel.com/legal/privacy-policy
- (z) Posthog - Product analytics. Privacy Policy: https://posthog.com/privacy
- (aa) Hotjar - User behavior analytics (heatmaps, session recordings). Privacy Policy: https://www.hotjar.com/legal/policies/privacy/
- (bb) Railway - Cloud infrastructure and backend service hosting. Used to run server-side analysis processes (e.g., Puppeteer-based page rendering). Data processed includes website URLs submitted for analysis, which are not stored. Privacy Policy: https://railway.com/legal/privacy
- (cc) Google Gemini AI (Google LLC) - AI-powered suggestion generation. When you request AI-based recommendations (e.g., meta tag or schema suggestions), relevant page metadata is sent to Gemini API for processing. This data is not stored by us after the response is returned. Privacy Policy: https://policies.google.com/privacy
- (dd) Upstash - Serverless rate limiting and caching infrastructure. Used to enforce API usage quotas and protect against abuse. May process IP addresses and request metadata for rate limiting purposes. Privacy Policy: https://upstash.com/trust/privacy.pdf
5.2 Data Transfers Outside the EU
Some of our service providers are based outside the European Union:
- (ee) Paddle operates in the UK and USA. They comply with GDPR and use Standard Contractual Clauses for data transfers;
- (ff) Google, Vercel, and other providers may process data in the USA or other countries. They are certified under the EU-US Data Privacy Framework and/or use Standard Contractual Clauses.
- (gg) Railway may process data outside the EU. They use Standard Contractual Clauses and implement appropriate safeguards for international transfers. We ensure that all third parties provide adequate safeguards for your personal data in accordance with GDPR requirements.
5.3 Legal Obligations
We may disclose your personal data if required by law, court order, or governmental authority, or to protect our rights, property, or safety, or that of others.
6. How Long We Keep Your Data
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
- (hh) Account data: Retained while your account is active. If you delete your account, we delete your personal data within 30 days, except where we must retain it for legal or accounting purposes (up to 5 years for tax compliance);
- (ii) Website analysis data: NOT STORED - analyzed in real-time and discarded immediately after displaying results to you;
- (jj) AI suggestion data: Metadata sent to Gemini AI for suggestion generation is not stored by us after the response is returned;
- (kk) Usage and analytics data: Retained for up to 26 months to identify trends and improve our Services;
- (ll) Payment records: Stored by Paddle for the duration required by tax and accounting laws (typically 5-7 years).
7. How We Protect Your Data
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, or misuse:
- (mm) Encryption: All data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security);
- (nn) Password security: Passwords are hashed using industry-standard algorithms and never stored in plain text;
- (oo) Access controls: Only authorized personnel have access to systems containing personal data;
- (pp) Infrastructure security: We use enterprise-grade cloud providers (Supabase, Vercel, Railway) with SOC 2 Type II compliance and regular security audits. Important: While we take reasonable precautions, no method of transmission or storage is 100% secure. As a beta/MVP product, our security measures are continually evolving. Please report any security concerns to info@speedflow.cc immediately.
8. Your Data Protection Rights
Under GDPR and Polish data protection law, you have the following rights regarding your personal data:
- (qq) Right of Access (Article 15 GDPR): You can request a copy of the personal data we hold about you;
- (rr) Right to Rectification (Article 16 GDPR): You can correct inaccurate or incomplete personal data;
- (ss) Right to Erasure (Article 17 GDPR): You can request deletion of your personal data (“right to be forgotten”), subject to certain legal exceptions;
- (tt) Right to Restriction of Processing (Article 18 GDPR): You can request that we limit how we use your data in certain circumstances;
- (uu) Right to Data Portability (Article 20 GDPR): You can receive your personal data in a structured, commonly-used, machine-readable format;
- (vv) Right to Object (Article 21 GDPR): You can object to processing based on legitimate interests;
- (ww) Right to Withdraw Consent: Where we process data based on your consent (e.g., analytics cookies), you can withdraw consent at any time without affecting prior processing. How to exercise your rights: To exercise any of these rights, contact us at info@speedflow.cc. We will respond within 30 days of receiving your request. You also have the right to lodge a complaint with your local data protection authority if you believe we have violated your privacy rights. In Poland, this is the Personal Data Protection Office (UODO): https://uodo.gov.pl/
9. Children’s Privacy
Our Services are not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us immediately, and we will take steps to delete such information.
10. Changes to This Privacy Policy
As Speedflow is a beta/MVP product, we may update this Privacy Policy more frequently than a mature product. We will notify you of material changes by:
- (xx) Sending an email to your registered email address;
- (yy) Displaying a prominent notice on our Website. We encourage you to review this Privacy Policy periodically. The “Last updated” date at the top indicates when changes were last made. Continued use of our Services after changes constitutes acceptance of the updated Privacy Policy.
11. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please contact us: Email: info@speedflow.cc Response time: We aim to respond to all inquiries within 5 business days. * * * Thank you for trusting Speedflow with your data. We are committed to protecting your privacy and handling your personal data responsibly.