Privacy Policy
Last updated: September 27, 2026
This policy describes how Gaplume handles information when you create an account, analyze websites, or contact support.
Information we use
- Account information: your name, email address, authentication credentials handled by Supabase, and account status.
- Project information: website and competitor URLs, target market, goals, and report settings.
- Research records: collected public page excerpts and metadata, analysis reports, recommendations, task statuses, and provider usage information.
- Billing information, when paid billing is enabled: provider customer and subscription identifiers, plan, payment status, billing period, and verified billing events. Card details are entered on the payment provider’s checkout rather than stored by Gaplume.
- Operational information: activity events, support requests, and information needed to enforce account limits and prevent abuse.
How AI processing works
When you start an analysis, public page content and the project context you supply are sent to OpenRouter and the selected AI model provider. Questions and saved report content are sent for report chat; relevant saved findings are used for brief generation. Their processing is subject to their applicable terms and privacy policies. Please do not submit confidential information, passwords, API keys, or personal data about other people.
Our service providers
Gaplume uses Vercel for website hosting, Supabase for account authentication and database storage, Amazon SES to deliver authentication emails from noreply@gaplume.app, and OpenRouter to access AI models. When paid billing is enabled, FastSpring processes payment information and sends subscription updates to Gaplume. The provider’s identity and payment details appear at checkout. These services may process data in locations outside your country. Authorized administrators can access account, research, activity, and support records to operate the service.
Cookies and browser storage
Authentication cookies keep you signed in and protect your session. Your light or dark theme preference is saved in this browser. We do not use that preference to track you across websites. Report chat questions and answers are stored with your account activity so you can return to the conversation. Relevant requests and processing records are also handled by our service providers.
Use and retention
We use your information to provide research, save your work, enforce quotas, handle support, and keep the service working. Your saved projects and reports remain available until removed or an account deletion request is processed. Operational records and provider backups may remain where needed for security, service operation, or applicable requirements.
Your choices
You can update your name in Settings, export saved reports, and delete projects and their associated research. For account deletion or a privacy request, use Help & support in your workspace. Confirm your identity through your account before requesting changes to private data.
Public website content
We analyze accessible public pages within a bounded crawl. Public availability does not remove the rights of website owners. Only provide websites and information you are entitled to use for your research.
Changes to this policy
We may update this policy as the service changes. The date above identifies the latest version.