Privacy Policy

Last updated: 18 July 2026

1. Introduction

Compliance Copilot ("we", "our", "us") operates the website securemymvp.com and provides a SOC2 compliance automation platform for micro-SaaS teams. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services.

2. Information We Collect

We collect information you provide directly and information collected automatically:

Personal information you provide:

  • Email address (for account creation and magic-link sign-in)
  • Name (optional, derived from email or provided by you)
  • Billing information (processed by Stripe; we never see your card number)
  • Policies, evidence files, and checklists you upload
  • Support communications when you contact us

Information collected automatically:

  • IP address and approximate geolocation (from request headers)
  • Browser type, device type, operating system
  • Pages visited, time spent, referring URL (via privacy-friendly analytics)
  • Cookies (essential only — see section 5)

3. How We Use Your Information

We use your information to:

  • Provide and maintain the Compliance Copilot service
  • Send you magic-link sign-in emails
  • Process subscription payments via Stripe
  • Send important service updates (security incidents, policy changes)
  • Send marketing emails only with your explicit consent (waitlist signup)
  • Improve our platform through aggregated, anonymized analytics
  • Detect and prevent fraud, abuse, or security incidents
  • Comply with legal obligations

4. AI-Generated Content

Our AI Policy Generator uses third-party language models, routed through OpenRouter and its downstream model providers, to draft policies based on your prompts. If OpenRouter is unavailable and a fallback is configured, Anthropic may process the request directly. Your prompts and generated policies are processed by these providers under their data processing agreements. We do not use your content to train AI models. Generated content remains your property.

5. Cookies

We use only essential cookies required for authentication (NextAuth session cookies) and CSRF protection. We do not use advertising or cross-site tracking cookies. We may use privacy-friendly analytics (e.g., Plausible) that do not require consent banners.

6. Data Sharing

We never sell your personal data. We share data only with vetted sub-processors necessary to operate our service:

  • Stripe — payment processing (PCI-DSS Level 1)
  • Lemon Squeezy — payment fallback (Merchant of Record)
  • Railway — hosting infrastructure (PostgreSQL, server)
  • Resend / SMTP provider — transactional email
  • OpenRouter and downstream model providers — primary AI policy generation
  • Anthropic — optional direct fallback for AI policy generation
  • Vercel/Railway CDN — static asset delivery

We may also disclose information when required by law, to protect our rights, or in connection with a business transfer (acquisition, merger). We will notify you of any such disclosure where legally permitted.

7. Data Retention

We retain your account data for as long as your account is active. If you cancel your subscription, your data is retained for 30 days then permanently deleted, unless you request earlier deletion. You can request data export or deletion at any time by emailing privacy@securemymvp.com.

8. Your Rights (GDPR & CCPA)

If you are in the EU/EEA, UK, or California, you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data ("right to be forgotten")
  • Object to or restrict processing
  • Data portability (export your data in machine-readable format)
  • Withdraw consent at any time (for marketing communications)
  • Lodge a complaint with your local data protection authority

To exercise any of these rights, email privacy@securemymvp.com. We respond within 30 days.

9. Security

We implement industry-standard security measures:

  • HTTPS-only with HSTS preload
  • Content Security Policy (CSP) headers
  • Rate-limiting on all API endpoints
  • Hashed magic-link authentication tokens
  • Encrypted database backups
  • Quarterly security review

We practice what we preach: our own SOC2 compliance journey is documented in our public roadmap.

10. Children's Privacy

Our service is not intended for children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us for immediate deletion.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email (if you have an account) and by posting a notice on our website at least 14 days before changes take effect.

12. Contact Us

For privacy questions or to exercise your rights:
Email: privacy@securemymvp.com
Data Protection Officer: Maulky
Address: Available on request via email