Conciply
Legal

Privacy Policy

Effective: June 2025 · Last updated: June 2025

1. Overview

Conciply ("we", "us", "the Service") is designed to be privacy-light by default. We do not require account creation. We do not sell, rent, or broker your data. This policy explains what limited information we collect, why we collect it, and how it is handled.

By using Conciply, you agree to the data practices described in this Privacy Policy.

2. Information We Collect

a) Business descriptions you submit
When you submit a business or idea for analysis, that text is transmitted to OpenAI's API to generate your growth playbook. This text is not stored on our servers after the API response is returned. You should not submit personally identifiable information, confidential trade secrets, or sensitive third-party data in your submissions.

b) IP address
We log your IP address solely for rate limiting (to enforce free plan limits) and abuse prevention. IP addresses are not linked to personal identities, are not shared with third parties (except as required by law), and are purged within 30 days.

c) Payment information
All payment processing is handled entirely by Stripe, Inc. We never receive, see, or store your full credit card number or sensitive payment details. Stripe may collect your billing name, email address, and payment method details. Their handling of this data is governed by the Stripe Privacy Policy.

d) License key
Your license key is stored in your browser's localStorage and is sent to our server with each API request to verify your subscription tier. We do not associate license keys with personal identity beyond what Stripe provides at checkout (email address used to purchase).

3. Report Storage

All generated reports, workspace edits, and notes are stored exclusively in your browser's localStorage. This data never leaves your device to our servers. As a result:

  • Clearing your browser data will permanently delete your reports.
  • Reports are not accessible from other devices unless you use the Restore feature.
  • We cannot retrieve, recover, or access your report data on your behalf.

4. OpenAI Data Processing

Conciply uses OpenAI's API to generate reports. When you submit a business description, that text is sent to OpenAI's servers for processing. By using Conciply, you acknowledge and accept that:

  • Your submitted text is transmitted to OpenAI and processed according to OpenAI's Privacy Policy.
  • OpenAI does not use API data to train their models by default (as per their API data usage policy).
  • Do not submit confidential information, trade secrets, personally identifiable information of third parties, or sensitive data.

5. Cookies and Tracking

Conciply does not use cookies, tracking pixels, advertising scripts, or third-party analytics services (including Google Analytics). The only browser storage we use is localStorage for your reports and license key — which stays on your device and is not accessible to us.

6. Data Sharing

We do not sell, rent, or share your personal data with third parties except in the following limited circumstances:

  • Stripe — to process subscription payments.
  • OpenAI — your submitted business description is sent to their API to generate reports.
  • Legal compliance — if required by law, court order, or governmental authority.
  • Business transfer — in the event of a merger, acquisition, or sale of assets, your data may be transferred. We will notify users via this page before any such transfer.

7. Data Retention

We retain server logs (IP addresses, request metadata) for up to 30 days for abuse prevention, after which they are deleted. Payment records are retained by Stripe in accordance with their legal and regulatory obligations. We hold no other personal data on our servers.

8. Children's Privacy

Conciply is not directed at or intended for use by individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has used the Service, please contact us at hello@conciply.com and we will take appropriate steps.

9. International Users — GDPR and CCPA

European Union (GDPR): If you are located in the EU or EEA, you have rights under the General Data Protection Regulation, including the right to access, correct, delete, or restrict processing of your personal data. Given that we hold minimal personal data (IP address for up to 30 days, and email via Stripe), most rights can be exercised by contacting us directly. Our legal basis for processing IP addresses is legitimate interest (rate limiting and abuse prevention).

California (CCPA): If you are a California resident, you have the right to know what personal information we collect, request deletion of that information, and opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact us at hello@conciply.com.

10. Security

We implement reasonable technical and organizational measures to protect the limited data we hold. All data transmitted between your browser and our servers is encrypted via HTTPS/TLS. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

11. Your Rights

You may contact us at any time to:

  • Request information about what data we hold related to you.
  • Request deletion of any personal data we hold.
  • Raise concerns about how your data is handled.

We will respond to all requests within 30 days. Since we hold minimal data, most requests are simple to fulfill.

12. Changes to This Policy

We may update this policy from time to time. The "Last updated" date at the top will reflect any changes. Continued use of the Service after changes are posted constitutes acceptance of the updated policy. For material changes, we will make reasonable efforts to provide notice.

13. Contact

Privacy questions or requests? Email us at hello@conciply.com. We aim to respond within 30 days.