Privacy Policy
Last updated: June 10, 2026
This Privacy Policy explains how BuildMyFunnel (“BuildMyFunnel, ” “we,” “us”) collects, uses, and protects information when you use buildmyfunnel.app and related services (the “Service”). By using the Service you agree to this Policy.
1. Information we collect
- •Account data. Your email address, authenticated through a one-time code (we never store a password), and the account/plan you belong to.
- •Project content. The briefs, descriptions, and inputs you provide, and the products and funnel assets the Service generates from them.
- •Billing data. Your subscription plan, status, and billing history. Card details are entered directly with our payment processor (Stripe) and are never stored on our servers.
- •Your AI provider key (BYOK). If you choose Bring-Your-Own-Key, your Anthropic API key is encrypted (AES-256-GCM) before storage and used only to run generations on your behalf. We never display it back to you in full and never log it in plain text.
- •Usage & technical data. Build counts, token/cost usage for metering and limits, timestamps, and standard server logs (IP, user agent) used for security and diagnostics.
2. How we use your information
- •To provide, operate, and secure the Service.
- •To generate the products and funnel assets you request.
- •To process subscriptions, enforce plan limits, and prevent abuse.
- •To send service emails (sign-in codes, billing, important notices).
- •To diagnose problems, improve reliability, and comply with law.
We do not sell your personal data, and we do not use your project content to train our own models.
3. Legal bases (EEA/UK users)
Where the GDPR applies, we process data to perform our contract with you (providing the Service), for our legitimate interests (security, abuse prevention, improving the Service), to comply with legal obligations, and with your consent where required.
4. Service providers (subprocessors)
We share data with the following processors only as needed to run the Service. Each is bound by its own data-protection terms:
- •Supabase — authentication, database, and file storage.
- •Anthropic — AI model inference (your briefs and generated content are processed to produce outputs).
- •Stripe — payment processing and subscription billing.
- •Vercel — application hosting and isolated build compute.
- •Resend — transactional email delivery.
5. AI processing
Generating a product or funnel sends your brief and intermediate content to Anthropic’s API to produce the result. In managed mode we call Anthropic with our key on your behalf; in BYOK mode we use your key. Anthropic processes this data under its own commercial terms and does not train its models on data submitted through its API.
6. Payments
Payments are handled by Stripe. We receive confirmation of your subscription status and the last four digits/brand of your card for reference, but we never receive or store full card numbers.
7. Data retention
We keep account, project, and billing data for as long as your account is active and as needed to provide the Service or meet legal/accounting obligations. You can request deletion of your projects or your entire account at any time (see “Your rights”). Encrypted BYOK keys are deleted when you remove them or close your account.
8. Your rights
Depending on your location, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise any of these, email contact@eugenpopa.com. We will respond within the timeframe required by applicable law.
9. Cookies
We use only essential cookies needed to keep you signed in and to keep the Service secure. We do not use advertising or cross-site tracking cookies.
10. Security
We use encryption in transit (HTTPS), encryption at rest for sensitive fields such as BYOK keys, strict access controls between accounts, and isolated compute per build. No method of transmission or storage is perfectly secure, but we work to protect your data using industry-standard measures.
11. International transfers
Our providers may process data in the United States and other countries. Where required, such transfers rely on appropriate safeguards (e.g. Standard Contractual Clauses) offered by those providers.
12. Children
The Service is intended for businesses and users aged 18 or older. We do not knowingly collect data from children.
13. Changes to this Policy
We may update this Policy from time to time. Material changes will be reflected by updating the “Last updated” date above and, where appropriate, by notifying you.
14. Contact
Questions about this Policy or your data? Email contact@eugenpopa.com.