Privacy Policy
How the SaaS Factory beta processes account, product, and first-party funnel data.
Beta notice: this policy describes the current SaaS Factory beta behavior. Operator identity, privacy contact, jurisdiction-specific rights, and any additional production subprocessors must be finalized before a broader commercial launch. This text is not legal advice.
Information you provide
We process account information such as your name, email address, authentication credentials, profile image, support messages, files you upload, API-key metadata, and billing identifiers. Product API keys created for end users are shown once and stored only as a cryptographic hash and readable prefix. An administrator may separately configure an external AI-provider credential for SaaS Factory; that credential is encrypted at rest and is never returned by the settings API after it is saved.
Information generated through use
The service may record session metadata, product activity, billing events, webhook identifiers, file metadata, waitlist position, referral information, and technical logs needed to secure and operate the service. SaaS Factory also records a bounded first-party product funnel so the operator can see where the beta experience fails: homepage visit, signup start/completion, idea submission, first successful build, successful Ask AI change, sharing, customer signup, first customer-data write, and a later builder return. The funnel does not store the idea text, email address, IP address, or user agent. Before signup it uses a random identifier scoped to the current browser session; after signup the event is associated with the account or generated product.
Infrastructure and subprocessors
Depending on configuration, data may be processed by:
- Cloudflare for Workers, D1, R2, KV, Email, and Workers AI;
- Stripe, Creem, or Waffo for payments;
- Resend, Cloudflare Email, or AWS SES for transactional email;
- Resend or Beehiiv for newsletters;
- configured analytics, chat, notification, and AI providers.
Only providers enabled by the operator receive the data required for that workflow.
Purpose and legal basis
We use data to provide and secure accounts, process purchases, deliver files and API access, respond to support, communicate service updates, prevent abuse, comply with law, and improve the product. Operators should document the legal bases that apply in their jurisdictions.
Retention and deletion
Account data is retained while an account is active and for the period required for security, tax, dispute, and legal obligations. SaaS Factory funnel events are retained for at most 90 days. Account deletion removes application database records through relational cascades and deletes owned R2 objects through the account-deletion workflow. Independent providers may retain records under their own legal obligations.
Your choices
You may update your profile, change email and password, revoke sessions, revoke API keys, manage billing through the selected provider, unsubscribe from newsletters, and request account deletion from the product settings.
Contact
Publish a valid privacy contact before launch and describe the process for access, correction, portability, objection, and deletion requests.