Privacy Policy
Last updated: March 28, 2026
1. Introduction
ChurnNote (“we”, “us”, “our”) operates the churnnote.com website and the ChurnNote SaaS application. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
2. Information We Collect
Account Information
- Name and email address (via Google OAuth sign-in)
- Profile picture (from your Google account)
Payment Provider Data
- Stripe or Lemon Squeezy API keys (encrypted at rest)
- Cancellation event data from your connected payment provider (customer email, name, subscription details)
Email Data
- Emails sent on your behalf to your cancelled customers
- Replies received from your cancelled customers
- Sender configuration (your name, email, company name)
Usage Data
- Log data (IP address, browser type, pages visited)
- Feature usage within the application
3. How We Use Your Information
- To provide and maintain the ChurnNote service
- To send exit emails to your cancelled customers on your behalf
- To capture and categorize customer replies
- To generate weekly digest reports for you
- To process your subscription payments via Lemon Squeezy
- To improve and optimize our service
- To communicate with you about your account
4. AI Processing
We use AI (OpenAI GPT-4o-mini) to generate personalized exit emails and to categorize customer replies. Your customer data is sent to OpenAI's API for processing. OpenAI does not use API data for training their models. We only send the minimum data necessary for email generation and categorization.
5. Data Storage and Security
- All data is stored in Supabase (hosted on AWS infrastructure)
- API keys are encrypted at rest in the database
- We use Row Level Security (RLS) to ensure users can only access their own data
- All connections use HTTPS/TLS encryption in transit
- We do not sell, rent, or share your data with third parties for marketing purposes
6. Third-Party Services
We use the following third-party services to operate ChurnNote:
- Supabase — Authentication and database hosting
- Vercel — Application hosting and deployment
- Resend — Email sending and inbound email processing
- OpenAI — AI email generation and reply categorization
- Lemon Squeezy — Subscription billing for ChurnNote
- Stripe / Lemon Squeezy — Your connected payment provider (for reading cancellation data)
Each third-party service has its own privacy policy governing their use of data.
7. Data Retention
We retain your account data and cancellation history for as long as your account is active. If you delete your account, we will delete your data within 30 days. Webhook event logs are retained for 90 days for debugging purposes.
8. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Export your cancellation data
- Disconnect your payment provider at any time
- Cancel your ChurnNote subscription at any time
9. Cookies
We use essential cookies for authentication and session management. We do not use advertising or tracking cookies. See our Cookie Policy for details.
10. Children's Privacy
ChurnNote is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the “Last updated” date.
12. Contact Us
If you have any questions about this Privacy Policy, please contact us at privacy@churnnote.com.