Privacy Policy
Last updated: May 25, 2026
1. Who we are
MVP Generation Engine is operated by Truth J Blue ("Truth J Blue," "we," "us," or "our"). We operate the website at mvp.truthjblue.dev and the API at api-mvp.truthjblue.dev. Contact us at hello@truthjblue.dev.
2. What data we collect
- Account data — your email address (used for magic-link authentication via Supabase Auth) and an internal tenant ID.
- Payment data — collected and stored by Stripe. We receive only the Stripe customer ID, subscription ID, and metadata (tier, status, current period dates). We never receive or store your full card number, CVV, or bank credentials.
- API usage data — request timestamps, the API key used (only the hashed digest, never the raw key), endpoint hit, and per-request metadata you optionally send.
- Generation content — the intake you submit (niche, audience, transformation, optional notes) and the assets we generate from it. Stored in Supabase Storage with signed-URL access scoped to your account.
- Operational logs — application error logs, webhook delivery attempts, and Celery task records used for debugging and reliability.
3. How we use your data
- Provide and operate the API (generate assets, deliver webhooks, sign download URLs).
- Bill you correctly (per-generation usage events forwarded to Stripe's metered billing).
- Respond to support requests you initiate.
- Detect abuse, enforce rate limits, and investigate security incidents.
- Improve the service (aggregate usage analytics — we do not use your generation content to train models).
4. Third-party processors
We share data with the following sub-processors only as needed to deliver the service:
- Stripe — payment processing, billing, and invoicing. Stripe Privacy Policy.
- Supabase — authentication, Postgres database, and object storage. Supabase Privacy Policy.
- OpenAI — large language model inference for generation. Inputs are sent over TLS; OpenAI's API tier does not train on submitted content. OpenAI API data usage.
- Vercel — frontend hosting and edge delivery. Vercel Privacy Policy.
- Hostinger — VPS hosting for the API backend. Hostinger Privacy Policy.
We do not sell your personal data, and we do not share it with advertising or marketing networks.
5. Data retention
- Account data — retained while your account is active.
- Generated assets — retained while your account is active so you can re-download from the dashboard.
- Usage events & billing records — retained for 7 years for tax/accounting compliance, then deleted.
- Application logs — typically retained for 30 days, then rotated out.
If you delete your account, we delete your generated assets and account data within 30 days, except where retention is required by law (billing records as noted above).
6. Your rights
You can request the following at any time by emailing hello@truthjblue.dev:
- Access to the data we hold about you
- Correction of inaccurate data
- Export of your generated assets and account record
- Deletion of your account and associated data
- Restriction of processing or objection to specific uses
We respond within 30 days. If you're in the EU/UK, you also have the right to lodge a complaint with your local data protection authority.
7. Cookies
We use a minimal set of cookies, all functional: a Supabase Auth session cookie to keep you signed in, and Vercel platform cookies for routing. We do not use advertising, marketing, or cross-site tracking cookies.
8. Children
The service is not directed to children under 16. We do not knowingly collect data from children. If you believe a child has submitted data, contact us and we will delete it.
9. International transfers
Our sub-processors (Stripe, OpenAI, Vercel) may process data in the United States. By using the service, you consent to this transfer. We rely on standard contractual safeguards for cross-border data flows where applicable.
10. Changes to this policy
We will post material changes here with an updated "Last updated" date. For substantive changes affecting paid customers, we will also notify the email on file at least 14 days before the change takes effect.
11. Contact
Questions or requests: hello@truthjblue.dev.