Information we process
We process submitted product URLs, extracted public website information, confirmed product details and edits, search queries, progress, results, source posts, public founder handles, and generated comparisons. For signed-in use, records are associated with a Clerk account identifier. Clerk manages account authentication and the account information you provide to it.
An anonymous browser session is associated with a hashed session identifier. We store operational events such as feedback, opening comparisons, copying summaries, and requesting a watch. Payment records include account and scan identifiers, product, amount, currency, status, and Dodo checkout and payment identifiers. We do not store full card details. Hosting and service providers may process standard request and security logs.
Why we use this information
We use information to analyze products, find and rank matches, save and deliver reports, authenticate accounts, process purchases, provide support, prevent misuse, control provider costs, and understand service reliability and usefulness. Where applicable data protection law requires a legal basis, these purposes rely on providing the requested service, legitimate interests in operating and protecting it, and legal obligations for transaction records. Consent is used where required for an optional activity.
Public product index and private findings
Public website profiles and supporting public evidence may be stored in a reusable product index and used in other visitors’ searches. User-edited fingerprints are kept in the scan rather than copied into the shared public index. Account-linked scan history and paid reports are access-controlled. Public source information may already be available on X or the relevant website independently of SaaS Twin.
Service providers and AI processing
OpenAI receives product descriptions, public evidence, and relevant scan context for website analysis and report generation. When TypeSafe/Jev is configured, it receives relevant product and candidate information for screening and structured evaluation. Do not submit confidential or sensitive information in product fields.
Clerk provides authentication; Dodo Payments processes purchases, taxes, refunds, and disputes; X supplies public discovery evidence. Hosting and database providers store and process application data. Providers process data under their own applicable terms and privacy arrangements, which may include processing outside your country. We may disclose information when required by law, to protect the service and its users, or as part of a business transfer with appropriate safeguards. We do not sell account-linked scan histories or reports.
Cookies
Our twin_session cookie lasts up to 30 days and enables anonymous scan ownership and browser usage controls. Authentication and checkout providers may use their own cookies. The Cookies page explains these uses and browser controls. We also use Vercel Web Analytics for aggregate website traffic statistics without analytics cookies. Admin pages are excluded, and query strings and URL fragments are removed from analytics event URLs. Scan-related operational events are stored separately in our database.
Retention and security
We keep scans, profiles, and reports to provide saved access and reusable discovery. There is currently no automatic scan deletion schedule. Retention decisions consider account access, relevance of public profiles, support requests, security needs, legal obligations, and payment or dispute records. Financial and security records may need to be kept after other data is removed.
We use account and session ownership checks, authenticated report access, and verified payment events to limit access. No service can guarantee absolute security. Settings lets you delete saved app data or close your account. This removes owned scans, comparisons, reports, watches, and notifications from the live app database. Paid access to deleted reports is lost; deletion does not itself issue a refund. Account closure also removes your Clerk sign-in profile. Clerk profile deletions are synchronized through verified deletion events.
Deletion retains minimal transaction references for payment support and legal obligations, hashed deletion markers to prevent stale requests from restoring data, and daily usage counters for spending protection. Shared public website profiles are managed separately; contact us to request removal or correction. Information held independently by X, AI, payment, or hosting providers and backups is subject to their applicable retention cycles. Clearing cookies alone does not erase stored records and can prevent us from locating unclaimed scans without further verification.
Your choices and rights
Depending on applicable law, you may request access, correction, deletion, portability, restriction, or objection to processing, and withdraw consent for activities that rely on consent. Contact us with enough information to locate your account or record; we may verify ownership before acting. Some information may need to be retained for legal, security, or transaction obligations. You may also complain to the data protection authority where you live or work, where applicable.
If public product or founder information about you is inaccurate or should be removed, send the affected source or product URL through the Contact page. The service is not intended for children under 18. Contact us if you believe a child has submitted personal data.
Policy updates
We update this policy when our practices change and identify the revision date. Material changes will be communicated through an appropriate service channel. Operator and contact details are provided on the Contact page.
Contact
Operator: SaaS Twin.
For questions, support, or data requests, visit our Contact page.