2. Data We Collect
- Account data: email address, name, and authentication data via Clerk.
- Usage data: analysis history, plan status, timestamps of analyses performed.
- Code submitted for analysis: processed to generate the analysis report. Not stored beyond the analysis session unless saved by the user.
- Payment data: processed by Paddle. We do not store card details.
- Technical data: IP address, browser type, usage logs for security and performance.
3. How We Use Your Data
- To provide and operate the JOptimize platform
- To manage your account and subscription
- To process payments and issue invoices
- To respond to support requests
- To improve the platform via anonymized analytics
- To comply with legal obligations
4. Legal Basis (GDPR)
- Contract performance: to provide the service you subscribed to
- Legitimate interest: security, fraud prevention, platform improvement
- Legal obligation: compliance with applicable laws
- Consent: for analytics cookies
5. Data Sharing
We do not sell your personal data. We share data only with:
- Clerk — authentication
- Paddle — payment processing and subscription management
- Railway — backend hosting
- Vercel — frontend hosting
- Anthropic (Claude) — AI analysis features (Pro plan only). No source code is sent — only issue metadata.
6. Data Retention
- Account data: retained while active and up to 2 years after deletion
- Analysis results: retained until you delete them
- Source code: not retained beyond the analysis session
- Payment records: retained for 10 years as required by law
7. Your Rights
Under GDPR and applicable laws, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict certain processing
- Data portability
Contact us at support@joptimize.io. We respond within 30 days.
8. Cookies
- Authentication cookies (Clerk) — strictly necessary
- Analytics cookies (Google Analytics) — anonymized usage data. You may opt out via browser settings.
9. Security
We implement industry-standard security measures including HTTPS encryption, secure authentication, and access controls. No system is 100% secure.