Legal
Privacy Policy
Last updated: September 26, 2026
1. What we collect
- Whop account data: your Whop user ID, username, and email address when you sign in with Whop.
- Ideas and reports: the SaaS ideas you submit and the validation reports generated for you, stored so you can revisit them.
- Usage data: how many reports you run, to enforce the free daily limit.
2. What we do NOT collect
We never see or store your payment card details. All payments are processed by Whop. There is no guest mode, so we don't track anonymous visitors.
3. Third-party services
We rely on these processors to run TestMySaaS:
- Whop — authentication and payments. Your sign-in and checkout happen on Whop's infrastructure under their privacy policy.
- Groq — runs the AI analysis of your idea together with the research evidence.
- Tavily — performs the live web searches (competitor pages, market data, Reddit threads) that ground the report.
Your idea text is sent to these services solely to generate your report. We don't sell your data, and we don't use your ideas to train models.
4. Data retention & deletion
Reports are kept until you ask us to delete them. You can request full deletion of your account and all stored reports at any time by contacting us — we'll remove everything within 30 days.
5. Security
Sessions use signed, HTTP-only cookies. API keys are stored server-side only and never exposed to the browser.
6. Changes
If we change this policy materially, we'll update the date above. Continued use of TestMySaaS after changes means you accept the updated policy.