← Back to home

Privacy Policy

Last updated 2026-09-15

What we collect

We keep data collection to a minimum:

  • Account info: your email address (for sign-in by one-time code).
  • Email signups: if you request a free resource or our email course, we store your email address and the fact that you consented to receive those emails. You can unsubscribe at any time.
  • Validation content: the ideas, scores, research, and notes you create inside Olune.
  • Consulting enquiries and email replies: if you send an enquiry from our consulting page, we store your name, your email, what you are deciding, any budget you typed, the page you came from and where your enquiry stands with us, in Supabase. Resend sends a copy of the enquiry to our inbox and a confirmation to you. Our inbox, hello@getolune.com, runs on Google Workspace, so that copy and any email you send us, including replies with money or household details you choose to share, are stored there. Please do not email us account numbers, statements or passwords. We keep enquiries and emails while we are in conversation with you and, if we work together, for as long as that work lasts. Ask us and we delete them (see Your rights).
  • Usage analytics: we use Google Analytics, Microsoft Clarity and PostHog to see how the site is used. Clarity records session replays and heatmaps of clicks, scrolls and mouse movement. Clarity masks what you type into form fields, we also mask the text of your ideas and results on the page, and we remove idea text from page addresses before these tools read them. One exception: the page title of a result you choose to make public includes its idea name. In some regions these tools wait for your choice before they store anything in your browser, and Clarity waits before it loads at all (see Cookies below).
  • Advertising measurement: we use the Meta (Facebook) pixel to measure our ads and to show ads to people who have visited the site. It sets advertising cookies and shares limited event data, such as page views, with Meta. When you submit a form, such as an email signup, we may also send Meta a hashed copy of your email so it can match the signup to an ad. Both only run when advertising is allowed under your choice (see Cookies below).
  • Operational logs: request metadata (URL, response status, duration) for debugging. Logs are retained 30 days.

What we do NOT collect

  • We don't sell your data, ever.
  • Capital Commitment Brief: the worksheet at /consulting/brief keeps your answers in the open page only. Nothing you type there is sent to us, saved or tracked, Clarity session replay does not record that page, and the Meta pixel does not load on it.
  • We don't train AI models on your validation content. Your ideas are sent to OpenRouter (the LLM provider) only to generate the response you see — they are not stored or used for training by us.

How we use your data

  • To provide the Olune product (sign-in, save your work, run AI requests).
  • To debug errors and improve reliability.
  • To understand which features people actually use, so we can prioritize fixes.

Sub-processors

We rely on the following infrastructure providers:

  • Supabase — database + authentication. Data hosted in their managed Postgres in their default region.
  • Vercel — hosting + serverless function execution.
  • Google Analytics (GA4): traffic and usage analytics. It sets analytics cookies only when analytics is allowed, and uses advertising signals only when advertising is allowed. Otherwise Google still receives cookieless page-view requests, which include your IP address, browser details and the page address.
  • Microsoft Clarity: masked session replays and heatmaps, only when analytics is allowed. Sets analytics cookies (for example _clck, _clsk) and Microsoft cookies such as MUID, which Microsoft uses for advertising, site analytics and other operational purposes. We tell Clarity whether advertising storage is allowed.
  • Meta (Facebook): advertising pixel and Conversions API, only when advertising is allowed. We share limited event data (such as page views, or a hashed email when you submit a form) to measure ad performance and reach people who have visited the site. Sets advertising cookies.
  • Resend: sends our email-course and transactional messages. Receives your email address if you sign up for a free resource or course. If you send a consulting enquiry, it also carries our copy of the enquiry (your name, email, what you are deciding and any budget you gave) and your confirmation email.
  • Google Workspace: hosts our hello@getolune.com inbox. Copies of consulting enquiries, and any email you send us, including replies to our confirmation email, are stored there.
  • OpenRouter — routes LLM requests to underlying model providers (Anthropic, OpenAI). Per OpenRouter's policy, your prompts pass through but are not stored beyond what's required for the response.
  • Serper / DataForSEO — third-party APIs that power the keyword and community research agents. We send your idea title / target keywords to these providers.
  • PostHog: product analytics. Hosted in PostHog's EU cloud (Frankfurt). Where we ask first, and when analytics is not allowed, it keeps its identifier in page memory only, so nothing is stored in your browser. PostHog still receives each page view, including your IP address and browser details.

Your rights

  • Access: you can export all of your validations as PDF or Markdown from the results page.
  • Deletion: email hello@getolune.com from your account email and we'll delete your account + all validations within 7 days.
  • Enquiries and emails: email hello@getolune.com from the address you used and we'll delete your consulting enquiry and the emails you sent us within 7 days.
  • Correction: you can edit your display name and any validation content yourself in-app.
  • Unsubscribe: every course or marketing email has an unsubscribe link, and you can email us to be removed from all email lists.

Cookies

Olune uses:

  • Functional cookies: Supabase Auth keeps you signed in. Two small cookies of our own: olune_geo notes whether you appear to be in a region where we ask first (a yes or no, not your location), and olune_consent remembers your choice for 180 days.
  • Analytics cookies and storage: Google Analytics (for example _ga), Microsoft Clarity (_clck, _clsk, plus Microsoft cookies such as MUID) and PostHog (in your browser's local storage).
  • Advertising cookies: the Meta pixel (for example _fbp) and Google advertising signals.

Your choice. If you visit from the European Economic Area, the United Kingdom or Switzerland, or we cannot tell where you are, we show a short banner. Analytics and advertising are separate purposes: Accept allows both, Decline allows neither, and Choose separately lets you allow one without the other. Until you allow a purpose, its cookies wait.

If analytics is not allowed, Clarity does not load, and Google Analytics and PostHog still receive basic page-view requests, which include your IP address, browser details and the page address, but store no identifier in your browser. If advertising is not allowed, the Meta pixel does not load and we send nothing to Meta's Conversions API. If you withdraw a purpose while its tool is already running, the page reloads so the tool stops at once.

Everywhere else these tools run as described above, and you can still turn them off.

You can change your choice at any time with Cookie settings, in the site footer, at the bottom of every validation and results page, or right here: . Your choice is honoured wherever you are, and the product works fully either way.

Children

Olune is not intended for users under 13. Don't sign up if you are.

Changes

We'll update this page if anything material changes. The “Last updated” date at the top reflects the most recent change.

Contact

Questions or requests: hello@getolune.com.

See also: Terms of Service.