Your data, plainly described
Privacy Policy
Startup MRI collects the minimum data needed to generate the validation report you asked for. This page describes what is collected, why, how long it is kept, and how to ask for it to be deleted.
Last updated · August 23, 2026
Quick answer
What we collect and why
When you submit an analysis, we store the idea text, target audience, monetization choice, distribution channel, and technical background you typed, plus the report URL we generated. We use the inputs to compute a deterministic score and to render the report page. We do not sell your data, do not run third-party advertising trackers in the analyze flow, and do not profile you across other sites.
1. What we collect
The service is structured into five data flows. Each is described below in plain language.
Analysis inputs
When you submit the analyze form, we store the one-sentence idea, the target audience you typed, the monetization and acquisition choices you selected, and your technical background. These five fields are the inputs to the deterministic scoring engine. The text inputs are stored verbatim so you can return to the generated report URL later.
Generated report
Each submission produces a report URL with a unique identifier. The report contains the computed scores, the critical-assumption callout, and the AI-written narrative layer. The page is noindexed (does not appear in Google or Bing) but is reachable by anyone who has the URL. Treat the URL the way you would treat a private note.
Feedback widget
The report page optionally shows a feedback widget (rating + comment). If you submit feedback, the rating and the comment are stored so the team can review patterns across reports. There is no required identity; the feedback is associated with the report ID, not with your name or email.
Hosting analytics
Vercel and our self-hosted Umami instance collect aggregate request counts (page, time, country) for capacity planning. These analytics are first-party and do not include cookies that identify you across other sites. We do not use Google Analytics.
2. How we use what we collect
The data is used only to operate the service you asked for. We do not sell, rent, or share it for advertising purposes.
- Compute the deterministic score from the rule engine.
- Render the report page at the generated URL.
- Allow the team to read feedback and improve the product.
- Diagnose outages, abuse, and capacity issues.
3. Third parties we use
Four third parties handle data on our behalf. Each has a defined scope.
Supabase (database)
Stores the analysis inputs, the report JSON, and the feedback rows. Hosted on managed Postgres in a single region. Access is limited to the production application; we do not grant third-party access.
OpenAI-compatible LLM (narrative layer)
Receives the analysis inputs and the computed scores to generate the AI-written narrative inside the report. The LLM does not receive identifying information beyond the inputs you typed. The narrative is grounded in the rule-engine output, not in your identity.
Vercel (hosting)
Hosts the application. Receives standard HTTP request logs (IP, user-agent, request path). Logs are retained by Vercel per their default policy; we do not export them.
Google AdSense (advertising, if enabled)
If advertising is enabled on the publication pages, Google AdSense may set cookies to measure ad performance. We do not enable AdSense on the analyze flow or on report pages. See Google's AdSense policies for how they handle advertising cookies.
4. Cookies
We do not set tracking cookies on the analyze or report pages. The site sets only the cookies that next-intl needs to remember your language preference, plus the cookies the ad network (if enabled) sets on the editorial pages. You can block all cookies in your browser without losing access to the service.
5. How long we keep your data
Reports are retained until you ask for them to be deleted. Feedback rows are reviewed quarterly and deleted after one year unless they describe a reproducible bug. Hosting logs are retained by Vercel per their default policy (usually 30 days).
6. Your rights
You can exercise the rights below at any time.
- Request a copy of every report and feedback row associated with your submission.
- Request deletion of a specific report or all reports you have submitted.
- Request correction if any of the stored inputs is wrong.
Send requests to the address listed on the Contact page. We respond within 30 days.
7. Changes to this policy
If we change what is collected, how long it is kept, or which third parties see it, we update this page with a new effective date. The change is also reflected in the report footer so any user who has submitted can see what changed.