Legal
Privacy Policy
Effective July 26, 2026
The short version
We store your account, your saved products, and your research history so the product works. Research findings come from public web sources and every finding keeps its source link. We don't sell your data. You can delete any brief, or your whole account, yourself. Immediately.
1. What we collect from you
- Account data: name, email, and authentication identifiers, handled by our auth provider (Clerk). If you joined our waitlist before signing up, that email too (it's removed when you delete your account).
- Product usage: the briefs you run, your saved products and preferences, any reply outcomes you record, feedback you submit, links you share, API keys you create, referral activity, your credit history, and product-usage events (which record what you did, not who you researched).
- Billing data: handled by Stripe; we never see or store card numbers.
Your “Download your data” export in Settings contains all of it — what you see there is what we hold.
2. What briefs contain
Research findings summarize information that is already publicly available on the open web: public posts, articles, podcasts, and profiles. Every research finding carries a link to its public source. We do not scrape behind logins or access anything a search engine couldn't. Separately from those findings, the contact card may suggest a business email: that comes from Hunter.io, a business-contact lookup service, and is shown with its own confidence score rather than a source link — it's a lookup, not a public page. We also deliberately exclude entire categories from briefs even when they are public: health, children and family, religion, politics, sexuality or gender identity, racial or ethnic origin, trade-union membership, immigration status, and legal or financial matters are never surfaced (see our taste policy). Briefs inform a human's judgment about how to write one message — we make no automated decisions about anyone, whether a user or a person in a brief, that carry legal or similarly significant effects.
3. Who processes data on our behalf
The service is assembled from a small set of processors, each receiving only what its job requires: Clerk (authentication), Supabase (database), Stripe (payments), Anthropic (AI synthesis), Exa (web search), Serper.dev (social-profile discovery search), Hunter.io (business-email lookup), Resend (notification email), Sentry (error monitoring), and Railway (hosting). If you connect HubSpot, briefs you explicitly push are sent there too, and stop when you disconnect it. We don't sell or rent your personal data to anyone. Briefs about prospects are delivered only to the customer who requested that research — we never sell them onward, aggregate them into a database product, or share one customer's research with another.
We are a US-based service and most data is processed in the United States, though some processors operate in other countries. If you're in the EU, UK, or Switzerland, transfers to our processors are covered by recognized safeguards — each processor's EU–US Data Privacy Framework certification, or the Standard Contractual Clauses (or the UK equivalent) in its data-processing agreement with us.
4. Retention, and your controls
- Research history is kept for a window set by your plan (30 days on the free plan, 90 days on Starter, unlimited on Pro and Scale). Briefs you pin are kept until you unpin or delete them.
- You can delete any brieffrom its page at any time. That's a hard delete, effective immediately — and it takes down any public share link you created from that brief.
- You can delete your whole account from Settings. It cancels any subscription and permanently erases your briefs, watches, integrations (including stored CRM tokens), API keys, and settings, immediately. No email required, no 30-day queue.
- Everything that isn't a brief — your account details, preferences, credit history, reply outcomes, feedback, and product-usage events — is kept for as long as your account exists and erased with it when you delete the account. Our infrastructure providers' short-lived backups and logs can outlive a deletion by days, not months (roughly a week for database backups, 30 days for email and error logs).
5. Cookies & local storage
We use only what sign-in and the product need: authentication cookies set by Clerk (strictly necessary — they are your session), and browser local storage for small product state like a referral code you arrived with or a research link handed off from the browser extension. If you drop a CSV of prospects on our site before signing in, that list is parsed in your browser and held in your browser's local storage so it survives sign-up — it is cleared as soon as it loads into the bulk page, expires by itself after 30 minutes, and reaches our servers only when you start the batch. One third-party script runs for signed-out visitors: Google's sign-in prompt, which offers one-click sign-in if you already have a Google session and sets a cookie remembering that you dismissed it. It is there to sign you in, not to profile you, and it never loads once you're signed in. Beyond that: no advertising cookies, no tracking pixels, no analytics scripts from ad networks — which is why there's no cookie banner.
6. Emails we send
If you watch a prospect, we can email you when a check finds changes, per-check or as a weekly digest, your choice. Turn either off in Settings; every notification links there.
7. About the people in briefs
If a brief is about you: the underlying content is public, every finding links its source, and the source site is where removal of the content itself happens. But you can also ask us to exclude your profile from research entirely. Email hello@showyouknowme.comwith your LinkedIn URL and we'll add it to our suppression list, which blocks future research on that profile for everyaccount, including scheduled watches, not just the person who asked. On request we'll also delete the briefs that already exist about you, across all accounts, along with any public share links created from them.
8. Your rights
Depending on where you live, laws like the GDPR and the California Consumer Privacy Act give you rights over your personal data. We honor them for everyone, not just where required: the right to access and exportyour data (Settings → “Download your data”), to correct it (account details are editable in Settings; for anything else, email us), to delete it (per-brief or whole-account, above), to object to or restrictprocessing (for research about you, that's the suppression list in §7; for anything else, email us), and to not be discriminated againstfor exercising any of these. We don't sell personal data, so there is nothing to opt out of selling. If you're in the EU or UK, you also have the right to lodge a complaint with your data-protection authority — though we'd appreciate the chance to fix things first: hello@showyouknowme.com.
The service is built for business use and isn't directed to anyone under 16; we don't knowingly collect children's data, and the taste policy keeps children out of briefs entirely.
9. Security
Data in transit is encrypted with TLS; data at rest is encrypted by our infrastructure providers, and stored CRM tokens are additionally encrypted at the application layer. Access to production data is limited to the operator of the service.
10. Changes & contact
showyouknowme is operated by Show You Know Me LLC, a Georgia limited liability company, 8735 Dunwoody Place, Ste N, Atlanta, GA 30350.
We'll announce material changes to this policy in the app or by email; the effective date above always reflects the current version. Privacy questions: hello@showyouknowme.com.