Legal
Privacy Policy
Effective date: October 3, 2026
Ownfeed collects what it needs to run your feed: your email address, what you tell us about your product, a payment record, and what you do in your feed. It also processes public posts written by other people. This policy explains both.
1. What we collect from you
- Account. Your email address, stored with our auth provider, Supabase. If you sign in with Google, Google shares your email address and basic profile information with that provider; the app uses your email address. There are no passwords.
- Your product. Its name, URL, and description, the audience and competitors you set or we derive from it, and the search terms built from them.
- Payment records. Payments run through Stripe. We receive a customer and subscription or payment reference, the plan, its status, when it ends, and whether you have used the trial. Your card number never reaches our servers.
- Trial check. The trial is one per person. To enforce this, we keep a one-way hash (SHA-256) of your email address, and we keep it even after you delete your account. The hash cannot be turned back into your email address.
- Your activity in the feed. Which posts you saved, hid, or marked as replied, and your settings, such as how much of each platform you want to see.
- Operational records. Records of collection runs and their costs, and standard technical logs kept by us and our hosting and database providers to run and debug the Service.
2. Public posts from other people
To build your feed, we collect posts that are publicly visible on these platforms when we collect them:
- X
- Bluesky
- Hacker News
The list may change as we add, remove, or pause platforms. For each post we store the author's name, the URL of their profile, the URL of their profile picture, the text of the post, its URL, and related public details such as the title, the community it was posted in, when it was posted, and public counts like replies or likes. We show these to users whose product the post may be relevant to.
The authors of these posts are not Ownfeed users and have no relationship with us. Because these are public posts, they can contain personal data their authors chose to publish. We do not access private groups or direct messages, and we do not try to identify anyone beyond what they have made public.
3. Requests from the people who wrote those posts
If you wrote a public post that appears in Ownfeed and want it excluded from future collection, or deleted from the data we have stored, email support@ownfeed.dev with a link to the post or your profile. We will act on the request within 30 days.
4. How we use information
We use the information above to build and show your feed, run your plan and payments, answer support requests, and keep the Service secure and working. We do not sell personal information, and we do not use it for advertising.
5. Service providers
The Service is built on these providers, each processing data under its own terms:
- Supabase — authentication and database: your account, your product, your feed, and the posts collected for it. The database server is in Mumbai, India.
- Cloudflare — hosting. Requests to the Service pass through Cloudflare's network.
- Stripe and Link — payments, through Stripe Managed Payments. Stripe collects and stores card details. Link, a Stripe company, is the merchant of record and emails receipts and invoices directly (see the Terms, Section 5).
- OpenAI — analysing your product to build search terms, and judging whether collected posts are relevant to it. Your product details and the text of public posts are sent to OpenAI for this.
- Resend — sending sign-in emails. Your email address is sent to Resend for this.
- Bright Data and Apify — collecting public posts from some of the platforms above. Other posts are collected through each platform's public API.
- GitHub — the collection jobs run on GitHub Actions.
- Google — sign-in, when you choose to continue with Google.
6. Data retention and deletion
We keep your account data, product, and feed for as long as your account exists, including after a plan ends, so that coming back does not mean starting over. You can delete your account yourself from Settings in the app at any time, which removes them, or email support@ownfeed.dev from your account address; we complete a deletion request within 30 days. Payment records may be kept for as long as legal, tax, or accounting rules require. The hash of your email address used for the trial check is kept after deletion, as described in Section 1.
Public posts we collect are not deleted automatically on a schedule. We keep them for as long as we need them to provide the Service, and we delete them when their author asks (see Section 3).
You can also ask Stripe to delete the data it holds for your payments and the associated Link account.
7. How we protect data
- Traffic between your browser and the Service is encrypted (HTTPS).
- The database uses row-level access control, so each account can read only its own data.
- Secret keys for the database and payments are kept on the server only, never sent to the browser.
8. Cookies and similar technologies
Ownfeed sets only the cookies that keep you signed in: session cookies from our auth provider, Supabase. Your browser also stores your light or dark theme preference locally. We do not use analytics or advertising cookies, and we do not track you across sites. Stripe's checkout page is hosted by Stripe and sets its own cookies under Stripe's privacy policy.
9. Your privacy rights
Wherever you live, you can ask us to access, correct, delete, or export the personal data we hold about you, or to restrict or object to our processing of it, by emailing support@ownfeed.dev. We respond without undue delay, and exercising a privacy right never changes how we treat you.
If you are in the EEA or the UK: our legal bases are performance of our contract with you (your account, plan, and feed), our legitimate interests (collecting public posts to provide the Service, and keeping it secure), and legal obligations (payment and tax records). You also have the right to complain to your local data-protection authority.
If you are a California resident: we do not sell personal information and do not share it for cross-context behavioral advertising. The rights above cover your rights to know, delete, and correct.
10. International transfers
Ownfeed is operated from Japan. The providers in Section 5 run infrastructure in other countries, including India (our Supabase database, in Mumbai) and the United States, so your data may be processed outside the country where you live.
11. Children
The Service is not meant for anyone under 18 (or the age of majority where they live), and we do not knowingly accept them as users.
12. Changes to this policy
If this policy changes, the new version will be posted here with a new effective date. Material changes will be announced on the site or by email to your account address.
13. Contact
Ownfeed is operated by Shunsuke Nakagawa, an independent developer based in Japan, who is responsible for the data described in this policy. The operator's address is disclosed on request. For any privacy question or request, email support@ownfeed.dev.