Privacy Policy
Last updated: August 5, 2026
1. Overview
This policy explains what WhatWorked ("we", "us") collects when you use whatworked.online, why we collect it, and the choices you have. We collect the minimum needed to run the product and we do not sell personal data.
2. What we collect
- Account data — when you sign in with Google we receive your name, email address and profile picture.
- Product activity — favorites, collections, support messages, plan and credit usage, and the queries you run in the research tools (keywords, domains). These are stored so the product works and so cached results don't cost you credits twice.
- Payment data — payments are handled entirely by Dodo Payments, our merchant of record. We store only your subscription status and plan; we never see or store card numbers.
- Technical data — standard server logs (IP address, user agent) kept by our hosting providers for security and debugging.
3. Cookies
We use only essential cookies: authentication session cookies set by our auth provider (Supabase) and a theme preference. We do not use advertising or cross-site tracking cookies, which is why there is no cookie banner.
4. How we use data
- to provide the service — sign-in, saved items, plan features;
- to meter credit usage and prevent abuse (rate limiting);
- to respond to support requests;
- to send transactional email about your account or subscription (never marketing without your consent).
5. Who processes data for us
- Supabase — database, authentication and storage;
- Vercel — application hosting and server logs;
- Google — sign-in (OAuth);
- Dodo Payments — checkout, subscription billing, invoicing and taxes, as merchant of record;
- SEO data providers — the keywords and domains you look up are forwarded to third-party SEO data APIs to fetch metrics. No personal account data accompanies those requests.
Each provider processes data under its own security and privacy commitments. Data may be processed on servers outside your country.
6. Retention
Account and product data are kept while your account exists. Cached tool results are kept for short periods (days to weeks) to avoid re-billing credits. Server logs rotate on our providers' standard schedules. When your account is deleted, associated personal data is removed from the production database.
7. Your rights
You can access and update your name in settings. You may request a copy of your data, correction, or deletion of your account at any time — email us or use the support form, and we will respond within 30 days. Depending on where you live (e.g. the EU/UK GDPR or India's DPDP Act), you may have additional statutory rights, which we honour.
8. Security
Data is encrypted in transit (TLS) and at rest by our providers. Access to production data is restricted to the operator. Database access is enforced with row-level security so users can only read their own private data. No method of storage is 100% secure; if a breach affects your personal data we will notify you as required by law.
9. Children
The service is not directed at children under 18 and we do not knowingly collect their data.
10. Changes and contact
We will post any changes to this policy here and update the date above; material changes will be announced on the site. Questions or requests: support@whatworked.online or the support form.