Skip to content
TrendSuite

Privacy Policy

We collect only what we need to run the product. We do not sell your data. We do not use it to train AI models without your consent.

Last updated: 2026-07-07.

1. Introduction

This Privacy Policy describes how TrendSuite AI LLC, a Delaware limited liability company, operating as “TrendSuite” (“we”, “our”, “us”), collects, uses, stores, and discloses personal data when you use the TrendSuite platform, website, and related services (collectively, the “Service”). TrendSuite is the data controller for personal data processed through the Service. This policy applies to all users worldwide and is supplemented by jurisdiction-specific disclosures where applicable (see Sections 4 and 7).

This policy does not apply to third-party websites or services that we may link to. We encourage you to review the privacy policies of those services separately.

2. Data We Collect

Identifiers.Email address and display name, collected at account creation. If you sign in with Google, we receive your name and email from Google’s OAuth endpoint.

Brand profile data. The niche, target audience, tone of voice, content pillars, brand archetypes, and never-say rules you provide during onboarding and in subsequent profile edits. This is the primary input to content generation.

Social platform OAuth tokens. When you connect a social account, we store the OAuth access token and refresh token for that platform. These tokens are encrypted at the application layer using AES-256-GCM before being written to the database. We never store your social account passwords.

Usage data. In-product events such as features used, ideas generated, content plans created, and posts scheduled, linked to your account. Collected to understand how the product is used and to improve it.

Technical data.IP address, browser user agent, and device type. Collected by our hosting provider (Vercel) as part of normal server-side logging and retained according to Vercel’s log-retention policy.

Payment data. We do not collect or store payment card data. All payment processing is handled directly by Stripe; we receive only non-sensitive billing metadata such as your subscription status and plan.

3. How We Use Your Data

Running the product. Authentication, session management, content generation, trend personalisation, scheduling, and all core features of the Service.

Trend personalisation. Your brand profile (niche, audience, tone) is used to filter and rank trend signals so that what you see is relevant to your specific brand context.

AI content generation. Brand profile data is included in prompts sent to our AI providers — Anthropic (text generation) and OpenAI (text embeddings and, where enabled, image generation) — to produce on-brand output. Under both providers’ standard API terms, your prompts and completions are not used to train their models. A provider may retain API data for a limited period for abuse monitoring before deletion, as described in that provider’s own policies.

Billing. Subscription management, trial state, plan upgrades and downgrades, and payment processing via Stripe.

Communication. Welcome emails, trial lifecycle nudges, service announcements, and responses to your support requests. You may opt out of marketing emails at any time via the unsubscribe link; transactional emails (such as password resets) cannot be opted out of while your account is active.

Product analytics. We record in-product events (such as which features are used), linked to your account, to understand usage and prioritise the roadmap. These events are stored in our own database — we do not share them with any third-party analytics service.

Security monitoring. Error logs (via Sentry) and request logs (via Vercel) are used to detect and investigate security incidents, bugs, and abuse.

4. Legal Bases for Processing (GDPR)

For users in the European Economic Area, United Kingdom, and Switzerland, we rely on the following legal bases:

  • Contract performance (Article 6(1)(b)) — processing necessary to operate the Service you have signed up for, including authentication, content generation, and scheduling.
  • Legitimate interest (Article 6(1)(f)) — security monitoring, fraud prevention, error tracking, and product improvement through first-party product analytics. You may object to this processing (see Section 7).
  • Consent (Article 6(1)(a)) — where you give it for specific optional processing. Where we rely on consent, you can withdraw it at any time by contacting us.
  • Legal obligation (Article 6(1)(c)) — complying with applicable law, including responding to valid legal process.

5. Sub-Processors

We use the following third-party sub-processors to operate the Service. Each receives only the minimum data required for its specific function. Some sub-processors (for example, the website-analyzer and stock-photo providers) are engaged only when the corresponding feature is enabled. We enter into Data Processing Agreements with each sub-processor that handles personal data of EEA/UK users.

Sub-processorPurposeData sharedLocationCertifications
SupabaseDatabase and authenticationAll user and workspace dataUS-EastSOC 2 Type II
StripePayment processing and billingName, email, billing addressUS / IrelandPCI DSS Level 1
ResendTransactional email deliveryName, email addressUSSOC 2 (in progress)
AnthropicAI text generation (content plans, captions, analysis)Brand profile data, trend context, prompt inputsUSNot used to train models (per API terms); EU-US DPF
OpenAIText embeddings and, where enabled, image generationBrand profile text, content inputsUSNot used to train models (per API terms); EU-US DPF
VercelApplication hosting and edge networkRequest logs, IP addressesGlobal CDNSOC 2 Type II
SentryError monitoring and performanceStack traces, request contextUS / EUSOC 2 Type II
UpstashRate limiting and cacheSession identifiers, rate countersUS / EUSOC 2 Type II
FirecrawlWebsite analyzer — fetching your brand site during onboardingThe brand website URL you submitUSTLS in transit
Jina AIWebsite analyzer — fallback fetch for JS-heavy sitesThe brand website URL you submitUS / GlobalTLS in transit
PexelsStock-photo search for StudioYour search query strings (no personal data)USTLS in transit
PayPalAffiliate commission payoutsAffiliate payee email and payout amountUS / GlobalPCI DSS Level 1
SerpAPISearch trend signalsNiche query strings, no personal dataUSTLS in transit

We will notify users of material changes to this list at least 30 days in advance where required by applicable law.

6. Data Retention

Account data. Retained for the lifetime of your account. On account deletion, we initiate deletion within 30 days, subject to any legal hold obligations.

Server logs. Request and error logs are handled by our hosting and monitoring providers (Vercel and Sentry) and retained according to their respective retention policies.

Content & generation history. The ideas, content plans, and their generation inputs you create are retained for the life of your account so they remain available to you, and are deleted when your account is deleted, subject to the account-data schedule above.

Billing records. Transaction records are retained for 7 years as required by applicable tax and accounting laws, regardless of account deletion.

7. Your Rights

Depending on your jurisdiction, you have some or all of the following rights regarding the personal data we hold about you:

  • Access (GDPR Art. 15; CCPA): Request a copy of the personal data we hold about you.
  • Correction (GDPR Art. 16): Request that we correct inaccurate or incomplete data.
  • Deletion (GDPR Art. 17; CCPA): Request erasure of your personal data, subject to legal retention obligations.
  • Export / Portability (GDPR Art. 20): Receive your data in a structured, commonly used, machine-readable format.
  • Restriction (GDPR Art. 18): Ask us to restrict processing of your data under certain circumstances.
  • Objection (GDPR Art. 21): Object to processing based on legitimate interest, including profiling.
  • Opt-out of sale (CCPA): We do not sell personal data. If this changes, we will provide a clear opt-out mechanism.
  • Lodge a complaint: You have the right to lodge a complaint with your local supervisory authority (e.g., your national Data Protection Authority in the EU).

To exercise any right, email privacy@trendsuite.ai. We will respond within 30 days (or the shorter period required by applicable law). For complex or high-volume requests, we may extend this period by a further 60 days with notice.

8. International Transfers

TrendSuite operates primarily from the United States. When we transfer personal data of EEA or UK users to sub-processors outside the EEA/UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, supplemental technical and organisational measures where required, and the UK Addendum to the EU SCCs for UK transfers.

All sub-processors listed in Section 5 that are based outside the EEA operate under SCCs or an equivalent transfer mechanism. Several of our US-based providers (including OpenAI, Anthropic, and Stripe) are also self-certified under the EU-US Data Privacy Framework and its UK extension. Copies of the applicable transfer mechanisms are available on request.

9. Cookies & Tracking

We use a small number of cookies and similar technologies:

  • Authentication session cookie (essential) — maintains your logged-in state. Set by Supabase Auth. Expires when you log out or after the session timeout.
  • Theme preference (essential) — stores your light/dark mode preference. No personal data.
  • Affiliate attribution cookie (non-essential) — if you arrive through an affiliate referral link, we set a ts_ref cookie for up to 90 days so the referring affiliate is credited if you later subscribe. It is not used for advertising and is not shared with ad networks.

Error monitoring & session replay. We use Sentry to capture errors and diagnose problems. This includes a session-replay feature that records a sampled subset of sessions (a small percentage of sessions, plus sessions in which an error occurs) to help us reproduce bugs. Replays are configured to mask text you type and block media, so we do not capture the content of your inputs. This is used for reliability and security, not advertising.

We do not use advertising cookies, third-party ad-tracking pixels, or cross-site advertising trackers. We do not use Google Analytics or any other cloud analytics service that transfers browsing data to advertising platforms.

10. Children

The Service is not directed to children under 13 years of age. We do not knowingly collect personal data from children under 13. If we learn that a user under 13 has created an account, we will promptly delete the account and associated data. If you believe a child under 13 has provided us with personal data, please contact privacy@trendsuite.ai.

11. Security

We implement technical and organisational measures to protect your personal data. A detailed description of these measures — including encryption standards, access control architecture, and our responsible disclosure programme — is available on the Security Overview page.

12. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, as required by GDPR Article 33. Where the breach is likely to result in a high risk to individuals, we will also notify affected users directly without undue delay.

13. Changes to This Policy

We will update the “Last updated” date at the top of this page when we make material changes. For significant changes that affect your rights or how we use your data, we will notify you by email at least 14 days before the changes take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

14. Contact

Data controller. TrendSuite AI LLC, a Delaware limited liability company, operator of the TrendSuite Service. Postal address for legal and privacy notices: 801 Travis Street, Suite 2101, PMB 2028, Houston, TX 77002. GDPR Articles 13 and 14 require us to give you the controller’s identity and contact details, so this address and the contact routes below are provided regardless of our corporate status.

Privacy questions and rights requests: privacy@trendsuite.ai

Data Processing Agreement requests: dpa@trendsuite.ai

EU/EEA representative: To be appointed before general availability in the European Union.

Data Protection Officer: To be appointed before EU general availability. Applicable to processing at scale of special-category data or systematic monitoring, as required by GDPR Article 37.