Privacy Policy
Last updated: June 2026
1. Introduction
This Privacy Policy explains how SpyIQ ("SpyIQ", "we", "us", or "our") collects, uses, stores, and protects personal data when you access or use our services through spyiq.co or associated applications (the "Service"). By accessing the Service, you acknowledge that you have read and accepted this Privacy Policy. SpyIQ is the Data Controller responsible for processing your personal data.
2. Personal Data We Collect
- •Identification data: Full name
- •Contact data: Email address
- •Account information: Subscription plan (Free/Starter/Pro/Agency), billing status, AI credits usage
- •Technical data: IP address, device type, OS version, browser type, session logs
- •Usage data: Product searches, store/ad analyses, saved items, AI Analyzer queries, feature usage, time spent, crash reports
- •Support communication: messages, attachments
Payment information is processed securely by Stripe. We do not store full credit card numbers.
3. Legal Basis for Processing (GDPR)
- •Performance of a contract: to provide, manage, and maintain your account and subscription
- •Consent: for marketing communications and non-essential cookies
- •Legitimate interest: product improvement, fraud prevention, analytics
- •Legal compliance: tax, accounting, and regulatory obligations
4. How We Use Your Data
- •Provide and operate the Service (product research, store/ad intelligence, AI insights)
- •Authenticate access and manage subscriptions
- •Process payments
- •Generate AI-powered analysis and insights
- •Send alerts you've configured
- •Offer support and communicate product updates
- •Improve functionality and user experience
- •Detect and prevent fraud or abuse
- •Comply with applicable laws
5. Third-Party Processors
- •Supabase (authentication and database hosting)
- •Stripe (payment processing)
- •Anthropic (Claude AI API — powers AI Analyzer, IQ Scores, and store/ad analysis; your AI queries are sent to Anthropic to generate responses)
- •Upstash (Redis caching and rate limiting)
- •Vercel (application hosting)
These providers act under binding confidentiality and data protection agreements.
6. International Data Transfers
Your data may be transferred and stored outside your country, including the United States. When processing data from the EEA, UK, or Switzerland, we rely on the EU-US Data Privacy Framework, Standard Contractual Clauses (SCCs), and other legally recognized safeguards.
7. Cookies
We use essential cookies (required for authentication and functionality), analytics cookies, and marketing/advertising cookies. You may manage consent via your browser settings or our cookie banner.
8. Data Retention
We retain your personal data only as long as necessary for the purposes outlined above or as required by applicable law. Billing and legal data may be stored up to 7 years.
9. User Rights
Depending on your jurisdiction (GDPR, CCPA), you may request access, correction, deletion ("Right to be Forgotten"), restriction or objection to processing, withdrawal of consent, and data portability (export). To exercise these rights, contact: privacy@spyiq.co
10. Children's Privacy
The Service is not intended for individuals under 18 years old, and we do not knowingly collect their data.
11. Data Security
We apply commercially reasonable security measures including encryption and Supabase Row Level Security, but no electronic storage or transmission is fully secure.
12. Changes to This Policy
We may update this Policy from time to time. The "Last updated" date indicates the most recent modification.
13. Contact
For privacy inquiries or rights requests: privacy@spyiq.co