1. Who we are
waypoint.dog is an AI-powered Startup Operating System for indie hackers and solo founders. The product runs at waypoint.dog and on tool subdomains like validate, identity, and brand.
For privacy questions, email hello@waypoint.dog.
2. The data we collect
We collect the minimum we need to run the product:
- Account data: email and basic profile details when you sign in with a magic link, Google, or GitHub.
- Project data: projects you create, tool inputs, generations, and the shared project context tools read and write.
- Billing data: credit purchases and refunds handled by Paddle. We store payment references and credit ledger entries. Card numbers stay with Paddle.
- Generated assets: AI text and image outputs, plus files you store in the product (for example brand logos).
- Technical logs: operational logs and error reports (including Sentry) used for reliability and security.
3. How we use data
We use personal data to:
- Sign you in and keep sessions working across the main site and tool subdomains
- Run tools, reserve and consume credits, and keep project context in sync across Validate, Identity, and Brand
- Process purchases and refunds through Paddle
- Provide account settings, data export, and account deletion
- Protect the platform with rate limits, abuse checks, and fraud prevention
- Measure product usage with analytics only after you opt in (see Cookies)
We do not sell your personal data. Your startup ideas and project context are there so the product can help you build. We are not packaging them up as a dataset for anyone else.
4. Legal basis
Where GDPR or similar rules apply, we usually rely on three bases. First, contract: processing needed to provide the service you signed up for. Second, legitimate interests: securing and operating the platform. Third, consent: where required, such as non-essential analytics cookies.
5. Processors and subprocessors
We use other companies to run parts of the product:
- Hosting and edge delivery (Vercel)
- Database (Neon)
- Auth email (Resend) and OAuth (Google, GitHub)
- Payments / merchant of record (Paddle)
- Object storage (Cloudflare R2)
- Redis and job queues (Upstash)
- AI model providers for text and image generation
- Error monitoring (Sentry)
- Product analytics (PostHog), only when you accept analytics cookies
7. Retention
We keep account and project data while your account is active. Generations and context stay until you delete the related project or the account itself.
If you delete your account, we soft-delete first and purge after 30 days. Where hard delete is available, we can remove data immediately instead. Some payment records may be kept in anonymized or minimized form for accounting and fraud prevention.
8. Your rights
Depending on where you live, you may be able to access, correct, export, or delete personal data. Inside the product you can usually:
- Export: download a copy of your data from Settings. We may ask you to sign in again first.
- Delete: remove your account from Settings (soft-delete with a delayed purge, or hard delete where offered).
- Update: change profile details in the product, or email us if something looks wrong.
If you need help outside the UI, write to hello@waypoint.dog.
9. International transfers
Some of our providers run in the United States or other countries. When the law requires it, we rely on the transfer tools those providers offer, such as standard contractual clauses.
10. Children
waypoint.dog is for adults building startups. It is not aimed at children under 16, and we do not knowingly collect their personal data. If you think a child created an account, tell us and we will delete it.
11. Changes
We may update this policy as the product changes. For material updates we will change the date above and, when it makes sense, show a notice in the product.