Privacy policy
Last updated September 26, 2026
This policy explains what personal data Puentiac collects, why, who we share it with and the choices you have. Puentiac is the controller of your data.
1. What we collect
- Account: name, email (or a placeholder if you sign up with X and have not added one) and a hashed password.
- Sign in with X (optional): your X user ID, @username, display name and profile picture. We do not receive or keep your X access token, and we cannot read or post to your X account.
- Your content: your voice profile (niche, product, audience, tone, opinions, posts you are proud of), the work you log, the website address you give us, the posts and tasks generated for you and their status.
- Website check: if you add your website, we read that public page to learn your voice and to notice when it changes; we store a short snapshot for comparison.
- Usage and technical data: plan, usage counters, connection tokens (stored hashed), IP address and basic request logs for security and abuse prevention.
- Payments: handled by Stripe. We never see or store your card number; we keep only Stripe customer and subscription identifiers and your plan.
2. How we use it
- To provide the service: generate your posts, ideas and edits, show your queue and history, and keep your account secure.
- To bill you and manage your plan and free trial.
- To answer support requests and to prevent fraud and abuse.
- To improve the product using aggregated, non-identifying usage information.
We do not sell your personal data and we do not use it for advertising.
3. Legal bases
We process your data to perform our contract with you, to comply with legal obligations, for our legitimate interests in running and securing the service, and with your consent where required (for example, Sign in with X).
4. Who we share it with
We use these service providers, only as needed to run Puentiac:
- OpenAI: your voice profile and the topic or text of each post are sent to write and edit posts. Under OpenAI's API terms, data sent through the API is not used to train their models.
- Stripe: payments, invoices and subscription management.
- Supabase: database hosting.
- Vercel: hosting and delivery of the app.
- X (Twitter): only if you choose Sign in with X, to confirm your identity.
We may also disclose data if the law requires it. Some providers process data outside your country, including in the United States, under standard contractual safeguards.
5. Cookies and local storage
We do not use advertising or tracking cookies. To keep you logged in, the app stores a session token in your browser's local storage, and it stores a few interface preferences. You can clear them at any time by logging out or clearing your browser data.
6. How long we keep it
We keep your data while your account is active. When you delete your account we remove your profile, posts, work log, tokens and snapshots from our database. Payment records may be kept by Stripe and by us as long as tax and accounting law requires. Backups are overwritten on a regular schedule.
7. Your rights
Depending on where you live (for example under the GDPR) you can ask to access, correct, export, restrict or delete your data, to object to processing and to withdraw consent.
You can export everything we store about you and permanently delete your account yourself from Settings. For anything else, write to us. You also have the right to complain to your local data protection authority.
8. Security
We use encrypted connections, hashed passwords and hashed connection tokens, and limit access to your data. No system is perfectly secure, so please use a strong, unique password.
9. Children
Puentiac is not directed to anyone under 16 and we do not knowingly collect their data.
10. Changes
We may update this policy and will note the date at the top. For material changes we will let you know in the app or by email.
11. Contact
Privacy questions or requests? Write to support@rocketito.com.