Privacy Policy

This template privacy policy is provided for informational purposes only and does not constitute legal advice. You should consult a qualified attorney to ensure that your final privacy policy complies with applicable laws and reflects your actual data practices.

Last updated: 9/13/2025

1. Introduction

Welcome to smuch ("we", "us", "our"). We respect your privacy and are committed to protecting the personal information you share with us. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, mobile applications, and any related services (collectively, the "Service").

Key areas to confirm with your legal counsel:

  • Whether you fall under GDPR, CCPA, COPPA, or other regional privacy regulations.
  • Data processing addendums with third-party vendors (e.g., Supabase, Vercel, OpenAI).
  • Your approach to opt-in/opt-out for marketing communications.

2. Information We Collect

We collect the following categories of information:

  • Information You Provide: Email address, authentication provider details (e.g., Google sign-in), item photos, voice recordings/transcripts, notes, maintenance data.
  • Automatically Collected: Log data, device type, browser information, IP address, usage statistics, cookies, and similar technologies.
  • Third-Party Sources: Metadata and manuals fetched from external APIs to enrich your item catalog.

3. How We Use Your Information

We use your information to:

  • Provide, operate, and maintain the Service.
  • Personalize and improve your experience (e.g., AI-generated recommendations).
  • Send transactional emails and optional marketing communications.
  • Develop new features and perform analytics.
  • Detect, prevent, and address technical issues or security incidents.

4. Sharing of Information

We do not sell your personal information. We may share it with:

  • Service providers that process data on our behalf (e.g., Supabase, image recognition providers).
  • Analytics and monitoring tools (e.g., Vercel, Logflare) in aggregated or pseudonymized form.
  • Law enforcement or regulators when required by law.

5. Legal Bases for Processing (GDPR)

We process personal data under the following bases:

  • Performance of a contract (our Terms of Service).
  • Legitimate interests (e.g., improving Service, fraud prevention).
  • User consent (for marketing emails, cookies where required).
  • Compliance with legal obligations.

6. Your Rights & Choices

Depending on your location, you may have rights to:

  • Access, correct, or delete your personal information.
  • Object to or restrict certain processing.
  • Data portability.
  • Withdraw consent at any time.

To exercise these rights, please contact us. We may require verification of your identity before fulfilling requests.

7. Data Retention

We retain personal data only as long as necessary to fulfill the purposes outlined in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce our agreements.

8. Security

We implement industry-standard security measures to protect your information; however, no system is 100% secure. Please use the Service responsibly and report any vulnerabilities you discover.

9. International Transfers

We are based in the United States. If you access the Service from outside the U.S., your data may be transferred to, stored, and processed in the U.S. or other countries where we or our service providers operate.

10. Children's Privacy

The Service is not directed to children under 13. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will delete it as required by law.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date above.

12. Contact Us

If you have questions about this Privacy Policy, please contact us at: support@smuch.ai