Legal

Privacy Policy

Last updated: June 23, 2026

1. Who We Are

Waabang.ai (“Waabang,” “we,” “our,” or “us”) is an AI-powered platform that helps entrepreneurs discover, evaluate, and refine business ideas. Our registered contact email is [email protected].

2. Information We Collect

We collect information you provide directly and information generated by your use of the platform:

Information you provide

  • Account data — email address and password when you register.
  • Payment data — billing information processed by Stripe. We do not store full card numbers; Stripe handles PCI-compliant storage.
  • User-submitted content — business ideas, problem statements, and any other text you submit for review or refinement.
  • Communications — messages you send to our support email.

Information collected automatically

  • Usage data — pages visited, features used, ideas claimed or passed, timestamps.
  • Device and log data — IP address, browser type, operating system, and referring URLs.
  • Cookies and local storage — session tokens required for authentication. We do not use tracking or advertising cookies.

3. How We Use Your Information

  • To create and maintain your account.
  • To process payments and manage your subscription.
  • To deliver the services you request (idea reviews, AI panel reports, refinement sessions).
  • To send transactional emails — receipts, subscription confirmations, and review results.
  • To improve the platform — aggregated, anonymised usage data helps us prioritise features.
  • To comply with legal obligations and enforce our Terms of Service.

We do not sell your personal data. We do not use your submitted ideas or personal information to train AI models without your explicit consent.

4. How We Share Your Information

We share data only with the third-party services required to operate the platform:

  • Supabase — database and authentication infrastructure.
  • Stripe — payment processing. Governed by Stripe’s Privacy Policy.
  • Resend — transactional email delivery.
  • AI providers — when you submit an idea for review, your problem statement and associated context are sent to AI model providers (Anthropic, OpenAI, and others) solely to generate your report. These providers are contractually prohibited from using your data for model training under their API terms.
  • Legal requirements — we may disclose information if required by law, court order, or to protect the rights and safety of our users.

We do not share your data with advertisers or data brokers.

5. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where retention is required by law (e.g., financial records related to paid transactions, which we retain for 7 years). Anonymised aggregated data may be retained indefinitely.

6. Security

We implement industry-standard technical and organisational measures to protect your data, including encrypted connections (TLS), row-level security on our database, and access controls that restrict data to the user who owns it. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.

7. Your Rights

Depending on your jurisdiction, you may have rights including:

  • Access — request a copy of the personal data we hold about you.
  • Correction — ask us to correct inaccurate data.
  • Deletion — ask us to delete your account and personal data.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to certain processing activities.

To exercise any of these rights, email [email protected]. We will respond within 30 days.

8. Cookies

We use only functional cookies necessary to keep you logged in (a session token stored via Supabase Auth). We do not use analytics, advertising, or third-party tracking cookies. You can clear cookies in your browser settings at any time, which will log you out.

9. Children’s Privacy

Waabang is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe we have collected data from a child, contact us at [email protected] and we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page. For material changes, we will notify you by email or by a notice on the platform at least 14 days before the change takes effect.

11. Contact

Questions, concerns, or requests regarding this policy should be directed to: [email protected].