1. Who we are
Details.so (“we”, “us”, “our”) is operated from Switzerland. This Privacy Policy explains what personal data we collect, why we use it, who we share it with, and what rights you have.
For privacy requests, contact us at legal@details.so.
2. Data we collect
We collect only the data we need to run, secure, improve, and sell access to the Service.
- Account data — email address, Supabase user ID, login method, account timestamps, your confirmed account name, onboarding role and acquisition-source answers, and profile information shared by an OAuth provider such as Google, which may include your name and avatar.
- Authentication and session data — browser session tokens, auth status hints, account tier hints, and related local browser storage used to keep you signed in and show the right access state.
- Billing data — paid plan, billing period, subscription status, customer ID, checkout country, billing portal activity, payment event records, and invoice or tax records handled through Polar. We do not store full card numbers.
- Affiliate referral data — referral cookie IDs and checkout metadata used to attribute eligible Pro and Max purchases to approved affiliates.
- Member referral data — member invite codes, referral-cookie data, referrer and invitee account IDs, referral capture and expiry times, order and discount identifiers, purchase type and initial Team-seat weight, referral progress, reward unlocks, claims, and the limited name, avatar, or Team-name snapshot shown to the referring member after a successful referral.
- Product data — saved items, bookmarks, folders, account limits, tier usage, feedback messages, support requests, content suggestions, and related timestamps.
- Search and connected-assistant requests — search text, any short project context supplied with an inspiration search, requested reference or resource IDs, pagination, excluded source domains, and the requested resource content mode. When you connect Details to an assistant such as ChatGPT through MCP, we receive the arguments that assistant sends to our tools. The connection does not independently give Details access to your full conversation history or project files.
- Source evidence — for some website inspirations, Details captures publicly accessible source files, source metadata, and runtime observations so the service can verify the recorded interaction and provide a source brief. A source brief may include cited file paths, line ranges, and short source-code excerpts. These captures come from the referenced public website; they are not your private project files, credentials, or conversation history.
- Connected-assistant access and usage data — account or partner-access identifiers, authorized client identifiers, access grants, account tier, request and tool names, whether a request was allowed or limited, timestamps, and usage or credit accounting. Our MCP usage records do not contain search text, project context, complete tool arguments, response content, or access tokens.
- Email and marketing data — email address, confirmed account name or email-local-part fallback, subscription or waitlist segment, opt-in or opt-out status, email delivery events, and unsubscribe preferences.
- Technical and security data — IP address, approximate country, user agent, device and browser information, request metadata, rate-limit counters, server logs, and error logs.
- Analytics data — aggregate, privacy-friendly usage data used to understand how the product is used. We do not use analytics for advertising, retargeting, or cross-site tracking.
3. Why we use data
We use personal data to:
- create and secure accounts;
- authenticate users and maintain sessions;
- provide free and paid access to Inspo, Vault, bookmarks, folders, and account features;
- find and rank relevant inspiration and Vault results, deliver reference images and resource content, authorize connected assistants, and enforce usage allowances;
- process checkout, billing, invoices, renewals, cancellations, refunds where legally required, and customer support;
- run our invite-only affiliate program and attribute eligible Pro and Max purchases to approved affiliates;
- run the member referral program, apply the invite discount, attribute and count successful referrals, show referral progress, unlock and fulfil rewards, review Setup Fund claims, and prevent misuse;
- send service emails about login, account activity, billing, security, support, and important product changes;
- send newsletter, Lifetime waitlist, and Details.so product update emails where allowed, always with an unsubscribe option for marketing emails;
- verify email addresses, prevent abuse, enforce rate limits, and protect the Service;
- understand aggregate product usage and improve the Service;
- understand which roles and discovery channels bring people to the Service and improve onboarding;
- comply with legal, accounting, tax, and security obligations.
4. Legal basis
Where the EU GDPR, UK GDPR, or Swiss FADP applies, we rely on:
- Contract performance — to provide accounts, paid access, billing, support, and requested features.
- Legitimate interests — to secure the Service, prevent abuse, improve the product, send relevant Details.so product updates to account users where allowed, keep business records, and protect our legal rights.
- Consent — for newsletter signups, Lifetime waitlist signups, and any other processing where consent is required. You can withdraw consent at any time.
- Legal obligations — to keep accounting, tax, billing, compliance, and security records where required by law.
5. Marketing and service emails
We send transactional and service emails when needed for account access, login, security, billing, product operation, legal notices, support, and important account updates.
If you sign up for the newsletter or Lifetime waitlist, we use your email for that purpose until you unsubscribe or ask us to delete it.
If you create an account, we may send you Details.so product updates about our own similar features, releases, and offers where allowed by law. Each marketing email includes an unsubscribe option. Unsubscribing from marketing emails does not stop transactional or service emails.
6. Service providers
We do not sell your personal data. We share data only with providers we use to operate the Service:
- Supabase — authentication, database, storage, and user management. supabase.com/privacy
- OpenAI API — converts inspiration search text and any supplied short project context into numerical representations (embeddings) used to find relevant catalog entries. This processing may also occur when your connected assistant is provided by another company. OpenAI business data privacy
- bunny.net — delivers inspiration images and videos and stores private source-evidence files used for selected inspiration briefs. When your browser or assistant loads media, or when the MCP service reads source evidence, bunny.net processes the network information and authorization metadata needed to serve that request, such as IP address and request metadata. bunny.net/privacy
- Polar — checkout, subscriptions, billing portal, invoices, taxes where applicable, and payment-related records. polar.sh/legal/privacy
- Affonso — affiliate referral tracking, affiliate program management, and commission attribution for eligible purchases. affonso.io/privacy
- Resend — transactional emails, newsletter/waitlist emails, product update emails, and feedback/support email delivery. resend.com/legal/privacy-policy
- ZeroBounce — email address validation for newsletter, waitlist, and signup quality checks. zerobounce.net/privacy
- Vercel — hosting, CDN, serverless functions, request handling, logs, and deployment infrastructure. vercel.com/legal/privacy-policy
- Google — OAuth login, if you choose to sign in with Google. policies.google.com/privacy
These providers process data under their own legal terms and, where applicable, data processing agreements.
For inspiration matching, we send search text, supplied project context, and the resulting embeddings to our search database hosted by Supabase. We do not need credentials, payment details, or unrelated personal information in search text or project context.
If you use Details through a connected assistant, tool results are returned to that assistant. Its handling of your conversations and those results is governed by its provider’s terms, privacy policy, and your settings. This is separate from Details using the OpenAI API for search matching.
7. International transfers
We operate from Switzerland and use providers that may process data in Switzerland, the EEA, the United Kingdom, the United States, or other countries.
Where personal data is transferred internationally, we rely on appropriate safeguards such as adequacy decisions, Standard Contractual Clauses, the Swiss equivalents of those clauses, the EU-US Data Privacy Framework where applicable, or another lawful transfer mechanism.
8. Retention
We keep personal data only as long as reasonably needed for the purposes above, unless a longer period is required or allowed by law.
- Account data — kept while your account exists. If you request deletion, we delete or anonymize account data within a reasonable period, except data we must keep for legal, billing, security, or dispute reasons.
- Bookmarks, folders, saves, and product data — kept while your account exists and deleted or anonymized after account deletion unless retention is required.
- Billing, tax, invoice, and accounting records — kept for up to 10 years or longer if legally required.
- Payment, subscription, and webhook event records — kept as long as needed for billing integrity, accounting, fraud prevention, chargebacks, audits, disputes, and legal compliance.
- Affiliate referral records — kept as long as needed to attribute eligible purchases, administer commissions, prevent abuse, and keep business records.
- Member referral records — kept as long as needed to operate the Program, preserve progress and claim history, fulfil rewards, review refunds or misuse, resolve disputes, and meet accounting or legal obligations.
- Newsletter and waitlist data — kept until you unsubscribe, request deletion, or the list is no longer needed.
- Feedback and support messages — kept for up to 24 months unless needed longer for security, legal, or product history reasons.
- Search processing — our application keeps a limited cache of search text and embeddings in server memory for short-term reuse. Cached embeddings are reused for up to ten minutes; this is a reuse window, not a guarantee that all provider records are deleted after ten minutes. The search feature does not save a dedicated account search history. Provider and infrastructure records are subject to their applicable retention arrangements.
- Connected-assistant grants and usage records — kept as needed to maintain authorized connections, calculate allowances, prevent abuse, and resolve billing, security, or access disputes. Revoking a connection does not itself delete prior usage records; you can request access or deletion through the contact below, subject to the exceptions in this policy.
- Source evidence — captured source files, briefs, and verification metadata are kept in private storage for as long as needed to maintain the relevant catalog evidence and provide the source-inspection workflow. They are removed or replaced when the associated catalog evidence is retired or regenerated, subject to backup, security, legal, and operational retention requirements.
- Server, security, rate-limit, and error logs — usually kept for up to 30 days, unless needed longer for security, abuse investigation, debugging, legal claims, or compliance.
- Aggregate analytics — kept in aggregated form and not used to identify you.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or port your personal data, and to withdraw consent.
You can make a request by emailing legal@details.so. We may need to verify your identity before acting on a request. Some data may be exempt from deletion or access where we need it for legal, security, billing, accounting, dispute, or fraud-prevention reasons.
You can revoke an authorized assistant connection in the MCP section of your Details account settings and disconnect Details in your assistant’s settings. You can also limit the information you share by omitting optional project context and keeping search requests relevant to the reference or resource you need.
You may also have the right to complain to a data protection authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC). In the EU or UK, you can contact your local supervisory authority.
10. California and other US privacy rights
We do not sell personal information and do not share it for cross-context behavioral advertising. We do not use sensitive personal information to infer characteristics.
If a privacy law gives you rights to know, access, correct, delete, or opt out of certain processing, you can exercise those rights by emailing legal@details.so.
11. Children
The Service is not directed to children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has provided personal data, contact us and we will take appropriate steps to delete it.
12. Security
We use reasonable technical and organizational measures to protect personal data, including HTTPS, access controls, provider-managed security controls, and limited internal access. No online service is completely secure, and we cannot guarantee absolute security.
13. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date shows when the current version took effect. For material changes, we may notify active account holders by email, in-product notice, or another reasonable method.
14. Contact
Questions or privacy requests? Email legal@details.so.