This policy explains how SUMERA handles personal data when you visit sumera.io or use the service.
Data we collect
We collect account and profile information you provide, such as your name, email address, business details, preferences, and services. We also store the topics, answers, scripts, and production notes you create in SUMERA.
When you register, we keep one account record containing your account identifier, email, name, registration time, authentication method, browser and device category, language, timezone, screen dimensions, and approximate country, region, and city supplied by our hosting edge. We also keep the first SUMERA page you opened, the referring site name, and campaign labels when present. This first-touch record does not contain a browsing history, a full referring URL, or your raw IP address.
When you use the service, we receive technical and usage information such as pages visited, feature events, browser and device information, approximate location derived from IP address, and error diagnostics. Stripe sends us billing status, plan, transaction identifiers, and a card fingerprint that can identify the same payment method without revealing the card number. For trial protection, SUMERA stores a one-way cryptographic version of that fingerprint with the trial decision and coarse card country, funding, and wallet type when available. SUMERA does not receive or store your complete card number.
How we use data
We use personal data to provide and secure your account, generate and save scripts, enforce plan and trial limits, prevent repeated use of introductory offers, process subscriptions, answer support requests, diagnose errors, improve the product, and meet legal obligations.
We send script inputs and relevant profile context to the AI provider selected for a generation request. We do not sell personal data. We do not use your private scripts to train a SUMERA model.
Service providers and international processing
SUMERA operates first-party account authentication and uses service providers to run the product: Clerk temporarily supports migration of existing accounts, Stripe handles billing, OpenAI and Anthropic provide AI generation, Vercel hosts the application, a PostgreSQL database on SUMERA infrastructure stores product data, Resend delivers transactional email, and Sentry supports error diagnostics.
With your consent, we may also use PostHog, Google Analytics/Google Ads, and OpenAI Ads measurement tools to understand visits and attribute advertising conversions. These providers may process data outside your country under their own terms and safeguards.
Advertising, analytics, and consent
Non-essential analytics and advertising measurement are disabled until you choose “Accept analytics.” If you reject them, the core service remains available. You can change your choice at any time using the Privacy choices control in the site footer.
The limited first-touch record described above helps us understand which pages and campaigns lead to an account. It uses a first-party cookie and does not load a third-party analytics service. At checkout, a coarse source label and landing category may be copied to the Stripe subscription record so billing and acquisition can be reconciled. We do not send Stripe the full referring URL or a browsing history.
When consent is granted, the registration record may also contain advertising reference identifiers so a later signup or purchase can be attributed to the correct campaign. These advertising identifiers are omitted when consent is rejected and cleared when consent is withdrawn. For server-side conversion measurement, identifiers such as email addresses are normalized and cryptographically hashed before being sent.
For signed-in accounts, we record product navigation and named feature actions as operational account activity even when non-essential analytics consent is declined. This record contains the account, action, product path or feature surface, time, and an opaque per-tab session identifier; it does not contain script text, payment-card details, referring URLs, advertising identifiers, or raw IP addresses.
Storage, security, and retention
Account and product data is stored in PostgreSQL with access controls and encrypted network connections. We use reasonable technical and organizational safeguards, but no online service can guarantee absolute security.
We keep account data while your account is active and as needed to provide the service. Billing, transaction, and pseudonymous trial-protection records may be retained for tax, accounting, fraud prevention, and legal requirements. Support messages and security logs are retained only as long as reasonably necessary for those purposes.
Your content
You retain your rights in the original inputs and scripts you create. You give SUMERA a limited right to process that content only as needed to operate, secure, and support the service. AI output may contain errors or material similar to existing content, so you are responsible for reviewing it before publication.
Your choices and rights
Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to processing of personal data, and to withdraw consent. You may also cancel a subscription through the billing portal.
Submit a request through the contact form. We may need to verify your identity before acting on a data request. You may also complain to your local data-protection authority.
Changes and contact
We may update this policy when the product or legal requirements change. Material changes will be communicated through the service or by email when appropriate.
For privacy questions or requests, use the contact form and select “General inquiry.”