Privacy
What Termind collects, what it never collects, where it is stored, and how long it is kept.
Last updated 29 July 2026
Who we are
Termind is a product analytics service. Customers install our tracking script on their own websites and applications, and we process the resulting data on their behalf.
For data collected through our customers' websites, our customer is the data controller and Termind is the data processor. For data about our own customers — account details, billing, support — we are the controller.
What we collect
Through the tracking script: page URL and path, referrer, UTM parameters, page title, viewport size, browser language, a randomly generated anonymous identifier stored in the visitor's browser, and a session identifier that expires when the browser session ends.
When our customer calls identify(), we additionally store the user identifier and any traits they choose to send, such as an email address or plan name.
When a customer connects Stripe, we read subscription, invoice, charge and refund records in order to show MRR, subscriptions and recorded revenue.
We do not collect full IP addresses by default, we do not use third-party advertising cookies, and we do not track visitors across unrelated websites.
What the tracker does not capture
The current tracking script does not read the contents of form inputs or record session replays.
For batch events, ingestion removes a fixed set of exact top-level property names associated with credentials or payment data, plus configured sensitive URL parameters. Customers remain responsible for not sending restricted data through custom events, identify() or group().
Legal basis and consent
Our customers decide the lawful basis for collection on their own sites and are responsible for obtaining any consent their jurisdiction requires. Customers can withhold the tracking script until consent is obtained.
The script and ingestion endpoint honour the browser Do Not Track signal when that option is configured.
Where data is stored
Data is stored in the European Union (Ireland). Application servers run in the same region to keep processing local.
Every workspace is isolated at the database level by row-level security, so one customer's queries cannot return another customer's rows.
Retention
Ingestion rejects events older than the workspace's configured event-acceptance window. Automatic retention deletion is not currently available.
Workspace records use cascading database relationships. Contact us by email to request export or deletion.
Subprocessors
We use Supabase for database, authentication and storage; Vercel for application hosting; Google (Gemini API) for the AI analysis features; and Stripe for payment data when a customer connects it.
The current Ask flow sends computed analytics and a compact evidence pack to the AI provider. If recent feedback or release text exists in the workspace, that text may also be included. Raw event rows are not sent by the current Ask flow.
Your rights
If you are an end user of a site that uses our service, contact that site's operator — they control the data and can ask us to help with an access, export or deletion request.
If you are our direct customer, contact us by email to request access, export or deletion.
Contact
Questions about this policy can be sent to us by email.
Questions? Email us.
This document describes how the product works. It is not legal advice. Back to home