Privacy Policy
Your revenue is public because you chose to publish it. Nothing else about you is — and the list of what we collect is short enough to read.
Last updated August 11, 2026 · Operated by Lior Pesoa
1. Who is responsible
Lior Pesoa operates didihit1mmrr.com and didih.it and is the data controller for the personal data described here. Contact: privacy@didihit1mmrr.com.
This policy covers the website, the founder dashboard, the public profiles, and the embeddable widgets. It does not cover the payment providers you connect, or any other site we link to.
2. What we collect
Account data. Your email address, which is how you sign in — we send a link to it rather than storing a password. Sign-in timestamps.
Profile data. Whatever you choose to publish: username, display name, avatar, bio, reporting currency, start date, and whether your profile is listed at all.
Startup data. The names, descriptions, websites, and logos of the startups you add, and which of them count towards your public number.
Revenue data. From each payment provider you connect we read aggregate metrics only: monthly recurring revenue, annual run rate, active subscription count, and currency, stored as dated snapshots so the chart has a history.
Provider credentials. API keys or OAuth tokens for the providers you connect, encrypted with AES-256-GCM before they are stored. They are never shown back to you or to anyone else, and we ask only for read-only access.
Content you write. Public updates, their titles and bodies, and which startup each one is about.
Technical data. Standard server and request logs — IP address, user agent, pages requested, timestamps — kept for security, abuse prevention, and debugging.
3. What we deliberately do not collect
From your connected payment providers we do not read, request, or store: your customers’ names or email addresses, subscriber or customer lists, individual invoices, transactions, or payment methods, card numbers, bank details, or payout information.
We do not run analytics, advertising, or tracking scripts, and we do not sell, rent, or share personal data with data brokers or advertisers. Ever.
4. What becomes public
The point of the service is a public scoreboard, so some of what you give us is published by design: your username, display name, avatar, bio, verification status, the aggregate MRR of the startups you chose to include, its history over time, the startups themselves if you marked them public, and any updates you write.
Published data is served on public pages, in social preview images, and in embeddable widgets that anyone can put on any site. Search engines, archives, and other people’s caches will copy it. Unpublishing something removes it from us; it does not recall copies that already left.
Your email address is never published. Neither is any credential, nor any individual transaction.
5. Why we process it, and on what legal basis
To provide the service you asked for — running your account, syncing your revenue, publishing your profile. Legal basis: performance of our contract with you.
To keep the service working and safe — logging, rate limiting, preventing abuse and fraudulent numbers. Legal basis: our legitimate interests in a service that is not trivially gameable.
To contact you about the service — sign-in links, and notices when a sync breaks or something material changes. Legal basis: contract, and legitimate interests.
To take payment where you buy something optional. Legal basis: performance of a contract, and our legal obligations around tax records.
To comply with the law when we are required to. Legal basis: legal obligation.
Where we ask for consent — for anything optional, such as sending a URL to an AI service to draft a form for you — you can decline, and declining costs you nothing but that feature.
6. Who else processes it
We keep the list short on purpose. Each of these is a processor acting on our instructions, under a data processing agreement:
- Supabase — database, authentication, and the emails that carry your sign-in links.
- Vercel — hosting, edge delivery, and server logs.
- Polar Software Inc. — payments, as merchant of record, if and when you buy something. Polar collects your billing details directly; we receive a record that a purchase happened, not your card.
- Anthropic — only if you use the optional autofill button, and only for that request: the website address you entered and text from that public page are sent to draft your startup’s details. No account, revenue, or customer data is sent, and the output lands in a form you can edit before anything is saved.
- The payment providers you connect yourself — Stripe, Polar, Lemon Squeezy, Paddle, Creem, Dodo Payments. Here they are your providers, not ours; their own privacy policies govern the account you are connecting.
We will also disclose data where we are legally required to, or where it is necessary to investigate abuse or protect someone’s safety. If we are ever acquired, data may transfer with the service, and you would be told before it did.
8. Where it is stored
Our providers operate in the United States and the European Union, so your data may be processed outside your country. Where data leaves the EEA or the UK, transfers rely on the European Commission’s Standard Contractual Clauses or another approved safeguard in our agreements with those providers.
9. How long we keep it
Account, profile, startup, and revenue data: for as long as your account exists.
Provider credentials: until you disconnect that provider, at which point the encrypted credential is deleted.
Server logs: a short rolling window, typically no more than 30 days, unless a specific security investigation needs longer.
Payment and tax records: as long as tax and accounting law requires, which is generally several years, and is handled by Polar as merchant of record.
When you delete your account, your profile, startups, revenue snapshots, updates, and stored credentials are deleted. Backups age out on their own cycle, and anything already copied by search engines, archives, or people who embedded your widget is beyond our reach.
10. Your rights
You can access, correct, export, or delete your data. Most of it you can do yourself from the dashboard, immediately: edit your profile, unpublish a startup, disconnect a provider, delete your account.
Depending on where you live you may also have the right to object to or restrict processing, to withdraw consent, to data portability, and to complain to your local data protection authority. In the EEA or the UK that is your national supervisory authority; in Israel it is the Privacy Protection Authority.
If you are in California, note that we do not sell or share personal information as those terms are defined by the CCPA, and we do not discriminate against anyone for exercising their rights.
To exercise anything you cannot do from the dashboard, email privacy@didihit1mmrr.com. We answer within 30 days, and we may need to confirm you control the account’s email address first.
11. Security
Everything is served over HTTPS. Provider credentials are encrypted at rest with AES-256-GCM using a key held only in server environment configuration, and they are never sent to the browser. Access to your rows is enforced in the database itself through row-level security, not only in application code. Requests to third-party sites on your behalf are restricted so they cannot be pointed at our internal network.
No system is perfectly secure. If you find a vulnerability, please tell us at privacy@didihit1mmrr.com before telling anyone else, and we will work with you.
12. Children
The service is not intended for anyone under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
13. Changes to this policy
When this policy changes we update the date at the top of the page. If a change materially affects how we handle your data, we will make a reasonable effort to tell you directly before it takes effect.
Questions, requests, or complaints: privacy@didihit1mmrr.com.