// legal

Privacy Policy

Last updated: July 31, 2026

1. Overview

customer.log ("we", "us") provides real-time event logging for founders and small teams. This policy explains what data we collect, why, and the controls you have over it.

2. Data we collect

Account data — name, email address, and authentication details when you sign up. Event data — the events you log through the SDK, including channels, titles, messages, metadata, and tags. Usage data — aggregated counts of events for billing and feature health. Device data — basic browser and platform information needed to operate the web app.

3. How we use your data

We use your data to deliver and maintain the service: storing and displaying your events, delivering notifications to the channels you configure (Slack, email), generating AI summaries, and billing based on event volume. We never sell your data.

4. AI processing

When you enable AI summaries, event data is sent to Google's Gemini API to generate daily digests and weekly reports. Events are processed to produce summaries and are not used to train external models.

5. Third-party services

The service relies on: Firebase (authentication), MongoDB (data storage), Resend (email delivery), Google Gemini (AI summaries), and Slack (via webhooks you configure). Each provider processes data only as needed to run their part of the service.

6. Cookies

We use essential cookies to keep you signed in and functional cookies for the web app. We do not use advertising cookies.

7. Data retention and deletion

Event data is retained while your project is active. You can delete events from your dashboard, and deleting your account removes your projects, events, and usage records. Backup copies are purged per our retention schedule.

8. Security

Event ingestion is authenticated with per-project API keys. Sessions are protected with JWT and industry-standard practices. No system is fully immune to compromise, but we apply reasonable technical and organizational safeguards.

9. Data protection rights

Depending on your jurisdiction (including GDPR and CCPA), you may have the right to access, correct, export, or delete your personal data. Contact us at the address below and we will respond within 30 days.

10. Children's privacy

The service is intended for founders and teams operating a business. It is not directed to children under 13, and we do not knowingly collect their data.

11. Changes to this policy

We may update this policy as the service evolves. Material changes will be announced in the changelog and via email to account holders.

12. Contact

Questions about this policy can be sent to privacy@getcustomerlog.com.