Privacy Policy
Last updated: September 2026
1. Information We Collect
Account data: when you register, we collect your email address and authentication identifiers (via email/password or Google OAuth).
Integration data: to operate the recovery engine, we store the configuration you provide — your Stripe webhook signing secret, optional Stripe API secret key (for refunds), and Telegram chat ID. A WhatsApp number may be stored for upcoming founder alerts. Stripe secrets are encrypted at rest with AES-256-GCM when SECRETS_ENCRYPTION_KEY is configured on our servers.
Payment event data: when your Stripe account sends us an invoice.payment_failed or invoice.payment_succeeded event, we process and store the customer email, amount due, currency, and payment status necessary to perform the recovery service.
Billing data: purchases of Ronin Mind AI subscriptions are processed by Paddle, our Merchant of Record. We do not store your card details.
2. How We Use Information
To send automated payment recovery emails to your customers (on your behalf) and Telegram alerts to you as the merchant. WhatsApp founder alerts are coming soon.
To display recovery analytics in your dashboard.
To manage your subscription status and provide support.
We do not sell, rent, or trade your data or your customers' data to third parties.
3. Third-Party Processors
Supabase — authentication and database hosting.
Resend — transactional email delivery.
Paddle — payment processing and Merchant of Record.
Telegram and Meta (WhatsApp Cloud API, coming soon) — message delivery where you enable those channels.
Each processor handles data under its own privacy policy and only to the extent required to deliver the service.
4. Data Retention & Security
We retain recovery logs and integration settings while your account is active. You may request deletion of your account and associated data at any time from the dashboard or by emailing support@roninmindai.com.
Access to stored data is enforced with row-level security. Billing and secret columns cannot be updated by end-user sessions. Stripe secrets are encrypted at rest when encryption is configured.
Browser sessions: after you log in we store a signed session in first-party cookies on roninmindai.com only (Secure, SameSite=Lax, up to 7 days). The session refreshes while you use the product. Logging out deletes the cookies on this browser. We do not use session cookies for advertising.
5. Your Rights
Depending on your jurisdiction (including GDPR and CCPA), you may have rights to access, correct, export, or delete your personal data. Contact support@roninmindai.com to exercise these rights.
6. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced on this page with an updated revision date.
7. Contact
Ronin Mind AI — roninmindai.com. For any privacy question, email support@roninmindai.com, message WhatsApp +37360480287, or Telegram @igorlupan.