← Churnmend

Privacy Policy

Effective July 14, 2026

This policy explains what Churnmend (“we,” “us”) collects, how we use it, and the choices you have. Churnmend serves businesses (“founders”) that bill their customers through Stripe. Two roles matter here: for founder account data we are the controller; for the personal information of a founder's customers we are a processor/service provider acting on the founder's instructions.

1. What we collect

From founders (account holders):

About founders' customers (processed on the founder's behalf):

We never receive or store card numbers or bank details — payment credentials stay with Stripe. We also collect standard technical data needed to run and protect the service (such as IP-based rate-limit counters and server logs).

2. How we use it

We do not sell personal information and we do not use it for third-party advertising.

3. AI processing

Recovery emails may be personalized using an AI model provided by Anthropic. The model receives the founder's approved template and limited context about the failed payment (such as first name, amount, and decline reason). Outputs are validated before sending, and anything that fails validation falls back to the approved template. Our AI provider processes this data to provide the service to us and, per its API terms, does not train its models on it.

4. Who we share it with (subprocessors)

We may also disclose information if required by law, or as part of a merger or acquisition (in which case this policy continues to apply to previously collected data).

5. Cookies

The app uses essential cookies only — the session cookie that keeps a founder signed in. There are no advertising or cross-site tracking cookies.

6. Security

Data is encrypted in transit (TLS). Stripe tokens and widget secrets are encrypted at rest. Database access is locked down so that browsers can only read their own account's rows, all money-state writes go through controlled server paths, and key audit records are append-only. No system is perfectly secure, but the service is designed so the most sensitive actions are structurally impossible (for example, the code contains no path that can create a new charge).

7. Retention

Founder account data is kept while the account is active. Payment-recovery and cancel-flow records are kept while needed to provide the service and for bookkeeping and audit purposes, then deleted or de-identified. Unsubscribe records are kept as long as necessary to honor the request. You can ask us to delete your account data at any time (see below); we may retain what the law requires us to keep.

8. Your choices and rights

9. Where data is processed

Our infrastructure is hosted in the United States.

10. Children

The service is for businesses and is not directed to anyone under 16.

11. Changes

We may update this policy from time to time. Material changes will be announced by email or in the dashboard before they take effect.

12. Contact

Privacy questions or requests: support@churnmend.com.