Privacy Policy
Last Updated: November 18, 2025
TL;DR: We collect your email and questionnaire responses to generate personalized business ideas using AI. We don't sell your data. We use secure third-party services (Supabase, OpenAI, RevenueCat) to provide our service.
1. Introduction
Welcome to SideHustle AI ("we," "our," or "us"). We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application (the "App").
By using SideHustle AI, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Personal Information
When you create an account, we collect:
- Email Address: Used for account creation, authentication, and communication
- Password: Stored securely (hashed) and never shared
2.2 Questionnaire Data
To generate personalized side hustle ideas, we collect:
- Skills: Your professional and personal skills
- Interests: Topics and industries you're interested in
- Available Time: Hours per week you can dedicate
- Budget: Your starting capital for a side business
- Risk Tolerance: Your comfort level with business risk
2.3 Generated Content
We store:
- AI-Generated Plans: The personalized business plans created for you
- Usage History: Your past questionnaire responses and generated plans
2.4 Subscription Information
If you subscribe to premium:
- Subscription Status: Active, expired, or cancelled
- Purchase History: Transaction records (processed by Apple/Google, not us)
- Customer ID: Anonymous identifier from RevenueCat
2.5 Automatically Collected Information
- Device Information: Device type, operating system version
- Usage Data: App features used, session duration
- Error Logs: Crash reports and technical diagnostics
2.6 Information We Do NOT Collect
- ❌ We do NOT collect your location
- ❌ We do NOT access your contacts
- ❌ We do NOT access your photos
- ❌ We do NOT track you across other apps or websites
- ❌ We do NOT sell your data to third parties
3. How We Use Your Information
We use your information to:
- Provide Our Service: Generate personalized AI business plans based on your questionnaire
- Authenticate: Securely log you in and protect your account
- Process Payments: Manage your premium subscription
- Improve Our App: Analyze usage patterns to enhance features
- Customer Support: Respond to your questions and issues
- Send Updates: Notify you about new features or important changes (you can opt out)
- Legal Compliance: Comply with applicable laws and regulations
4. Third-Party Services
We use trusted third-party services to operate our app. Each has their own privacy policy:
4.1 Supabase (Database & Authentication)
- Purpose: Stores user accounts, questionnaire data, and generated plans
- Data Shared: Email, encrypted password, questionnaire responses
- Privacy Policy: supabase.com/privacy
- Location: Data stored in US-based servers (AWS)
4.2 OpenAI (AI Generation)
- Purpose: Generates personalized business plans using GPT-4
- Data Shared: Your questionnaire responses (skills, interests, budget, time, risk tolerance)
- Privacy Policy: openai.com/privacy
- Data Retention: OpenAI does NOT use your data to train their models (per their API terms)
- Note: No personally identifiable information (email, name) is sent to OpenAI
4.3 RevenueCat (Subscription Management)
- Purpose: Manages premium subscriptions and in-app purchases
- Data Shared: User ID, subscription status, purchase events
- Privacy Policy: revenuecat.com/privacy
4.4 Apple App Store / Google Play Store
- Purpose: Payment processing for subscriptions
- Data Shared: Handled directly by Apple/Google (we don't see payment details)
- Privacy Policies:
5. Data Security
We implement industry-standard security measures:
- Encryption in Transit: All data sent between your device and our servers is encrypted (HTTPS/TLS)
- Encryption at Rest: Data stored in our database is encrypted
- Password Hashing: Passwords are hashed using bcrypt (never stored in plain text)
- Row-Level Security: Database policies ensure you can only access your own data
- API Key Protection: OpenAI API calls happen server-side (not exposed in the app)
- Regular Updates: We keep our dependencies and security patches up to date
While we strive to protect your data, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
6. Data Retention
- Active Accounts: We retain your data as long as your account is active
- Deleted Accounts: When you delete your account, we permanently delete your personal data within 30 days
- Legal Obligations: Some data may be retained longer if required by law (e.g., transaction records for tax purposes)
- Backups: Data may persist in backups for up to 90 days after deletion
7. Your Rights
You have the following rights regarding your data:
7.1 Access
You can view all your data within the app (questionnaire history, generated plans, subscription status).
7.2 Correction
You can update your email or regenerate plans with new questionnaire responses.
7.3 Deletion
You can request account deletion by emailing us at privacy@sidehustleai.com. We will delete your data within 30 days.
7.4 Data Portability
You can request a copy of your data in a machine-readable format (JSON/CSV).
7.5 Opt-Out
You can opt out of marketing emails at any time (account-related emails cannot be disabled).
7.6 GDPR Rights (EU Users)
If you're in the European Union, you have additional rights:
- Right to restrict processing
- Right to object to processing
- Right to lodge a complaint with a supervisory authority
7.7 CCPA Rights (California Users)
California residents have the right to:
- Know what personal information is collected
- Know if personal information is sold or disclosed (we do NOT sell)
- Opt-out of the sale of personal information (not applicable - we don't sell)
- Request deletion of personal information
- Not be discriminated against for exercising these rights
8. Children's Privacy
SideHustle AI is NOT intended for users under 18 years old. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately, and we will delete it.
9. International Data Transfers
Your data may be transferred to and processed in countries other than your own. Our servers are located in the United States. By using our app, you consent to the transfer of your data to the US and other countries where our service providers operate.
We ensure adequate safeguards are in place for international transfers (e.g., Standard Contractual Clauses for EU users).
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. Significant changes will be communicated via:
- In-app notification
- Email to registered users
Continued use of the app after changes constitutes acceptance of the updated policy.
11. Do Not Track
We do not track users across third-party websites or apps. Our app does not respond to "Do Not Track" browser signals because we don't engage in tracking that would require such a response.
12. Data Breach Notification
In the unlikely event of a data breach that affects your personal information, we will:
- Notify affected users within 72 hours
- Provide details about the breach
- Explain steps we're taking to address it
- Offer guidance on protecting yourself
© 2026 SideHustle AI. All rights reserved.