Privacy Policy

Last updated: March 20, 2026

1. What We Collect

Account data: Email address (required for login). We do not collect passwords - authentication uses one-time codes or passkeys.

Amazon affiliate tag: Provided by you voluntarily to enable commission tracking.

Funnel data: Amazon product URLs you submit, generated funnel content, and funnel performance metrics (visits, clicks).

Usage data: IP address hashes (not full IPs), user agent strings, and page referrers for analytics. We hash IP addresses before storage - we cannot recover your actual IP.

2. How We Use Your Data

We use your data to: provide the funnel generation service; track visits and clicks for your dashboard analytics; determine traffic splitting for affiliate tags; send login codes via email; and improve the Service.

3. Third-Party Services

Amazon: We access publicly available product data from Amazon.com to generate funnels. Funnel visitors are redirected to Amazon with affiliate tags.

Anthropic (Claude AI): Product data is sent to Anthropic's API to generate funnel content. See Anthropic's Privacy Policy.

Resend: Used to deliver login code emails. See Resend's Privacy Policy.

4. Data Retention

Account data is retained while your account is active. Funnel data is retained indefinitely unless you delete your funnels. Visit and click logs are retained for 90 days. You can delete your funnels at any time from the dashboard.

5. Cookies

We use a single session cookie (funnel_session) for authentication. It is httpOnly, secure, and expires after 30 days. We do not use tracking cookies, advertising cookies, or third-party analytics.

6. Your Rights

You can: access your data via the dashboard; delete your funnels and associated data; close your account by contacting us. For EU residents (GDPR): you have rights to access, rectification, erasure, and data portability.

7. Security

Data is transmitted over HTTPS. Passwords are not stored (we use passwordless authentication). IP addresses are hashed. Sessions use cryptographically secure tokens.

8. Children

The Service is not intended for children under 18.

9. Changes

We may update this policy. We'll notify registered users of material changes via email.

10. Contact

Privacy questions? Email hello@funn.to.