MilestoneGlow ("we", "our", "us") operates the website milestoneglow.com and the MilestoneGlow web application. This Privacy Policy explains how we collect, use, store, and protect your information when you use our service.
By using MilestoneGlow, you agree to the terms of this Privacy Policy.
1. Information We Collect
1.1 Information You Provide Directly
- Email address — when you create an account or sign in
- Payment information — processed securely by DodoPayments (we never store your card details)
- Template content — text, numbers, and colors you enter in the editor
1.2 Information Collected Automatically
- Usage data — pages visited, features used, export count
- Device information — browser type, operating system, screen resolution
- IP address — for security and fraud prevention
- Cookies and local storage — to keep you logged in and remember preferences
1.3 Information from Third-Party Integrations
When you connect external services, we may receive:
- GitHub — public repository stars, forks, follower counts (public data only)
- YouTube — public subscriber and view counts (public data only)
- TrustMRR — verified MRR and startup data (only what you explicitly authorize)
- Reddit — public subreddit subscriber counts (public data only)
We only access public data from these integrations. We do not access private messages, private repositories, or any non-public data.
2. How We Use Your Information
We use your information to:
- Provide the service — create your account, process exports, track usage limits
- Process payments — verify your plan (Free, Pro, or Lifetime)
- Send transactional emails — account confirmation, export limit warnings, payment receipts
- Improve the product — understand which templates and features are used most
- Prevent abuse — detect fraudulent activity and enforce usage limits
- Comply with legal obligations — respond to lawful requests from authorities
We do not sell your personal data to third parties. We do not use your data for advertising purposes.
3. Data Storage and Security
- Your data is stored securely using Supabase (PostgreSQL database with Row Level Security)
- Passwords are never stored — we use magic link authentication via Supabase Auth
- Payment data is handled entirely by DodoPayments — we never see your card numbers
- All data is transmitted over HTTPS/TLS encryption
- We store data on servers located in the United States / European Union
- Export files (MP4/WebM) are generated entirely in your browser and never uploaded to our servers
4. Cookies and Tracking
We use the following cookies:
| Cookie | Purpose | Duration |
|---|
| sb-auth-token | Supabase authentication session | Session |
| user-plan | Cache your current plan locally | 24 hours |
| Analytics cookies | Understand usage patterns (anonymized) | 30 days |
You can disable cookies in your browser settings. Note that disabling authentication cookies will prevent you from staying logged in. We do not use advertising cookies or cross-site tracking.
5. Third-Party Services
| Service | Purpose |
|---|
| Supabase | Authentication and database |
| DodoPayments | Payment processing |
| Resend | Transactional email |
| Vercel | Website hosting |
| GitHub API | Fetch public repo stats |
| YouTube API | Fetch public channel stats |
| Reddit API | Fetch public subreddit stats |
| TrustMRR API | Fetch verified MRR data |
6. Data Retention
- Account data — retained while your account is active
- Export history — retained for 12 months
- Payment records — retained for 7 years (legal requirement)
- Deleted accounts — all personal data deleted within 30 days of account deletion
7. Your Rights
Depending on your location, you may have the following rights:
- Access — request a copy of your personal data
- Correction — update incorrect or incomplete data
- Deletion — request deletion of your account and data
- Portability — receive your data in a machine-readable format
- Objection — object to certain types of processing
- Restriction — request we limit how we use your data
For EU/EEA users (GDPR): You have the right to lodge a complaint with your local data protection authority.
For California users (CCPA): You have the right to know what data we collect and to request deletion.
To exercise any of these rights, email us at: privacy@milestoneglow.com
8. Children's Privacy
MilestoneGlow is not intended for users under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such data, please contact us immediately at privacy@milestoneglow.com.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do:
- We will update the "Last Updated" date at the top
- For significant changes, we will notify you by email
- Continued use of MilestoneGlow after changes constitutes acceptance
10. Contact Us
For privacy-related questions or requests: