Privacy Policy
Last updated: August 2026
AutoTraction is a marketing platform for solo founders. This policy explains, in plain language, what data we collect, why we collect it, who processes it, and how to get it deleted. If anything here is unclear, email us and we will give you a straight answer.
What we collect and why
Account. Your email address and a password (or your Google sign-in), handled by Supabase Auth. We need this to know which workspace is yours.
Brand inputs. What you tell us about your product, audience, and voice during onboarding. This is the raw material for everything we draft for you.
Connected accounts. When you connect a social or ad account (Meta, X, TikTok, LinkedIn, Reddit), the platform gives us an access token limited to the scopes you approved. We store these tokens encrypted at rest with AES-256-GCM, alongside the account id and display name so you can see what is connected.
Content. Drafts, published posts, launch assets, and other marketing material we generate for you or you write in the product.
Site analytics. If you install our tracking snippet on your own site, it sends us events from that site: pageviews, signups, purchases, the page URL, referrer, UTM parameters, ad click ids, and a random per-browser session id kept in localStorage. This exists so you can see which marketing actually works. We do not use it to build profiles of your visitors across other sites.
Billing. Payments run through Stripe-hosted checkout. Card numbers go to Stripe, never to us. We store your Stripe customer id and a ledger of the credits you have bought and spent.
Outreach data. If you use outreach, we store the leads you source (names, emails, companies), the mailboxes used to send, the messages sent and replies received, and a suppression list so people who opt out stay opted out.
What we never do
- We never sell your data, or anyone else's data, to anyone.
- We never post, message, or act on a connected account beyond what you have explicitly authorized in the product.
- We never read or request data from connected accounts beyond the scopes you granted when connecting them.
Third-party processors
We use a small set of services to run AutoTraction. Each one only receives what it needs:
- Supabase: database and authentication.
- Vercel: application hosting.
- Cloudflare: DNS, domain registration, and email routing for domains managed through the product.
- Stripe: payments and billing.
- Anthropic and OpenRouter: AI text generation. Your brand inputs and content prompts are sent to these providers to generate drafts.
- InboxKit: outreach mailbox provisioning.
- Platform APIs (Meta, X, TikTok, LinkedIn, Reddit): used to publish and manage what you approved, on the accounts you connected.
Data retention
We keep your data for as long as your account is active. When you delete your account, or ask us to, we delete your workspace data: brand inputs, content, connected-account tokens, analytics events, and outreach records. Billing records are kept as long as tax and accounting law requires. Backups roll off on the infrastructure providers' standard schedules.
Deletion rights
Email support@autotraction.ai from your account email and we will delete your data. No forms, no retention offers.
If you connected a Meta account, you can also trigger deletion from Meta itself: remove AutoTraction in your Facebook settings and Meta will send us a deletion request. We delete the stored connection and tokens and give you a confirmation code you can check on our data deletion status page.
Cookies
The app uses cookies for one thing: keeping you signed in (the Supabase auth session). No advertising cookies, no third-party tracking cookies. The analytics snippet you may install on your own site does not set cookies either; it keeps a random session id in the browser's localStorage on your site.
Contact
Questions about this policy or your data: support@autotraction.ai.
AutoTraction, autotraction.ai. Terms of Service