What this policy covers
This Privacy Policy describes how GravyPicks LLC ("we", "us", "our") collects, uses, and discloses information about you when you use our website and services. We've tried to keep this short and honest. If you have questions, email hello@gravypicks.com.
Information we collect
What you give us directly
- Email address — when you sign up via Google or email, captured through our identity provider, Clerk.
- Name and profile photo — if you sign in with Google, we receive your name and profile picture so we can show them on your account page.
- Subscription billing information — handled entirely by Stripe. We never see or store your credit card number. Stripe sends us only a customer ID and your subscription status.
What we collect automatically
- Session cookies — a single secure cookie (set by Clerk) keeps you signed in across visits.
- Request logs — Vercel records standard web-server logs (IP address, user agent, request paths) for security and operations. These are retained per Vercel's standard policy.
What we don't collect
- We do not use Google Analytics, Facebook Pixel, or any third-party advertising tracker.
- We do not sell or rent any user information.
- We do not access your browsing activity outside of GravyPicks.
How we use information
- To create and maintain your account.
- To bill your subscription via Stripe.
- To deliver picks, emails, and other communications you request.
- To detect, prevent, and respond to fraud, security incidents, and abuse.
- To comply with applicable laws.
Third parties we use
We share data with the following service providers as needed to operate the service:
- Clerk Inc. — authentication and identity management. Sees your email, name, profile photo, and sign-in activity.
- Stripe Inc. — payment processing. Sees your billing details, payment method, and subscription history.
- Supabase Inc. — database hosting. Stores your profile, subscription status, and your sign-in activity.
- Vercel Inc. — application hosting. Sees IP addresses and request logs.
- Anthropic PBC — provides AI capabilities used to generate our daily picks. We do not send any of your personal data to Anthropic.
Each of these providers has their own privacy policy and security practices that apply to the data we share with them.
Your rights
Depending on your state, you may have one or more of the following rights:
- Right to access — request a copy of the personal data we hold about you.
- Right to delete — request that we delete your account and associated data.
- Right to correct — request that we update inaccurate or incomplete data.
- Right to opt out — opt out of any future sale of your data (we currently do not sell data).
To exercise any of these rights, email hello@gravypicks.com from the address associated with your account. We will respond within 30 days.
California residents have specific rights under the California Consumer Privacy Act (CCPA). The list above describes those rights as they apply to our service.
Data retention
- Active accounts: we retain your data for as long as you maintain an account.
- Closed accounts: we delete personal identifiers within 30 days of account closure, except where we are required by law (e.g., tax records) to retain certain data longer. Aggregated, anonymous statistics may be retained indefinitely.
- Stripe billing records: retained by Stripe in accordance with their compliance obligations.
Security
We use industry-standard security practices: HTTPS everywhere, secure cookies, encrypted database connections, and least-privilege access controls. No system is perfectly secure, but we work to make ours as secure as we reasonably can.
Children
Our service is intended for users 21 and older. We do not knowingly collect personal information from anyone under 21. If you believe a minor has provided us with information, contact us immediately and we will delete it.
International users
GravyPicks is intended for users in the United States. Our servers and service providers are located in the U.S. If you access the service from outside the U.S., you consent to having your data transferred to and processed in the U.S.
Changes to this policy
We may update this Privacy Policy from time to time. We will post any changes on this page and update the "Last updated" date at the top. Material changes will be communicated by email at least 14 days before they take effect.
Contact us
Privacy questions or requests: hello@gravypicks.com.