Legal
Privacy Policy
Effective date: 1 March 2026 · Last updated: 1 March 2026
Fiftycore ("we", "us", or "our") is operated by Harsh Surela. This Privacy Policy explains how we collect, use, share, and protect personal information when you use fiftycore.com and the related application (the "Service"). By using the Service you agree to the practices described here.
1. Information We Collect
1.1 Account information
When you register or sign in, we collect your email address and, if you sign in via OAuth (Google), your name and profile picture as provided by the identity provider.
1.2 Content you create
We store the ideas, project details, report content, execution outcomes, and any other content you submit while using the Service ("User Content"). This is necessary to deliver the core features of the platform.
1.3 Usage data
We automatically collect information about how you interact with the Service, including pages visited, features used, timestamps, device type, browser type, and IP address. This data is used to improve the Service and monitor for security issues.
1.4 Payment information
We do not collect or store payment card details. All payment processing is handled by Paddle.com (our Merchant of Record). Paddle may collect billing name, address, and payment details directly. Their use of that data is governed by Paddle's Privacy Policy.
1.5 Cookies and local storage
We use authentication cookies managed by Supabase to keep you signed in. We also use localStorage to store a temporary anonymous client identifier before you register. No third-party advertising cookies are used.
2. How We Use Your Information
To create and manage your account and authenticate your identity.
To generate AI-powered market validation reports, design specs, and execution plans using your submitted content.
To deliver, operate, and improve the Service.
To process subscriptions and communicate billing-related information via Paddle.
To send transactional emails (account verification, password reset, subscription confirmations). We do not send unsolicited marketing emails.
To detect and prevent fraud, abuse, and security incidents.
To comply with applicable legal obligations.
We do not use your User Content to train AI models without your explicit consent.
3. Third-Party Services
We share data with the following third-party providers to operate the Service:
Supabase
Authentication and PostgreSQL database hosting. Stores account data and User Content. Data is processed in accordance with Supabase's data processing agreement and GDPR Standard Contractual Clauses.
Google (Gemini API)
AI text generation. Your submitted idea and project text is sent to Google's Gemini API to produce report content. Google's API usage policies apply. We use the API in a manner that prohibits Google from using your data for model training.
Paddle.com
Payment processing and subscription management. Paddle acts as the Merchant of Record and processes all billing on our behalf. Your payment data is held by Paddle and governed by their privacy policy.
Vercel
Cloud hosting and CDN infrastructure. Request logs including IP addresses may be retained by Vercel per their data retention policies.
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
4. Data Retention
We retain your account and User Content for as long as your account is active. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required to retain it for legal or compliance purposes (for example, billing records required by tax law).
5. Security
We implement industry-standard security measures including HTTPS/TLS encryption in transit, access controls, and row-level security in our database. While we take reasonable steps to protect your data, no system is completely secure. You are responsible for keeping your account credentials confidential.
6. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
Access — request a copy of the personal data we hold about you.
Correction — ask us to correct inaccurate or incomplete data.
Deletion — request deletion of your personal data.
Portability — request your data in a structured, machine-readable format.
Objection / Restriction — object to or restrict certain processing activities.
To exercise any of these rights, email us at founder@fiftycore.com. We will respond within 30 days.
7. Children's Privacy
The Service is not directed to children under the age of 18. We do not knowingly collect personal information from anyone under 18. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the revised version on this page with an updated effective date. Continued use of the Service after a change constitutes acceptance of the revised policy.
9. Contact
For any privacy-related questions or requests:
