Legal

Privacy Policy

How we collect, use and protect your information.

Last updated: September 2, 2026

This Privacy Policy explains how Suelo Piotr Osmola (“SaaS or Pass”, “we”, “us” or “our”) processes personal data when you use the SaaS or Pass website, anonymous swipe experience, founder dashboard, submission and capture tools, response-credit billing and related services (the “Service”).

1. Controller and contact

SaaS or Pass is operated by:

  • Legal entity: Suelo Piotr Osmola
  • Registered address: Ptaszkowa 920, 33-333 Ptaszkowa, Poland
  • Company / registration number: 122557840
  • VAT / tax ID: PL7343434569
  • Privacy and support contact: support@saasorpass.now

For GDPR purposes, Suelo Piotr Osmola is the controller of the personal data described in this Policy.

2. Data we process

Account and authentication data

Founder accounts may include:

  • email address and email-verification status;
  • optional first and last name;
  • account role, settings and creation or update timestamps;
  • response-credit balances, grants, reservations and account activity; and
  • a Stripe customer identifier when billing features are used.

Authentication uses passwordless email one-time codes. We process a hashed code, expiry time, attempt count, use status and keyed rate-limit signals. We do not store the one-time code in plain text.

Anonymous visitors and swiping

You can browse and respond without creating an account. Anonymous does not mean untracked: we use opaque, first-party identifiers to maintain feed progress and protect response integrity. The short-lived sop_anonymous_session identifier has a rolling 24-hour lifetime. The separate durable sop_anonymous_voter identifier has a rolling 180-day lifetime so clearing or replacing a progress session does not make the same product eligible again.

Depending on how you use the swipe experience, we process:

  • generated anonymous voter and session identifiers, stored server-side only as cryptographic hashes;
  • product impressions, start and completion times, skips and coarse referrer class;
  • PASS or TRY verdicts, comprehension choices and an optional short response reason;
  • visible exposure duration and the interaction method submitted with a response;
  • the first destination-visit time associated with a response and raw outbound product-click events;
  • coarse language/locale and a coarse mobile or desktop device class; and
  • quality and validity status used to decide whether a response counts.

Public discovery clicks record the product, test, source and timestamp. They do not store an IP address, network hash, cookie, session, user agent or browser fingerprint. Swipe-reveal clicks may be linked to the response that caused the reveal so visit metrics can be calculated.

Founder submissions and captured website data

When a founder submits a product, we process information such as:

  • the submitted and normalized URL, domain and final destination;
  • product name, tagline, category and comprehension-answer drafts;
  • desktop and mobile first-viewport screenshots and, where available, a site icon;
  • bounded page title, description and rendered plain text extracted from the public page;
  • capture status, sanitized failure information and provider request identifiers; and
  • submission, version, approval, moderation and audit information.

Product content is distinct from private account data. Once approved, product identity, submitted metadata, screenshots, destination links and aggregated testing or discovery metrics may be shown publicly in the swipe reveal, rankings and other discovery surfaces. Individual founder reports remain account-restricted.

Website fetching and screenshots

Our capture infrastructure visits a submitted public URL and the public resources needed to render it. It checks redirects and destinations, creates separate desktop and mobile screenshots, and extracts limited metadata needed to prepare and operate a test. The capture process does not receive SaaS or Pass account cookies, application credentials or authorization headers. Submitting a website does not transfer ownership of that website to us.

AI-assisted submission processing

Server-side OpenAI tools may process the submitted URL, captured title, description and rendered page text, founder-edited fields, and the two captured screenshots. They are used narrowly to suggest a category and comprehension answers, screen content, and recommend automatic approval or human review of a software landing-page submission.

We store bounded run information such as status, input hash, model and prompt versions, provider response ID, token usage, reason codes, result summary, timing and sanitized failure code. We do not store model reasoning or duplicate screenshots in the AI-run record, and requests are configured not to be stored by the OpenAI API. AI output can be inaccurate. AI never automatically rejects a submission; uncertain or risky results are routed for review. This processing does not make legal or similarly significant decisions about people.

Payments and billing

If you purchase response credits, Stripe processes checkout and payment details. Stripe may collect your legal name, email, billing address, company details, VAT or tax ID, payment method and invoice information. Card details and raw payment credentials are handled by Stripe rather than stored by SaaS or Pass.

We retain the Stripe customer, checkout-session and payment-intent identifiers; selected package and credit quantity; configured subtotal, tax and charged total; currency; payment, fulfillment and refund status; and related timestamps. The authenticated Stripe Customer Portal lets founders update billing information and download invoices.

Email and communications

Brevo delivers email one-time codes and may deliver other account, security, payment or service-related messages. If you contact us directly, we process the contact details and message content needed to respond. SaaS or Pass does not currently operate a newsletter or marketing-email system.

Operational and security records

We process bounded request, event, entity, status, timing and sanitized error information to run, debug and secure the Service. Application logs are designed not to include submitted URL paths or query strings, emails, request bodies, cookies, one-time codes, payment payloads or secrets.

3. How we use data

We use the data described above to:

  • provide anonymous discovery, voting, founder accounts, submissions, reports and billing;
  • authenticate users and deliver requested transactional messages;
  • capture submitted public websites and prepare editable submission drafts;
  • count valid responses, show separate interest and clarity measures, and produce public rankings;
  • track destination visits and raw product-link activations without creating advertising profiles;
  • prevent duplicate or manipulated responses, bots, fraud and infrastructure abuse;
  • moderate submissions, investigate problems and enforce our Terms;
  • process purchases, taxes, invoices, credit fulfillment and refunds; and
  • meet accounting, tax, legal and regulatory obligations.

4. Vote integrity and abuse prevention

Response integrity is central to SaaS or Pass. We use voter and session continuity, server timing, signed feed offers, rate limits, quality checks and Cloudflare Turnstile to detect automation, reduce repeated or manipulated responses, protect purchased founder results and keep rankings meaningful.

A trusted network address may be processed briefly in memory and converted immediately into rotating, HMAC-protected abuse signals. We intentionally do not persist or log the raw or truncated IP address and do not create a browser fingerprint. Short-lived network-completion records and keyed rate-limit buckets support bounded voter, network and product-level controls. Turnstile verification sent by our server does not include the raw client address, although Cloudflare may independently receive browser and network information when providing its challenge technology.

5. Cookies and similar technologies

SaaS or Pass currently uses first-party cookies and similar technologies for necessary functions:

  • Authentication: session and request-security cookies maintain a signed-in session, protect authentication flows and reduce one-time-code abuse. The dedicated authentication client identifier has a 30-day lifetime, while the signed-in session is configured for up to seven days.
  • Anonymous swiping: the 24-hour progress session and 180-day voter identifier maintain feed continuity and enforce one-response-per-test protections.
  • Security: Cloudflare Turnstile and server-side anti-abuse controls distinguish legitimate use from automated or manipulated traffic.

The current Service does not use non-essential advertising, cross-site marketing or optional analytics cookies. Product click records are functional, server-side event records and do not use a persistent click-tracking identity. Blocking necessary cookies may prevent sign-in or anonymous response continuity from working correctly.

6. Service providers and disclosures

We use service providers only for the purposes needed to operate the Service. These include:

  • Stripe for customer records, checkout, payments, tax calculation, tax IDs, invoices, refunds and the billing portal;
  • Brevo for email one-time codes and transactional email delivery;
  • Cloudflare for Turnstile bot and abuse protection;
  • OpenAI for submission drafting, classification and moderation assistance;
  • Vercel for private screenshot and icon storage through Vercel Blob and, where selected, application hosting and server infrastructure;
  • Browserless, when the hosted-browser capture mode is selected, for isolated browser infrastructure used to access submitted public pages;
  • our configured PostgreSQL infrastructure provider for application and account records; and
  • Google Fonts for web-font delivery, which can cause your browser to connect to Google when a page loads.

A deployment may instead use the isolated managed Chrome capture service included with SaaS or Pass. We may also disclose information to professional advisers, authorities or other parties when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or complete a business reorganization with appropriate safeguards. We do not sell personal data.

7. Legal bases

Where the GDPR applies, our legal bases are:

  • Performance of a contract: to provide a requested founder account, submission, report, credit purchase, invoice, support response or related Service feature.
  • Legitimate interests: to provide anonymous discovery, maintain fair response and ranking systems, prevent fraud and abuse, secure and troubleshoot the Service, moderate listings and improve reliability. We balance these interests against affected users’ rights.
  • Legal obligations: to comply with tax, accounting, consumer-protection, payment and lawful authority requirements.
  • Consent: only where we specifically request it for an optional activity or applicable law requires it. Consent is not the blanket basis for essential authentication or security processing.

8. Retention

We keep information only as long as reasonably necessary for its purpose, taking account of:

  • the active life of an account, product listing, capture, test, report, credit balance or support matter;
  • the 24-hour rolling lifetime of an anonymous swipe session;
  • the 180-day rolling lifetime of an anonymous voter identifier;
  • brief authentication-challenge, network-completion and keyed rate-limit windows used for security and abuse prevention;
  • the need to preserve anonymized response aggregates and ranking integrity; and
  • applicable limitation periods and accounting, tax, invoice, fraud-prevention or legal obligations.

Expired anonymous session and voter token hashes are anonymized, and their user links and coarse session metadata are removed, through audited privacy cleanup. Expired network-completion and rate-limit records are also removed. The current cleanup gives those security records expiries of no more than 48 hours, but actual deletion occurs when the cleanup process runs. Used or expired authentication challenges are removed after a separately configured short retention window.

Billing, tax, invoice and transaction records may remain with Stripe or be retained where applicable law requires it, including after an account-deletion request. Backups and security logs may persist until their normal protected rotation or deletion cycle completes.

9. Account deletion

An authenticated founder can request account deletion from account settings by confirming the account email. When deletion succeeds, current database rules remove the local account and founder-owned product and testing records. Links from anonymous voter/session or response records to the deleted user are removed. Provider records, invoices or information that must be retained for legal, payment, security or dispute purposes may remain for the applicable period.

10. International transfers

Some providers may process information outside Poland or the European Economic Area, including in the United States. Where required, we rely on lawful safeguards such as adequacy decisions, data-processing agreements, Standard Contractual Clauses or another permitted transfer mechanism.

11. Your privacy rights

Subject to applicable law, you may have the right to:

  • request access to and a copy of your personal data;
  • correct inaccurate or incomplete data;
  • request deletion of data;
  • restrict or object to certain processing;
  • receive portable data where the right applies;
  • withdraw consent without affecting earlier lawful processing; and
  • lodge a complaint with a competent supervisory authority.

In Poland, the supervisory authority is the President of the Personal Data Protection Office (UODO). You may also complain to the authority in the EU or EEA country where you live or work, or where an alleged infringement occurred.

To exercise a right, email support@saasorpass.now. We may need to verify your identity. Anonymous identifiers may not let us reliably identify a person without additional information from the relevant browser or session.

12. Security

We use reasonable technical and organizational measures designed to protect information, including access controls, hashed one-time codes and anonymous tokens, restricted secrets, input validation, public-network capture controls, rate limits, signed feed offers, Turnstile verification, Stripe webhook verification, private capture storage and bounded logging. No internet service can guarantee absolute security.

13. Children

SaaS or Pass is a product-discovery and founder-research service and is not directed to children under 16. We do not knowingly collect personal data from children under 16. Founder accounts and purchases require the legal capacity or authorization described in our Terms. If you believe a child has provided personal data, contact us so we can investigate.

14. Changes to this Policy

We may update this Privacy Policy as the Service or applicable requirements change. The date at the top shows when it was last updated. If a change is material, we may provide additional notice through the Service or by email where appropriate.

15. Contact

Questions, privacy requests and data-protection notices should be sent to support@saasorpass.now.