Privacy Policy
Last updated: October 3, 2026
1. Who controls your data
Startups Compass is the data controller for the information described in this policy. Startups Compass is operated by QUANOMALY LTD (קואנומלי בע"מ), a limited liability company incorporated in Israel, company number 517297453, registered at HaAtzma'ut Road 45, Haifa 3303323, Israel. Contact: [email protected].
2. What we collect, and why
| Where | What we collect | Why |
|---|---|---|
| Creating an account (app.startupscompass.com) | Work email address and password (handled directly by our authentication provider, Supabase — we never see your password), plus company name and phone number | To create and secure your account, verify you're using a real work email, and let you sign back in on future visits |
| Your access code (if you registered with one) | The access code your account was created with, the date it was redeemed, and the date your free year ends — stored against your email address. No payment details are collected at registration or at any point during your free year: no card number, no billing address, nothing. There is no payment method on file for your account. | To enforce how many accounts a code can create, to make sure a code is only used once per account, and to know when your free year ends so we can tell you in advance |
| Historical: waitlist signup form | Email address, name (optional), browser language, the page you signed up from, and your IP address at the moment of signup | Kept from an earlier stage of the product, before direct registration existed. Kept as a record of consent (timestamp and IP address) |
| Sign-up and login forms | A verification token from Cloudflare Turnstile, our bot-protection provider, based on technical signals about your browser/device — we don't receive or read the underlying signals ourselves, only a pass/fail result | To block automated/bot sign-ups and protect the Service from abuse |
| This website generally | Nothing. No cookies, no analytics, no tracking pixels. | — |
| The Startups Compass application — Local mode (the default) | Nothing you enter is sent to us. Your investor pipeline, cap table, and all other app data stay in your browser's local storage on your own device. (The one request the application makes to our servers in this mode is the public exchange-rate lookup described further down, which carries no app data.) | — |
| The Startups Compass application — Cloud backup (Cloud plan; on by default there, and can be turned off) | A copy of that same app data — investors, contacts, notes, cap table — is stored on our servers in the European Union, together with dated restore points (the current copy is refreshed within seconds of a change; a restore point is kept at most once a day, and the most recent 10 are retained). It is encrypted in transit and at rest, but it is not end-to-end encrypted: we are technically able to read it. We do not read it except as needed to provide, secure, restore or support the service, or where legally required. We never combine it with other customers' data, and we never build any product or dataset out of it. You can erase the cloud copy and every restore point yourself, from inside the app, at any time — immediately and permanently. | So that your data can be restored if this browser is lost or cleared, or an edit goes wrong. That is the whole reason the mode exists, and it is why we keep the ability to read the copy: end-to-end encryption would mean we could not restore anything for you. If that trade is not one you want, stay in Local mode — it remains the default and is not going away. |
| The Startups Compass application — Files you attach (Cloud plan) | Files you attach to your records — for example contracts, NDAs, term sheets, financial models and presentations — which may contain personal data of other people, such as investors' names, contact details or signatures. They are stored with Cloudflare R2 in the European Union, encrypted in transit and at rest, and are not end-to-end encrypted: we are technically able to read them. We do not read them except as needed to provide, secure or support the service, or where legally required, and never use them for any other purpose. We do not send, share or publish them. On the Local plan only a link you enter is kept, in your own browser. | To store them for you and let you find, download, replace, move and delete them. |
| The "Find Investors" feature | Nothing is sent to us, but your browser sends search terms directly to a third-party search service — Wikipedia, and Google Programmable Search only if you supply your own API key. Those search terms are built from your startup profile's sectors, funding stages, and niche description. Your investor records, contacts, notes, and cap table are never included. | To find investors matching your profile. This runs automatically in the background when the app loads (so the "Find Investors" tab can show how many new matches exist) — not only when you open that tab. It does not run at all if you haven't set any sectors on your startup profile. |
| Exchange rates in the Costs tab | When a cost or the display currency is not US dollars, the app asks our own server (api.startupscompass.com/fx) for the current exchange rates, at most once a day. The request carries no app data — only the ordinary information any web request carries, such as your IP address and browser type, which our hosting provider processes to answer it. The server in turn fetches the European Central Bank's public daily reference rates, republished by frankfurter.dev; that request comes from our server, so those services never see you. The rates are stored in your browser and, if you use Cloud backup, in your backup copy, together with the date they were published. |
So that costs in different currencies can be added into one total with a real rate rather than one you type in. It does not run at all if every cost and your display currency are in US dollars. |
| Investor and company logos | Nothing is sent to us. When an investor record (or your own startup profile) has a website saved, the app displays that company's logo by loading its website icon from Google's favicon service at www.google.com/s2/favicons. The website's domain name is therefore visible to that service, along with your IP address, as part of a normal image request — so over time it can see the domains of the investors you have saved. Nothing else is included: never the investor's name, your contacts, notes, amounts, pipeline status, or any other field. This happens wherever a logo is shown, including the investor list, so it is not limited to records you open. |
To show a recognizable logo instead of a blank placeholder. Two things switch it off: an investor record with no website saved never triggers a request, and setting your own logo image URL on a record (Investor details — "Set logo") always takes precedence, so that record's logo is loaded from wherever you chose instead. |
| The Gmail integration (restricted — not part of the product offered to customers) | This is not a feature of the service you sign up for. It is an internal capability limited to a small number of specific accounts operated by us, and it cannot be enabled on a customer account — the control is not shown, and the server refuses to complete the connection, for any account outside that list. It is described here for completeness because the application does hold Google API credentials, not because it is something you can turn on. Where it is enabled, and only if that account explicitly connects it: read-only, metadata-only access to that Gmail account (Google API scopes gmail.metadata and openid email) to check, on each app load, whether a new message has arrived from an email address already saved on one of that account's investor records. This scope only exposes message metadata (sender address, subject line, date) — Google does not grant this scope access to message body content at all, so we couldn't read it even if we wanted to. We do not store or display any of that metadata beyond the sender-address match itself, and we never send, delete, or modify anything in that mailbox. Nothing from that inbox is ever sent to or stored on a Startups Compass server: the Google access token and everything derived from a scan stay in that browser's local storage, the same as all other business data in this app. The one exception is the moment of first connection (or reconnection) — the authorization code Google issues is relayed, once, through a small server-side function whose only job is exchanging it for that access token using our app's Google API credentials, exactly as Google's own sign-in flow for websites requires; that function does not read, log, or retain any Gmail data itself. As a customer, none of this applies to your account: no Gmail access is ever requested from you, and nothing in your mailbox is touched, because the integration cannot be enabled for you at all. |
An internal convenience on our own accounts — surfacing that a tracked investor has sent a new email without checking the inbox by hand. It is not offered to, and cannot be used by, customer accounts. |
On Cloud backup and files: for the personal data of other people inside your app data or your files — an investor's name, email or phone — you remain the data controller and we act as a processor on your instructions. Turning the mode on does not move that responsibility to us, and it does not change those people's rights. In Local mode we are neither, because we never receive the data at all.
On the "Find Investors" and logo rows above: those requests go from your browser straight to those third parties, so they see your IP address and the search terms or domain requested, and their own privacy policies apply to what they do with them — we are not an intermediary and never receive the query, the result, or the image. Apart from those two, and the exchange-rate lookup above (which goes to our own server and carries no app data), the rest of the application works without sending anything anywhere. The Gmail integration described above is not among them for you: it cannot be enabled on a customer account at all.
Startups Compass's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We process this account and waitlist data based on your consent and our legitimate interest in developing our service. Providing this information is not legally required and is done at your own free will. The only exception to "nothing is sent to us" from the application is if you voluntarily contact us for support or to report a bug — in that case, we only receive what you choose to share with us in that message (such as your email and a description of the issue), never your App Data itself.
3. Where account and waitlist data are stored
Account data (your login credentials, company name, email, and phone number) is stored using Supabase, a cloud database and authentication provider that hosts this data in Frankfurt, Germany (EU), and acts as our data processor. Files you attach on the Cloud plan are stored using Cloudflare R2 in its European Union jurisdiction, with Cloudflare, Inc. acting as our data processor. So that a refund ends your access at the end of your own day, the app also stores your browser's time zone setting (for example "Asia/Jerusalem") with your account. When you create an account we also record how you reached us: the campaign tags in the link you followed (utm_source, utm_medium, utm_campaign), if there were any, and the domain of the website that sent you — never the full address of that page. Your browser keeps them only for the length of that visit (in session storage, not a cookie), and we use them only to learn which channels bring founders to the service. Historical waitlist signups are stored using Cloudflare Workers KV, a cloud data store operated by Cloudflare, Inc., also acting as our data processor. Cloudflare Turnstile (part of Cloudflare, already named above) processes the technical signals described in Section 2 to verify you're not a bot; see Cloudflare's privacy policy for details. We don't sell this data or share it with advertisers. We may share it with service providers who help us operate the service — for example, Resend, our email delivery provider, which sends account-verification and related emails on our behalf — only as needed to provide the service to you.
We never see or store your payment details. Accounts created with an access code collect no payment details at all. For paid subscriptions, payment is collected by Paddle.com Market Limited ("Paddle"), our authorised reseller and merchant of record: card details are entered on Paddle's own checkout, processed by Paddle as an independent data controller under its own privacy policy, and never reach us. We receive back only what is needed to run the subscription — its status, the plan, and the renewal date — never a card number. Paid subscriptions are being rolled out; until they are active on your account, no payment data exists for you anywhere.
4. How long we keep it
We keep your account data for as long as your account is active, or until you ask us to delete it — whichever comes first. Inactive accounts are deleted automatically: an account whose email address was never confirmed is deleted 30 days after it was created; an account that has not been signed in to for 24 months receives a warning email, and is deleted 30 days after that warning unless it is signed in to in the meantime — a single sign-in resets the clock. An account with an active subscription, a paid period still running, or a free access period still in force is never deleted for inactivity. Deleting an account deletes the account itself, its registration details, its subscription and access-code records held by us, and its cloud copy with every restore point. Data stored in your own browser is not affected — we have no access to it. Payment records are kept by Paddle, our merchant of record, under its own retention obligations. We keep historical waitlist entries until you ask us to delete your entry, or until they're no longer needed for the purpose described above. If you turn on Cloud backup, your data's current copy is kept for as long as Cloud backup stays on, with restore points kept for at most 10 days each before being deleted automatically; deleting your account deletes the cloud copy and every restore point immediately, and you can also erase them yourself at any time from inside the app. If paid plans are ever introduced, any change to these retention rules will be described in an updated version of this policy first.
When a subscription ends, or Cloud is removed from it: your cloud copy, its restore points and the files you stored are kept for 60 days so you can download them, then permanently deleted. We email you when it happens and 30 and 7 days before the deletion. Data in your own browser is never touched by us. Deleting your account deletes them immediately.
5. Your rights
You can ask us at any time to:
- Tell you what data we hold about you
- Correct inaccurate data
- Delete your data (for example, delete your account, or remove you from the historical waitlist). Your business data is deleted differently depending on where it lives: in Local mode, clear your own browser's local storage — we never had a copy to delete. In Cloud backup mode, use the Erase cloud copy control inside the app (immediate and permanent), or ask us to delete your account, which deletes the cloud copy and every restore point along with it automatically. Files you stored on the Cloud plan can be deleted one by one in the app, and all of them are deleted with your account.
- Object to our processing your data based on legitimate interest
- Request restriction of processing, or a portable copy of your data, where applicable
To do any of this, email [email protected]. We may ask for reasonable proof of identity before acting on a request, to make sure we only disclose or delete data for its rightful owner. We'll respond within 30 days. If you're in the EU/EEA or UK, you also have rights under GDPR, including the right to lodge a complaint with your local data protection authority.
6. International transfers
Your account data is hosted by Supabase in Frankfurt, Germany (EU). Files you store on the Cloud plan are kept in Cloudflare R2's European Union jurisdiction. Cloudflare operates a global network, so your historical waitlist data, and files as they are delivered to you, may be processed in countries other than your own. Both providers maintain their own safeguards for cross-border data transfers; see their respective privacy policies for details. Where required, such transfers rely on Standard Contractual Clauses or another legally recognized transfer mechanism.
7. Business transfers
If Startups Compass is involved in a merger, acquisition, or sale of all or substantially all of its assets, your account and waitlist data may be transferred to the acquiring party as part of that transaction. Where required by law, we'll notify affected users by email before their data is transferred and becomes subject to a different privacy policy.
8. Children's privacy
Startups Compass is a business tool intended for founders and professionals. It is not directed at children, and we don't knowingly collect data from anyone under 16.
9. Changes to this policy
We may update this policy as the product evolves — for example, if we introduce paid plans, in which case we'll add a section covering payment data before any is collected. We'll update the "Last updated" date above whenever we do. We retain prior versions of this Policy and will provide a copy on request.
10. Contact
Questions about this policy or your data: [email protected]