Last updated 2026-08-30
Privacy
Short, because there is little to tell: no advertising, no tracking cookies, no data sold. We do measure aggregate site visits — see below.
Who is responsible
The data controller is 15953456 Canada Inc., 40 Ed Clark Gardens, Th09, Toronto, Ontario M6N 0B5, Canada. Privacy contact: privacy@demandlens.app — the privacy officer answers there.
Representative in the European Union
We have not designated a representative in the Union, and we rely on the exemption in Article 27(2)(a) GDPR: our processing is occasional, does not involve special categories of data on a large scale or data relating to criminal convictions, and is unlikely to result in a risk to the rights and freedoms of individuals.
This is a position, not a permanent state. We re-examine it as volume grows, and the day the exemption no longer holds we designate a representative and name them here. Saying nothing at all would leave you unable to tell an exemption from an oversight.
What we collect
- The idea text you submit — needed to run the scan. Treat it as you would any text sent to an online service; see the sub-processor list below.
- Your email address — collected at checkout, used to deliver the report and to let you retrieve it later.
- Payment data — handled by Stripe. We receive confirmation of payment and never see your card number.
- Scans and reports — the artefacts produced, so you can retrieve them.
- Connection metadata — IP address and user agent, in server logs and for rate limiting.
- Your email address, if you join a waitlist or ask for the newsletter — kept for that purpose alone, never merged with the reports you bought, and unsubscribing removes it. We send one message to confirm the address is yours: without that confirmation it is never added to the list, and nothing else is sent.
Aggregate benchmarks
If we ever publish figures about the ideas we have measured — for example, where a score sits among software ideas — those figures are computed on de-identified aggregates above a disclosed threshold: a cell too small to hide an individual is not published at all.
Your idea text never feeds any of it. An idea text cannot be anonymised, so it is excluded by rule rather than by care.
What we do not collect
No advertising pixels, no third-party trackers that follow you across other sites, no behavioural profiling, no cookie or device fingerprint used to identify you individually. Fonts are self-hosted, so your browser makes no request to a font provider when you visit.
Audience measurement
We use Cloudflare Web Analytics to count aggregate visits and measure page performance. It sets no cookie and stores no persistent identifier on your device — Cloudflare’s own description is that it counts page views, not people, and treats browser fingerprinting as more intrusive than cookies rather than using it as a substitute. No individually identifiable data about you is collected through this measurement.
Cookies and local storage
We use one strictly necessary cookie: a session cookie set after you verify a one-time retrieval code, so your recovered reports stay accessible. It is required for that feature to function and carries no tracking.
Your browser also keeps one access key per report in local storage, so a report you paid for stays readable when you come back. It never travels in a URL. Nothing else is written to your device.
Because we set no advertising cookies and our audience-measurement tool sets none either, no consent banner is required.
Who else processes your data
We use the following sub-processors, each for a stated purpose. The rule we apply: a party is listed when it receives data derived from your idea text, even if it never sees the text itself.
The public sources we query — Hacker News, Stack Exchange, GitHub, eBay — receive only a search term, never your idea text, your email, or any identifier. They are not sub-processors of your personal data, and we name them here so the distinction is yours to check rather than ours to assert.
- Stripe — payment processing: email, payment details (we never see or store card data).
- Anthropic — language model — structuring your brief, and standing in as backup on classification, query expansion, name proposal and the pre-mortem when the primary model is unavailable: the idea text you submit for scanning and, when Anthropic takes over, the same data as the corresponding DeepSeek entry.
- DeepSeek — classification of the submitted idea text: the idea text you submit for scanning. DeepSeek processes this in China; training on submitted data is on by default (opt out by emailing us)..
- DeepSeek — expansion of your search queries from the submitted idea: the idea text, your existing keywords and any known competitors you submit for scanning. DeepSeek processes this in China; training on submitted data is on by default (opt out by emailing us)..
- DeepSeek — proposal of brand names for the submitted idea: the idea text you submit for scanning. DeepSeek processes this in China; training on submitted data is on by default (opt out by emailing us)..
- DeepSeek — pre-mortem — the reasons your idea could fail: the idea text, its vertical, and snippets of the public evidence gathered during your scan. DeepSeek processes this in China; training on submitted data is on by default (opt out by emailing us)..
- Supabase — database — entitlements and orders: email, order and entitlement records.
- Railway — API hosting: all data in transit and the scan/report file store.
- Vercel — front-end hosting: connection metadata (IP, user agent).
- Resend — email delivery — your report, and the codes that restore access to it: email, the report link and its order reference, and the single-use recovery code.
- DataForSEO — search-volume measurement: a keyword derived from the idea text you submit.
- Porkbun — domain availability and pricing: candidate domain names derived from the idea text.
Why we are allowed to process it
Performing our contract with you (delivering and retrieving the report), complying with legal obligations (tax and accounting records), and our legitimate interest in keeping the service available and unabused (rate limiting, logs).
How long we keep it
Orders and entitlements are kept as long as needed to let you retrieve your reports and to meet accounting obligations. Server logs are short-lived. You may ask us to delete your data at any time, subject to records we are legally required to keep.
International transfers
We are established in Canada. For transfers from the EU/EEA, Canada benefits from a European Commission adequacy decision covering commercial organisations subject to PIPEDA, which is the basis on which your data reaches us. Sub-processors located elsewhere are engaged under their own transfer safeguards.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or port your data, to object to or restrict processing, and to withdraw consent.
Write to privacy@demandlens.app and we will answer within the time limit that applies to you.
Complaints
If you are in the EU/EEA you may complain to your national supervisory authority. In Canada you may complain to the Office of the Privacy Commissioner of Canada, and residents of Québec to the Commission d’accès à l’information.