Privacy Policy
Last Updated: May 18th, 2026
1. Information We Collect
Account Information
Email address and authentication credentials for registered users. Authentication is handled through Supabase Auth, which we use to securely manage sign-in, account recovery, and access to paid features and subscriptions.
Device & Technical Information
We may collect limited device and network information such as IP address, browser type, and device characteristics. This information is used to maintain security, prevent spam, detect abuse, and ensure platform stability for both registered and guest users.
Usage & Analytics Data
We collect non-identifying usage data about how users interact with the Services, such as page views, post impressions, clicks, session duration, navigation paths, and engagement with content. This data may be associated with a session or device identifier and is used to improve platform performance, measure engagement, and understand how features are used.
User-Generated Content: We store posts, comments, and media you upload. Guest content is linked to a device-based identifier rather than an email account.
2. Tracking and Identification Technologies
We use cookies, local storage, and similar technologies to maintain authentication state, secure sessions, and enable core platform functionality such as login persistence and user preferences.
For anonymous users, we may generate a stable session identifier using browser and device-level signals. This is used strictly for security, anti-spam protection, abuse prevention, and maintaining session continuity.
Supabase (Authentication & Database Services)
We use Supabase to handle user authentication and backend data storage. Supabase may process authentication-related data such as email addresses, login sessions, IP addresses, and device metadata as part of providing secure authentication and database services. Their processing of data is governed by their own privacy and security policies.
Google AdSense (Advertising)
We use Google AdSense to display advertisements. Google and its partners may use cookies, advertising identifiers, and similar technologies to serve and measure personalized ads based on your activity on this and other websites. This may include tracking browsing behavior across sites for ad personalization and performance measurement.
These third-party services may independently collect and process data according to their own privacy policies. We do not control how these providers collect or use data beyond what is necessary to integrate their services into our platform.
3. Third-Party Services & Data Processors
Infrastructure
We use Vercel for hosting and Supabase for database services, which may process IP addresses and operational metadata.
Payments
Payments are processed via Stripe and Apple App Store. We do not store raw payment card details.
AI Services
We use the xAI API for platform features. Some user content may be processed to generate responses or moderation outputs.
Advertising
We use Google AdSense to display ads, which may use cookies or identifiers for personalization.
4. Your Rights & Data Control
Depending on your location, you may have rights regarding your personal data, including the right to access, correct, export, restrict, or request deletion of your information. You may request a copy of the personal data associated with your account or identifier, including account information, content you have created, and certain usage data where applicable. You may also request deletion of your account and associated personal data. In some cases, we may retain limited information where required for legal compliance, security purposes, fraud prevention, or legitimate business interests such as preventing abuse or enforcing bans. Requests for data access or deletion may require verification to ensure that the request is made by the legitimate account owner or the rightful controller of the associated identifier.
Guest Users
For guest sessions, data is associated with a device-based identifier rather than a registered account. As a result, we may require proof of continued access to the same device or browser environment in order to process certain requests, such as data deletion or retrieval.
Where applicable, you may also have the right to opt out of certain types of data processing, including non-essential analytics or personalized advertising, depending on your jurisdiction.
5. Children’s Privacy
The Services are not intended for users under the age of 13, and users under 13 are not permitted to create an account or otherwise use the Services. We do not knowingly collect, store, or solicit personal information from children under 13. If we become aware that we have collected personal data from a child under 13, we will take reasonable steps to delete such information as soon as possible. In some jurisdictions, additional age requirements may apply for access to certain features, content, or functionalities. Where applicable, users are responsible for complying with the laws of their country or region.
If you believe that a child under 13 may have provided personal information to the Services, please contact us at support@therigidproject.com so that we can investigate and take appropriate action.
6. Legal Disclosure & Security
We do not sell your personal data.
We may access, preserve, and disclose information if we believe it is reasonably necessary to comply with applicable laws, regulations, legal processes, or governmental requests, or to enforce our Terms, protect our users, investigate abuse, prevent fraud, or ensure the security and integrity of the Services.
The Services rely on a number of third-party infrastructure and service providers to operate, including but not limited to Supabase (authentication and database services), Stripe and Apple (payment processing), Vercel (hosting and deployment infrastructure), xAI (AI-related functionality), and Google AdSense (advertising delivery and measurement).
These providers may process, store, or transmit data on our behalf as part of delivering their services. Their handling of data is governed by their own privacy and security policies, and may include independent data collection, logging, or processing required for security, fraud prevention, analytics, or service reliability.
While we implement reasonable administrative, technical, and organizational safeguards to protect user data, no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee absolute security of your information.
You acknowledge that your use of the Services and any transmission of information is at your own risk.
Guest Session Notice
Guest sessions are tied to device-level identifiers. Changing hardware, browser configurations, or system resets may result in loss of access to guest data. Creating an account is recommended for persistent access.
Contact Us
If you have any questions, concerns, or feedback about these Terms or the Services, you can contact us at:
Email: support@therigidproject.com
We aim to respond to all inquiries in a reasonable timeframe, though response times may vary depending on volume and request type.
