Privacy Policy
Last updated: January 15, 2026
Overview
SubSonar ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Reddit lead discovery service at subsonar.ai (the "Service").
By using SubSonar, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies, please do not use our Service.
Information We Collect
Account Information
When you create an account, we collect:
- Email address (required for account creation and authentication)
- Password (stored securely using industry-standard hashing)
- Account creation date and last login timestamp
Search & Usage Data
When you use our Service, we collect:
- Website URLs you submit for lead discovery
- Target audience descriptions you provide
- Search parameters (age range, location, pain points, etc.)
- Generated leads and AI-crafted messages
- Your interactions with leads (contacted, replied, converted status)
- Notes you add to leads
- Favorite and saved searches
Automatically Collected Information
We automatically collect certain information when you visit our Service:
- IP address (for security and rate limiting)
- Browser type and version
- Device information
- Pages visited and time spent
- Referring website
Analytics Data
We use Google Analytics to understand how users interact with our Service. Google Analytics collects information such as how often users visit the site, what pages they visit, and what other sites they used prior to coming to our site. We use this information to improve our Service. Google Analytics collects the IP address assigned to you on the date you visit the site, but not your name or other identifying information. You can opt-out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.
How We Use Your Information
We use the information we collect to:
- Provide and maintain our Service
- Process your searches and generate leads
- Create AI-personalized outreach messages
- Save your search history and lead data
- Send you important account notifications
- Respond to your inquiries and support requests
- Monitor usage to enforce rate limits and prevent abuse
- Improve and optimize our Service
- Detect and prevent fraud or security issues
- Comply with legal obligations
Payment Processing
We use Stripe for payment processing. When you make a purchase, your payment information is collected and processed directly by Stripe. We do not store your full credit card number, CVV, or other sensitive payment details on our servers.
We receive from Stripe:
- Last four digits of your card (for your reference)
- Card brand (Visa, Mastercard, etc.)
- Billing address
- Transaction history and subscription status
Stripe's privacy policy can be found at stripe.com/privacy.
Data Sharing & Third Parties
We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:
Service Providers
We use trusted third-party services to operate our business:
- Supabase — Database hosting and authentication
- Vercel — Website hosting and deployment
- OpenAI — AI-powered lead analysis and message generation
- Scraper API — Reddit data collection
- Google Analytics — Website analytics
- Stripe — Payment processing
- Resend — Transactional emails
Legal Requirements
We may disclose your information if required by law, such as to comply with a subpoena or similar legal process, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
Reddit Data
SubSonar accesses publicly available Reddit data to identify potential leads. We collect:
- Public Reddit usernames
- Public post titles and content
- Subreddit names
- Post timestamps and engagement metrics
We do not access private Reddit messages, private subreddits, or any information that requires Reddit authentication. All data we collect is publicly visible on Reddit.
Data Retention
We retain your information for as long as your account is active or as needed to provide our Service. Specifically:
- Account data — Retained until you delete your account
- Search history — Retained indefinitely (you can delete individual searches)
- Lead data — Retained until you delete leads or your account
- Reddit cache — Automatically expires after 30 minutes
- Log data — Retained for 90 days for security purposes
You can request deletion of your account and all associated data by contacting us.
Data Security
We implement appropriate technical and organizational measures to protect your personal information:
- All data transmitted via HTTPS/TLS encryption
- Passwords hashed using industry-standard algorithms
- Database access restricted and monitored
- Regular security audits and updates
- Row-level security policies on all user data
Your Rights
Depending on your location, you may have the following rights:
- Access — Request a copy of your personal data
- Correction — Request correction of inaccurate data
- Deletion — Request deletion of your data
- Portability — Request your data in a portable format
- Objection — Object to certain processing of your data
- Withdrawal — Withdraw consent where processing is based on consent
To exercise these rights, contact us.
Cookies
We use essential cookies to:
- Keep you signed in to your account
- Remember your preferences
- Ensure security of your session
We also use Google Analytics cookies for website analytics. You can control cookies through your browser settings.
Children's Privacy
SubSonar is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date. For significant changes, we will send an email notification.
Contact Us
If you have questions about this Privacy Policy or our data practices, contact us here.