Privacy Policy
Effective Date: March 29, 2026 — What It's Worth
1. Overview
What It's Worth ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our Service. By using the Service, you agree to the practices described here.
2. Information We Collect
We collect the following categories of information:
- Account Information: Email address and authentication credentials when you register.
- Usage Data: Pages visited, features used, valuation runs executed, and session timestamps.
- Company Data: Financial figures, industry details, and other company information you enter to generate valuations. This data is associated with your account.
- Payment Information: Billing details are processed by Stripe and are not stored on our servers. We receive only a payment confirmation token.
- Technical Data: IP address, browser type, and device information collected automatically during use.
- Watchlist & Journal Data: Companies you monitor and notes you create in the investment journal.
- Audit Log Data: For Enterprise users, detailed activity logs including actions taken, timestamps, and IP addresses.
- Referral Data: Referral codes, referred user relationships, and reward tracking when you participate in the referral program.
3. Authentication
Authentication is handled through Supabase, a third-party infrastructure provider. Supabase stores your authentication credentials securely and issues JWT tokens used to verify your identity when accessing the Service. We do not store your password in plain text at any point.
4. Payments
Subscription billing is processed by Stripe, Inc. When you subscribe, you are redirected to Stripe's secure checkout or payment interface. We do not receive or store your full credit card number, CVV, or bank account details. Stripe's privacy practices are governed by the Stripe Privacy Policy.
4A. AI and Machine Learning
Certain features of the Service — including company research, assumption validation, and executive summary generation — use third-party AI providers (currently Anthropic) to process your data. When you invoke these features, company information and financial data you have entered may be transmitted to the AI provider for processing.
AI providers process data according to their own privacy and data retention policies. We select providers with strong data handling practices and do not permit them to use your data to train their models. AI-generated outputs are returned to the Service and associated with your account.
4B. CRM Integrations
When you connect a CRM platform (HubSpot or Salesforce), you authorize the Service to share specific data with that platform, including company names, valuation summaries, and deal metadata. This data sharing occurs only at your direction (e.g., when you click "Sync to CRM"). Data transmitted to CRM platforms is governed by their respective privacy policies. You may disconnect CRM integrations at any time through your account settings.
5. How We Use Your Information
- To provide, maintain, and improve the Service
- To process your subscription and send billing-related communications
- To save and retrieve your valuation history
- To power AI features such as company research, assumption validation, and executive summaries
- To sync data with connected CRM platforms at your request
- To facilitate the referral program and track rewards
- To diagnose technical issues and improve Service reliability
- To communicate important updates about the Service
6. Cookies
We use session cookies and local storage to maintain your authenticated session. These are strictly necessary for the Service to function. We do not use advertising or tracking cookies. Third-party services (Supabase, Stripe) may set their own cookies in accordance with their respective policies.
7. Data Retention
We retain your account data and saved valuations for as long as your account is active. If you delete your account, we will remove your personal information and saved valuations within 30 days, except where retention is required by law or for legitimate business purposes such as resolving disputes.
8. Your Rights
You have the following rights regarding your data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your account and associated data.
- Portability: Request your saved valuation data in a portable format.
To exercise any of these rights, contact us through your account dashboard or the Service website.
9. Third-Party Data Sharing
We share data with the following categories of third-party service providers, solely to operate the Service:
- Supabase: Authentication and database infrastructure.
- Stripe: Payment processing for subscriptions.
- Anthropic: AI processing for research, validation, and summary features.
- HubSpot / Salesforce: CRM data sync, only when you explicitly connect and initiate a sync.
We do not sell, rent, or trade your personal information or company valuation data to any third party. We do not use your data for advertising purposes and do not share it with data brokers.
10. Security
We implement industry-standard security measures including encrypted connections (HTTPS), row-level security on our database, and secure credential handling. No system is completely secure, and we cannot guarantee absolute security, but we take reasonable precautions to protect your data.
11. Contact
For privacy-related questions or to exercise your data rights, contact us through what-its-worth.com or your account dashboard.