PowerFunnels
Privacy Policy
Effective August 30, 2026
This policy explains how PowerFunnels handles personal information through Changelog Creator, including its website, application, public portals, widgets, APIs, and Chrome extension (the “Service”).
1. Our role
PowerFunnels is the controller of information used to create and secure accounts, administer billing, provide support, communicate about the Service, and understand operation of the Service.
Organizations using Changelog Creator control the content and personal information placed in their workspaces. For that customer-controlled workspace data, PowerFunnels acts as a processor or service provider on the organization’s instructions. The organization remains responsible for its notices, permissions, and responses to requests concerning that data.
2. Information we collect
- Account and sign-in data: name, email address, account identifier, profile image, team membership, authentication records, and session data.
- Workspace content: feedback, ideas, comments, votes, follows, survey definitions and responses, attachments, announcements, roadmap entries, account and contact records, moderation decisions, imports, integration metadata, and audit history.
- Support and communications: messages, requests, troubleshooting information, notification preferences, and other information sent to us.
- Billing data: subscription, plan, seat, invoice, payment-status, and transaction metadata. Payment-card details are handled by Stripe when billing is enabled.
- Security and technical data: IP-derived security signals, browser and device type, timestamps, request and delivery identifiers, authentication failures, webhook results, and bounded operational logs.
- Usage analytics: limited first-party events such as impressions, opens, submissions, publication activity, and feature use. We use these events to operate and improve the Service, not to track people across unrelated services.
- Integrations and imports: data selected by a workspace administrator from GitHub, GoHighLevel, CSV files, Productboard, Canny, or another configured source.
3. Google sign-in data
When you choose Google sign-in, Google provides your Google account identifier, email address, display name, and profile image solely so Supabase can authenticate your account and maintain your Changelog Creator session. PowerFunnels does not sell this data, use it for advertising, or send it to AI providers.
You may revoke Changelog Creator’s Google access through your Google Account connections. You may also request deletion by emailing [email protected]. Revoking access stops future Google sign-in but does not itself delete information already required to maintain your Changelog Creator account; contact us for deletion.
4. Chrome extension capture
The Chrome extension captures only information you explicitly choose to send: selected text, the page title, and the page URL after query parameters and fragments have been removed. It may also include the account, source, or sentiment you select. It never scrapes or captures the full page.
5. AI-assisted drafting
AI features are optional and workspace-configured. When enabled, only selected, sanitized metadata is sent to the configured AI provider. Changelog Creator never sends repository source code or raw diffs to an AI provider. AI output remains a draft or proposal that requires human approval before publication or application.
PowerFunnels never uses customer content to train Changelog Creator’s own models. Google sign-in data is not included in AI requests.
6. How and why we use information
- Provide, authenticate, personalize, maintain, and support the Service.
- Process workspace instructions, imports, integrations, publications, surveys, notifications, and privacy requests.
- Secure accounts, prevent abuse and fraud, investigate failures, enforce permissions, and preserve service integrity.
- Administer subscriptions and billing, communicate service information, and answer support requests.
- Measure bounded product and operational performance and improve reliability and usability.
- Comply with law, resolve disputes, and establish, exercise, or defend legal claims.
Depending on the context and applicable law, our legal bases are performance of a contract or steps requested before a contract, our legitimate interests in providing and securing the Service, consent where requested, and compliance with legal obligations. You may withdraw consent at any time without affecting earlier lawful processing.
7. Cookies and local storage
Changelog Creator uses only essential cookies and browser or extension storage needed for authentication, session continuity, preferences, and security. The Service currently uses no advertising cookies and does not perform cross-context behavioral tracking or advertising, so it does not display an advertising-cookie banner. Blocking essential storage may prevent sign-in or other Service features from working.
8. Service providers and disclosures
We disclose only information reasonably needed for providers to perform services for us or for a customer-configured feature:
- Supabase for database, authentication, sessions, and file storage.
- Railway for application hosting and processing, and Cloudflare for network, DNS, and security services.
- Google when you use Google authentication.
- Stripe for billing and Resend for email, when those features are enabled.
- GitHub, GoHighLevel, import sources, and configured AI providers when a workspace connects or enables those features.
We may also disclose information to professional advisers, authorities, or other parties when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or establish or defend legal claims.
9. No sale or behavioral advertising
PowerFunnels does not sell personal information. We do not share personal information for cross-context behavioral advertising and do not use personal information for targeted advertising across unrelated services.
10. Retention
We keep information only as long as needed for the purposes described here. Workspace administrators may configure extension-clip and audit retention from 30 to 365 days; the default is 90 days. Analytics events are retained for up to 180 days. Import rollback artifacts are retained for 24 hours. Account and workspace content generally remains while the account or workspace is active or as directed by the controlling customer.
Some records may be kept longer when needed for security, fraud prevention, legal obligations, disputes, billing, or deletion-suppression. Retention may also be affected by backup cycles and a customer’s lawful instructions.
11. Deletion and anonymization
A verified deletion removes or de-identifies eligible identity data and deletes personal records that need not be retained. Feedback, votes, reactions, views, or similar contributions may remain in anonymized form when needed to preserve the integrity of workspace discussions, history, and aggregate counts.
We create keyed, one-way suppression hashes from deleted identity values so an import or integration cannot silently recreate the deleted identity. These hashes are not used to identify or contact you. Security, legal, billing, backup, and suppression records may remain for their applicable retention periods.
12. Your privacy rights
Depending on where you live and the role in which we process information, you may request access, correction, deletion, export, restriction, objection, or portability. You may withdraw consent and may opt out of the sale or sharing of personal information, although PowerFunnels does not sell personal information or share it for cross-context behavioral advertising.
For customer-controlled workspace data, contact the organization operating that workspace first; we assist that organization with verified requests. For PowerFunnels-controlled data, email [email protected] with “Privacy request” in the subject. We may verify your identity and authority before acting. We will not discriminate against you for exercising applicable privacy rights, and you may complain to your local data protection authority.
13. International processing
PowerFunnels is based in the United States, and we and our providers may process information in the United States and other countries. Where required, we use contractual or other lawful safeguards for international transfers. Privacy protections and government-access rules may differ by country.
14. Security
We use safeguards designed to protect information, including encrypted transport, access controls, tenant isolation, hashed or encrypted credentials, audit records, signature verification, bounded logs, and human approval for publication. No transmission or storage system can be guaranteed completely secure. Please report suspected security issues to [email protected].
15. Children
The Service is intended for businesses and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child supplied personal information, contact us so we can investigate and delete it where required.
16. Legal events, transfers, and external links
We may preserve or disclose information when required by law or reasonably necessary to protect people, rights, and the Service. If PowerFunnels is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may transfer as part of that transaction subject to this policy and applicable law.
The Service may link to sites or services we do not operate. Their privacy practices are governed by their own policies.
17. Changes to this policy
We may update this policy to reflect changes to the Service, providers, or law. We will post the revised policy here, update its effective date, and provide additional notice when required.
18. Contact PowerFunnels
PowerFunnelsAtlanta, Georgia, United States
[email protected]