Privacy Policy
Last updated: September 2026
GoMimic is operated by Akhil Gautam. We take privacy seriously. This policy explains what data we collect, why we collect it, how long we keep it, and how we use it.
1. What we collect
- Account information includes your email address and a password hash, managed by Supabase Auth.
- Client data you add includes client names, website URLs, and the voice profiles GoMimic builds from them.
- Content you paste includes the blog post text or URLs you submit for distribution.
- Generated outputs are the assets GoMimic produces, stored per client as your content history.
- Usage data includes basic activity within the app, captured via Supabase. We don't run any third-party analytics.
- IP address at signup, stored alongside your signup record for abuse prevention.
- Payment information is processed directly by PayPal or Razorpay. We never see or store your full card or bank details.
2. Why we collect it
- To provide the GoMimic service, turning a published blog post into distribution assets.
- To maintain each client's voice profile, so output stays consistent over time.
- To save your content history, so you and your clients have a record of what went out.
- To process payments and manage your subscription.
- To prevent abuse and protect the platform.
3. What we don't do
- We do not sell your data, to anyone, ever.
- We do not share client data with third parties, beyond the infrastructure providers that run the service: Supabase, Anthropic, Resend, PayPal, Razorpay, and Sentry.
- We do not use your content, or your clients' content, to train AI models.
- We do not run advertising, and we do not sell access to your data for advertising purposes.
4. Data retention and deletion
Trial accounts: If your trial expires and you do not upgrade, your account data — including all clients, voice profiles, content history, and generated assets — is retained for 60 days, then permanently and automatically deleted. Nothing is deleted while you still have access: if you have ever paid us, or your subscription is still within a period you paid for, this automatic deletion never applies to you.
Paid accounts: Your data is retained for as long as your account is active. If you cancel and want your data permanently deleted, you can do so at any time from Settings inside GoMimic.
Account deletion: You can delete your account at any time from your account settings. This removes your account and its content, except the records listed below.
What survives deletion: To protect the platform against abuse, your email address and signup IP address are retained in a separate abuse-prevention log even after your account is deleted. This record is not linked to your content or client data, and is never used for marketing.
Coming back later: That record is also what tells us you have been here before. You are welcome to open a new account with the same email address at any time, but the free trial is once per person: a returning account starts on a paid plan rather than a second trial.
Payment records: A record of each payment we received (the amount, currency, date, plan, and the PayPal or Razorpay payment reference) is kept after your account is deleted, because we are legally required to keep financial records. We remove the link to your GoMimic account, though the payment reference still identifies the transaction with PayPal or Razorpay.
Support tickets: If you contacted our support team, the content of those messages is scrubbed on account deletion. A record that a ticket existed is retained for internal audit purposes, with all identifying information removed.
5. Data storage and security
- Your data is stored in Supabase (PostgreSQL), hosted on AWS infrastructure.
- Row-level security is enforced on every table that holds client or content data. Each user's data is fully isolated from every other user's.
- Passwords are hashed by Supabase Auth. We never see or store them in plain text.
- API keys and other secrets are stored as environment variables and never committed to the codebase.
- Errors and performance issues are monitored via Sentry. Stack traces may include request metadata but never your content or client data.
6. Third-party services
- Supabase (database and authentication) at supabase.com/privacy
- Anthropic (powers the generation step) at anthropic.com/privacy
- Resend (transactional email delivery) at resend.com/privacy
- PayPal (payments) at paypal.com/privacy
- Razorpay (payments, India) at razorpay.com/privacy
- Sentry (error monitoring) at sentry.io/privacy
7. Your rights
- Delete your account and all associated data: go to Settings inside GoMimic and use the Delete Account option. Deletion is immediate and permanent.
- Export your data: contact hello@gomimic.ai.
- If you're based in the EU, you have GDPR rights to access, rectify, erase, and port your data. Reach out and we'll handle the request directly.
8. Contact
For any privacy questions or data requests: support@gomimic.ai