Privacy.

Updated October 10, 2026

Your Stripe key

You give us a read-only restricted key. It is sealed with AES-256-GCM before it is stored, and never shown again, only its last 4 characters.

We use it to read your subscriptions and coupons, and nothing else.

What we store

Your MRR, subscription count and goals, day by day. No customer data: no names, emails or cards.

Your account: email, password hash, and your X handle if you add one.

What is public

Your startup's name, X handle, MRR, goal and charts. Your email never is.

Switch off Public page in the dashboard to hide a startup. It disappears within minutes; card images already shared on X may stay cached for up to a day.

Visitors

Cheers, profile views and clicks to a site are counted once per visitor per day. So is the "here today" counter on the landing page.

A visitor is a keyed hash of IP and browser that changes every day. We never store the raw IP.

View, click and visit rows are deleted after 31 days.

To limit abuse, a keyed hash of your IP (or email, for a password reset) is also kept for a few minutes with each attempt to log in, sign up, reset a password, view a page or click a link.

One cookie keeps you logged in. Vercel Analytics counts pages without cookies.

Emails

We email you to reset your password, when you hit a cap, and when your Stripe key is paused.

Turn off the cap-hit email in the dashboard.

Services we use

Vercel for hosting, Neon for the database, Resend for email, Stripe for your numbers.

Deleting

Delete a startup in the dashboard: its key, history, goals, cheers and counters go with it.

To delete your account, email hello@nextcap.space.