This policy describes how GrowthRadar ("we," "us") handles data when you visit growthlanding.ai(the "Site"). It is written in plain language and reflects what the Site actually does. We have deliberately kept our data practices minimal.
1. Information we collect
Very little, and only what you choose to give. The Site has no comment system. You can browse every page — the full leaderboard, every product analysis, and the playbooks — without identifying yourself. The only personal data we collect is what you voluntarily provide, in one of two ways: subscribing to the weekly digest (your email), or creating an optional account (your OAuth profile). Accounts are covered in Section 2.
Specifically:
- Email address — only when you submit the newsletter form. Used solely to send the weekly digest. Stored in our database (Neon Postgres, Section 3) and synced to our email provider (Resend, Section 3) for delivery. You can unsubscribe at any time via the link in every email.
- Account profile — only if you choose to sign in. When you log in with GitHub or Google, we receive the profile information your provider shares with us: typically your name, email address, and profile image. See Section 2 for what we store and how.
- Saved sites (watchlist) — only if you use the watchlist feature while signed in. This is a list of product domains you have saved; it holds no additional personal data beyond what is needed to link them to your account.
We do not collect:
- Your physical address, phone number, or date of birth.
- Passwords — we never see or store one. Sign-in is handled entirely by your OAuth provider (GitHub or Google); we only receive the limited profile data described in Section 2.
- User-generated content — there is no comment system.
- Precise location or device fingerprints.
When you load a page, standard technical data (such as your IP address, browser type, and the requested URL) is transmitted to our hosting provider as part of how the web works. This is described in Section 3.
2. Accounts & authentication
Creating an account is optional. The core leaderboard, product pages, and playbooks are fully usable without signing in; an account only unlocks personal features such as the watchlist.
How you sign in. Authentication is handled by Auth.js using third-party OAuth providers — currently GitHub and Google. We do not offer password-based sign-in and never see or store your password. When you sign in, your provider authenticates you and then shares a limited profile with us (name, email, and profile image, as described in Section 1). GitHub and Google process the sign-in itself under their own privacy policies (see Section 3).
What we store. When you have an account, the following is kept in our database (Neon Postgres, Section 3):
- Profile — your name, email address, and profile image (as returned by your OAuth provider), plus an
emailVerifiedflag set by the provider. - OAuth tokens — the tokens your provider issues during sign-in (such as access, refresh, and ID tokens) are stored on the
accountstable so your session can be refreshed without prompting you again. We do not use these tokens to read or post on your behalf beyond keeping you signed in. - Watchlist — the product domains you save.
Your session. While you are signed in, your session is kept in an encrypted, httpOnly cookie (a JWT signed with our AUTH_SECRET). The session itself is notstored in the database — only the account data above is. The cookie cannot be read by client-side JavaScript. The header's account menu checks whether you are signed in by calling GET /api/me, which returns only your name and profile image — never your email address.
Signing out & deletion. You can sign out at any time, which clears the session cookie from your browser. To permanently delete your account and the associated data (profile, tokens, and watchlist), contact us as described in Section 7.
3. Third-party services
The Site is intentionally lean. As of the last update, the following third parties process data in connection with your visit:
GitHub & Google (sign-in providers)
When you sign in, you authenticate through GitHub or Google rather than through us. Whichever provider you choose processes the sign-in under its own privacy policy and shares with us the limited profile described in Sections 1 and 2 (name, email, and profile image) plus the OAuth tokens needed to keep you signed in. We request only the scopes required for sign-in and do not ask for access to your repositories, contacts, or other account data. See GitHub's Privacy Statement and Google's Privacy Policy.
Vercel (hosting infrastructure)
The Site is hosted on Vercel. When you request a page, Vercel processes the request and may log standard server-side data — IP address, timestamp, requested URL, browser user-agent, and HTTP status. This is operational infrastructure logging used to serve and secure the Site, not behavioral tracking. See Vercel's Privacy Policy.
Vercel Web Analytics & Speed Insights (privacy-friendly metrics)
The Site uses Vercel's built-in Web Analytics (to count page views, referrers, and rough geography) and Speed Insights (to measure Core Web Vitals — LCP, CLS, INP). Both are cookie-free and anonymous: instead of cookies, a visitor is identified by a short-lived hash of the request that Vercel discards after 24 hours. No data that can identify or re-identify an individual across sites is collected, stored, or shared with third parties.
The specific fields Vercel may attach to a page-view event are: timestamp, URL path, dynamic route, referrer, country/region, device OS, browser, and device type. All aggregated — never tied to your name, email, or a persistent profile. Because it is cookie-free and anonymized, no consent banner is required under GDPR/ePrivacy for this kind of measurement. See Vercel Analytics privacy & compliance.
Both services only operate in the deployed Vercel environment — they do not transmit data when you run the Site locally in development.
Google Analytics (cookie-based, consent-gated)
The Site also uses Google Analytics 4 to measure traffic. Unlike the Vercel services above, Google Analytics uses cookies (small files stored in your browser) to recognize returning visitors and aggregate usage data. The main cookies are _ga (distinguishes users, ~2 years) and _ga_<id> (maintains session state, ~2 years).
Cookie-based tracking requires your consent under EU/UK law (GDPR/ePrivacy). The Site implements Google Consent Mode v2 and a consent banner for visitors in the European Economic Area (EEA) and the United Kingdom:
- For EEA/UK visitors: Google Analytics cookies are notset until you click "Accept" on the banner. If you click "Reject" (or ignore it), Google still receives an anonymous, cookieless ping so aggregate trends can be modeled — but no cookie is written and you are not tracked across sessions.
- For visitors outside the EEA/UK: analytics is permitted by default under the region settings, so cookies are set without a banner. You can still opt out at any time via "Cookie Settings" in the footer.
You can change your choice any time by clicking Cookie Settings in the footer. See Google Consent Mode reference and how Google uses cookies.
Microsoft Clarity (session replay, consent-gated)
The Site uses Microsoft Clarity to record anonymous session replays and generate heatmaps — short recordings of how visitors move around and click on pages, used to find usability problems. Clarity uses cookies (mainly _clck and _clsk) to stitch page views into a session.
Because Clarity is cookie-based, it is held to the same consent gate as Google Analytics: the Clarity code is not loaded at alluntil you click "Accept" on the consent banner. If you reject (or ignore) the banner, no Clarity script runs, no recording is made, and no Clarity cookie is set. This is stricter than Clarity's own default, which would load immediately in a cookieless mode — we defer it entirely so nothing is collected before you opt in. If you later change your mind, clicking "Reject" in Cookie Settings tells Clarity to delete its cookies and end the session. See Clarity Consent Mode and Microsoft's Privacy Statement.
Google Favicons (site icons)
To show the logo of each listed product, the Site loads small icons from Google's public favicon service (www.google.com/s2/favicons). Your browser makes this request directly to Google, which means Google receives your IP address, the time of the request, and the specific domain whose icon is being loaded. We use this service only for display and do not control what Google does with that request data. See Google's Privacy Policy.
Fonts are not loaded from a third party — they are bundled into the Site at build time, so no request is made to a font service when you visit.
Neon Postgres (account & newsletter storage)
Our database is hosted on Neon Postgres (a managed PostgreSQL service). It holds two kinds of data. First, newsletter subscriptions: your email address, the submission timestamp, the page you subscribed from, and a status field (pending / subscribed / unsubscribed). Second, if you have an account, the account data described in Section 2 (profile, OAuth tokens, and watchlist). Neon processes this data on our behalf as a processor; we control the database and its contents. See Neon's security & privacy.
Resend (email delivery)
To send the weekly digest, your email address is synced to our email delivery provider, Resend. Resend receives only your email address (no other personal data) and sends on our behalf. Every email we send includes an unsubscribe link; using it updates your status in both Neon and Resend. See Resend's Privacy Policy.
4. Cookies and local storage
The Site uses four kinds of storage, and keeps them to a minimum:
- Session cookie — only if you sign in. An encrypted, httpOnly cookie (a JWT signed with our
AUTH_SECRET) keeps you signed in between requests. It is strictly functional (required for the account feature to work), is not readable by client-side JavaScript, and is not used for tracking or advertising. Signing out clears it. See Section 2. - Google Analytics cookies (
_ga,_ga_<id>) — only the GA service described in Section 3 sets these. They last about 2 years and are used to recognize returning visitors and aggregate usage. EEA/UK visitors: these are set only after you accept the consent banner. - Microsoft Clarity cookies (
_clck,_clsk) — set by the session-replay service described in Section 3 to group page views into a recording. They last roughly up to 1 year. Like the GA cookies, EEA/UK visitors: these are set only after you accept the consent banner (Clarity does not load until then). - Local storage — the Site stores your consent choice (Accept / Reject) in a single local-storage entry named
growthradar-consentso the banner doesn't reappear on every visit. This is strictly functional and contains no identifying information.
We do not set any advertising cookies, marketing cookies, or third-party cookies other than those listed above. There is no Facebook/Meta Pixel or cross-site behavioral tracking.
5. Analytics and advertising
The Site uses three analytics services, described in detail in Section 3:
- Vercel Web Analytics & Speed Insights — cookie-free and anonymous; no consent needed.
- Google Analytics 4 — cookie-based and consent-gated for EEA/UK visitors via Consent Mode v2.
- Microsoft Clarity — cookie-based session replay; not loaded at all until consent is granted (stricter than its default).
We do not use any advertising network and do not sell or share data with advertisers. We do not use cross-site behavioral trackers like the Facebook/Meta Pixel. If we ever add advertising or another cookie-based service, we will update this Policy before doing so and request consent where required.
6. Children's privacy
The Site is not directed at children under 13 and we do not knowingly collect data from them. The content (SaaS and AI product analysis) is intended for adults doing product and market research.
7. Your rights
If you have subscribed to the weekly digest, you can unsubscribe at any timeusing the link at the bottom of every digest email. If you want your email address fully deleted from our records, reply to any digest email (or reach out through the project's public channel linked from the Site) and we will remove it from both Neon and Resend.
If you have an account, you can sign out at any time from the account menu, which clears your session cookie. To permanently delete your account and the data tied to it — your profile, OAuth tokens, and watchlist — contact us through the same channel above and we will remove it from Neon. Signing out ends the current session but does not delete the account itself.
Depending on where you live, you may have rights under GDPR (EU/UK), CCPA (California), or similar laws — we will honor valid requests to access, correct, or delete your data.
8. External links
Each product page links to the product's own website. We are not responsible for the privacy practices or content of those external sites. Please review their policies separately.
9. Changes to this policy
We may update this Policy as the Site evolves. The "Last updated" date at the top will always reflect the most recent version. Material changes (such as introducing analytics or advertising) will be called out clearly.