Privacy.
Updated October 10, 2026
Your Stripe key
You give us a read-only restricted key. It is sealed with AES-256-GCM before it is stored, and never shown again, only its last 4 characters.
We use it to read your subscriptions and coupons, and nothing else.
What we store
Your MRR, subscription count and goals, day by day. No customer data: no names, emails or cards.
Your account: email, password hash, and your X handle if you add one.
What is public
Your startup's name, X handle, MRR, goal and charts. Your email never is.
Switch off Public page in the dashboard to hide a startup. It disappears within minutes; card images already shared on X may stay cached for up to a day.
Visitors
Cheers, profile views and clicks to a site are counted once per visitor per day. So is the "here today" counter on the landing page.
A visitor is a keyed hash of IP and browser that changes every day. We never store the raw IP.
View, click and visit rows are deleted after 31 days.
To limit abuse, a keyed hash of your IP (or email, for a password reset) is also kept for a few minutes with each attempt to log in, sign up, reset a password, view a page or click a link.
One cookie keeps you logged in. Vercel Analytics counts pages without cookies.
Emails
We email you to reset your password, when you hit a cap, and when your Stripe key is paused.
Turn off the cap-hit email in the dashboard.
Services we use
Vercel for hosting, Neon for the database, Resend for email, Stripe for your numbers.
Deleting
Delete a startup in the dashboard: its key, history, goals, cheers and counters go with it.
To delete your account, email hello@nextcap.space.