Privacy Policy

Last updated: March 12, 2026

1. Who We Are

PainSignal ("we," "us," "our") is a free market intelligence platform operated as part of the GZOO Business Platforms portfolio. PainSignal helps developers, founders, and product builders discover real-world problems worth solving by analyzing publicly available feedback from workers and business owners across every industry.

2. Information We Collect

Account Information

When you create an account, we collect:

  • Name and email address
  • Profile information (avatar, bio, username) you choose to provide
  • OAuth profile data if you sign in with GitHub or Google (name, email, avatar URL)

User-Generated Content

When you use community features, we collect:

  • Votes on problems and opportunities
  • Comments you post
  • Project submissions ("I'm Solving This" claims), including project name, URLs, description, and tech stack

Automatically Collected Information

  • Session cookies required for authentication (via NextAuth.js)
  • Cloudflare Turnstile tokens for bot protection on forms
  • Server logs (IP address, user agent, timestamps) retained for security and debugging

Public Data We Analyze

PainSignal collects and analyzes publicly available content from sources like YouTube comments and app store reviews. This data is not linked to individual identities. We use AI to extract structured insights about workplace problems — we do not collect or store any personal information from these public sources.

3. How We Use Your Information

  • To provide and maintain your account
  • To display your community contributions (comments, votes, project claims)
  • To send transactional emails related to your account (password resets, notifications you opt into)
  • To enforce our Terms of Service, including spam detection and content moderation
  • To improve the platform and fix bugs

4. AI Processing

We use artificial intelligence (including large language models) to:

  • Classify publicly available posts into structured problem signals
  • Generate opportunity summaries and app concept briefs
  • Screen user-submitted project links for quality and relevance
  • Detect spam in user-generated content

Your personal account information is not sent to AI models. AI processing applies only to public data and to content you voluntarily submit (project descriptions, comments).

5. Information Sharing

We do not sell your personal information. We share data only in these limited circumstances:

  • Public profile: Your name, avatar, and username are visible on your public builder profile and alongside your comments and project submissions.
  • Service providers: We use third-party services for authentication (GitHub, Google OAuth), bot protection (Cloudflare Turnstile), AI processing (Anthropic, OpenAI, DeepSeek, Google), and hosting (OVH). These providers process data only as needed to provide their services.
  • Legal requirements: We may disclose information if required by law, court order, or governmental request.

6. Cookies

We use only essential cookies required for authentication and session management. We do not use advertising cookies, tracking pixels, or third-party analytics cookies.

7. Data Retention

  • Account data: Retained as long as your account is active. You may request deletion at any time.
  • User-generated content: Comments, votes, and project submissions remain on the platform unless you delete them or request account deletion.
  • Server logs: Retained for up to 90 days for security and debugging purposes.
  • Public signal data: Retained indefinitely as aggregated, non-personal market intelligence.

8. Your Rights

You have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate information via your account settings
  • Delete your account and associated personal data
  • Export your data

To exercise these rights, contact us at our contact page or email [email protected].

9. Security

We implement industry-standard security measures including encrypted connections (HTTPS), hashed passwords, rate limiting, and bot protection. While no system is 100% secure, we take reasonable steps to protect your information.

10. Children's Privacy

PainSignal is not intended for children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes via email. The "Last updated" date at the top reflects the most recent revision.

12. Contact

For privacy-related questions or requests, contact us at [email protected] or use our contact form.