Privacy Policy
Last updated: 31 May 2026
This Privacy Policy explains how Licrat ("we", "us"), which operates the Winnow service at licrat.com, winnow.licrat.com and api.licrat.com (the "Service"), collects and uses personal data. We are the data controller for the data described below. For any question, contact support@licrat.com.
What we collect
- Account data. When you sign in with Google (and, in future, GitHub), we receive your name, email address and a unique account identifier from that provider. We never receive your password.
- Waitlist data. If you submit the early-access form, we store the email address you provide.
- Billing data. Payments are processed by Stripe. We do not see or store your card details. We store your Stripe customer and subscription identifiers and your plan status.
- API content. When you call the Winnow API, you send survey-response data to be scored. Winnow processes this data only to compute a quality score and return the result. We do not store the content of the responses you submit.
- Technical data. As with most online services, our infrastructure providers may log technical information such as IP address, request time and basic request metadata, for security and reliability.
Why we use it (legal bases)
- To provide and operate the Service and your account — performance of a contract.
- To process payments and manage subscriptions — performance of a contract.
- To keep the Service secure and enforce limits such as rate limiting and abuse prevention — our legitimate interests.
- To respond to the waitlist sign-up you requested — your request / consent.
Who processes it on our behalf
- Google — sign-in and authentication.
- Stripe — payment processing.
- Cloudflare — hosting, content delivery and storage.
- Google Cloud — hosting of the API.
Some of these providers are located outside the EU/EEA. Where that is the case, transfers are covered by appropriate safeguards such as Standard Contractual Clauses or adequacy decisions. We do not sell your personal data.
Data you submit about others
If the survey responses you send to the API contain personal data of your respondents, you are the controller of that data and we act as your processor, processing it only to provide the scoring service and not retaining it. A data processing agreement is available on request.
Retention
We keep account data while your account is active and for a reasonable period afterwards where needed for legal, accounting or security purposes. Waitlist emails are kept until you ask us to remove them. Technical logs are kept for a limited period.
Your rights
If you are in the EU/EEA, you have the right to access, correct, delete, restrict or object to the processing of your personal data, and the right to data portability. To exercise any of these, contact support@licrat.com. You also have the right to lodge a complaint with your local data protection authority — in Spain, the Agencia Española de Protección de Datos (AEPD, aepd.es).
Cookies
We use only strictly necessary cookies: a session cookie to keep you signed in, and a short-lived cookie used during sign-in for security. We do not use advertising or tracking cookies.
Changes
We may update this policy. We will post the new version here with an updated date.
Contact
Licrat, Spain — support@licrat.com