Legal

Privacy Policy

This policy explains how StartupWorker handles information when you browse the site, create an account, use professional signals, publish a profile or Playbook, or send us a submission.

Last updated: September 10, 2026

1. Scope and who we are

This Privacy Policy applies to StartupWorker’s website and related services (the “Service”). “StartupWorker,” “we,” “us,” and “our” refer to the operator of the Service. Privacy questions and requests may be sent to privacy@startupworker.com.

2. Information we collect

Information you provide

  • Account and sign-in information: your email address and authentication details provided through an email magic link or supported sign-in provider. If you use Google or GitHub sign-in, we may receive basic account information such as your name, email address, username, or profile image from that provider.
  • Profile and onboarding information: username, first and last name, optional professional title and company, selected work areas, headline, biography, avatar URL, website, and social-profile links. You decide whether to publish your profile.
  • Email preferences: whether you choose to receive optional StartupWorker editorial or product updates, along with the date, source, and policy version associated with that choice. Essential account and service messages are separate.
  • Saved and contributed content: private saves; follows; Playbook titles, descriptions, resources, Recipes, and notes; publication and legacy-consent choices; resource suggestions; corrections; blocks; reports; and messages included with submissions. Older recommendation and Toolbox records may be retained for compatibility but are not presented as current product features.
  • Communications: information you include when you contact us about support, privacy, security, or another request.

Information collected automatically

  • Service and device data: IP address, browser and device type, timestamps, requested pages, referring information, and security or diagnostic logs that our hosting, authentication, database, and network providers may process when they deliver the Service.
  • Product analytics: an anonymous first-party session identifier and limited events such as a search, result open, save, Playbook creation, submission, or outbound resource-link click. Analytics may include broad categories, counts, and whether a visitor was signed in. We do not send search text, profile text, Playbook text, notes, email addresses, account IDs, item IDs, URLs, or precise location to PostHog through our analytics endpoint, and we have disabled PostHog person profiles and GeoIP enrichment.

3. How we use information

We use information to:

  • provide accounts, authentication, onboarding, relevant discovery, private saves, professional signals, profiles, Playbooks, safety controls, and submissions;
  • send optional editorial and product updates when you choose to receive them and maintain your subscription preferences;
  • publish profiles, Playbooks, and eligible professional signals according to your publication, visibility, and consent choices;
  • review suggestions, prevent duplicates and abuse, maintain catalog quality, and communicate moderation outcomes;
  • operate, secure, troubleshoot, measure, and improve the Service;
  • respond to questions, requests, and security reports;
  • enforce our Terms of Use and protect users, StartupWorker, and others; and
  • comply with law and establish, exercise, or defend legal claims.

4. How we disclose information

We may disclose information in these circumstances:

  • At your direction or publicly: if you publish a profile or Playbook, the fields shown in the publication controls become available to anyone. New Follows of people, tools, courses, skills, agents, and Playbooks are public by default while your profile is published, subject to legacy consent and safety controls. A resource’s inclusion in a public Playbook is separate public contextual evidence. Public aggregate counts may be larger than public identity lists because some older identities are ineligible or hidden.
  • Information that remains private: Saves and saver identities are private. A private profile does not disclose follow identities. Existing follows made under the earlier private policy remain unattributed unless you separately consent to make them public. Your email address, email preferences, internal account ID, administrator status, blocks, reports, private Playbooks, and retained compatibility records are not intended to appear publicly.
  • Service providers: vendors that help us provide infrastructure, hosting, authentication, application data, email delivery, analytics, uploads, abuse prevention, security, and technical operations. These include Vercel for hosting, Supabase for authentication and application data, Resend for email delivery, PostHog for limited product analytics, Upstash for request throttling, and Vercel Blob for avatar storage, plus Google or GitHub when you choose the corresponding sign-in method. If automated moderation is enabled, the minimum necessary contribution text or submitted URL may also be sent to OpenAI for content classification or Google services for malicious-link and YouTube metadata checks; we do not include your email address or internal account identifier in those checks.
  • Legal and safety reasons: when we reasonably believe disclosure is required by law or necessary to protect rights, safety, security, or the integrity of the Service.
  • Business changes: in connection with a financing, merger, acquisition, reorganization, sale of assets, or similar transaction, subject to appropriate protections.

StartupWorker does not sell personal information for money or use personal information for cross-context behavioral advertising. If our business model or data practices change, we will update this policy and provide any notice or choice required by applicable law.

5. Cookies and similar technology

We use cookies required to authenticate users and maintain secure sessions. When analytics is configured, we also set an HTTP-only, first-party cookie containing a random identifier so that limited product events from the same browser session can be grouped without using an account identity. Our providers may use technical storage needed to deliver their services.

Browser controls can block or delete cookies, but blocking required authentication cookies may prevent sign-in and member features from working. Our limited product analytics are used to understand and improve the Service, not to serve targeted advertising.

6. Retention

We keep information only as long as reasonably necessary for the purposes described here, including to provide the Service, protect security, meet legal obligations, resolve disputes, and enforce agreements. Retention varies by data type and system.

If you request account deletion, StartupWorker immediately unpublishes your public profile and public Playbooks while the request is pending. After the request is verified and any lawful retention exception is resolved, an authorized operator deletes the authentication identity, which is designed to cascade through related live application records. Information may remain for a limited time in backups, security logs, provider systems, or records that we must retain for legal, fraud-prevention, dispute-resolution, or security purposes, and is removed or anonymized when those purposes expire.

7. Your choices and privacy rights

  • You can edit your profile and change whether your profile or Playbooks are public from your account controls. Making your profile private hides your follow identities.
  • You can change your optional editorial and product email preference from your profile settings. Essential account and service messages are separate from that preference.
  • New follows are public by default on a published profile. A separate one-time consent choice may be shown for follows created under the earlier private policy; publishing a profile does not silently make those older follows public.
  • You can remove Saves and Follows; edit or delete eligible Playbooks; block members; report content or conduct; and request account deletion.
  • You may ask to access, correct, or delete personal information, or object to or restrict certain processing. Your rights depend on where you live and may be subject to legal exceptions and identity verification.
  • If we deny a request, you may have a right to appeal or complain to a regulator, depending on applicable law.

To make a privacy request, use the in-product controls or email privacy@startupworker.com.

8. Security

We use administrative, technical, and organizational safeguards designed to protect information. No system is completely secure, and we cannot guarantee absolute security. Massachusetts law may require businesses holding certain personal information about Massachusetts residents to maintain a written information security program and provide notices after qualifying security incidents. See our Security page for reporting instructions.

9. Children

The Service is intended for adults. You must be at least 18 years old to create an account or contribute content. The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can review and take appropriate action.

10. Third-party services and international processing

The Service links to third-party tools, courses, agents, websites, and profiles. Their privacy practices are governed by their own notices. The Service also embeds videos using YouTube’s privacy-enhanced player; YouTube may receive service and device information when your browser loads or plays an embedded video. Our providers may process information in the United States and other places where they operate. Where required, we will use appropriate safeguards for cross-border transfers.

11. Changes to this policy

We may update this Privacy Policy as the Service, providers, or law changes. We will post the revised version and update the date above. If a change materially affects how we use information already collected, we will provide any additional notice or choice required by law.

12. Contact us

Privacy questions and requests may be sent to privacy@startupworker.com.