Privacy Policy

Last updated: October 6, 2026

1. Who we are

Honest MRR ("Honest MRR", "we", "us") provides subscription analytics that connect to your billing providers and produce MRR, churn, LTV, cohort, and related business reports. This policy explains what we collect, why, and your choices.

2. Information we collect

  • Account information — your name, email address and, if the service shares one, profile picture, received from the sign-in service you use (Google, Apple, Facebook or Microsoft, as offered on the sign-in page) when you create your account; used to authenticate you and to create your organization, which starts out named after you. With Apple you can share a private relay address instead of your own. For each sign-in we keep a session record, including the IP address and browser it came from, and we store the tokens the sign-in service returns with your account — we don't use them for anything beyond signing you in. If you invite teammates, we store the email you label the invite with and the accounts that accept.
  • Billing data we ingest on your behalf — when you connect a provider, we read your customers, subscriptions, prices, invoices, and charges to compute your metrics, and store those records — and the webhook events your providers send us — so every MRR movement can be traced to its source. Depending on the provider and what you store there, these records can include your customers' names, emails, billing addresses and phone numbers, transaction amounts, and card details such as brand, last four digits and expiry date — never full card numbers.
  • Provider credentials — the keys and tokens you paste (billing providers, app-store reporting credentials such as an Apple App Store Connect API key or Google Play service account, and traffic sources such as a Google Analytics service-account key, a Google Search Console service-account key, or a Bing Webmaster API key), stored encrypted (see §6). We ask for the most limited credential each service offers — read-only wherever one exists — use it only to read your data, and never initiate payments, refunds, or changes to your customers or subscriptions. The one thing we may create, and only when the key you provide permits it, is a webhook endpoint in your Stripe account pointing at Honest MRR, so changes reach your reports as they happen; it stays in your Stripe account after you disconnect, and you can delete it there.
  • Ad platform tokens and spend data — if you connect an ad account (TikTok, Meta, Google Ads, or Microsoft Advertising where it is offered), we store the OAuth tokens encrypted and read daily spend, impressions, clicks and reported conversions, per campaign and with campaign names, to compute acquisition metrics. We request read-only scopes where the platform offers them, and in every case use the connection only to read reporting data — never to create or modify campaigns.
  • Uploaded and downloaded reports — earnings reports you upload (e.g. Amazon Associates or creator payout CSVs) and the app-store report files we download are kept verbatim, so every figure remains traceable to its source document. Ad-spend CSVs you upload are stored as the daily rows we read from them.
  • Report links you save — for revenue sources without an API you may save a link to your platform's dashboard, and a link that returns your report as a CSV. We fetch a CSV link when you save it and then once a day, and import it like an upload; because such a link usually grants access on its own, we store it encrypted and show only its host. A dashboard link is never fetched.
  • Traffic analytics — if you connect Google Analytics, Google Search Console or Bing Webmaster, we read daily aggregate counts (sessions, users, pageviews, search clicks, impressions and average position) and, from the search sources, your top search queries and landing pages. We request only aggregate reports, never individual visitor data.
  • Information you enter — operating costs and a cash balance you type in for profit and runway, notes you write for investor updates, an optional MRR goal, expiry dates for the keys you connect, a Slack or Discord webhook for the weekly summary (stored encrypted), and an optional company profile (logo, tagline, founded year, website).
  • Payment information for our own plans — if you purchase a paid Honest MRR plan, payment is processed by Stripe: we create a Stripe customer under your organization's name, and you enter your payment details on Stripe's own checkout page. We receive and store your plan, its status and the Stripe identifiers; your full card number never touches our systems.
  • API keys you create — keys for our metrics API (read-only unless you grant the import scope) are stored as one-way hashes; the full key is shown to you once and cannot be recovered by us.
  • Messages you send us — if you email us, we receive what you write; the support page pre-fills your organization's name and ID so we can find it.
  • Technical data — logs needed to operate and secure the service (when something fails, they can include fragments of the data being processed), error reports (see §9), and usage analytics on our marketing pages (see §8).

3. How we use information

To provide and maintain the service: compute your reports, keep your data current — through webhooks, a daily re-read of sources without one, and a daily read of any report link you save — send the service emails you'd expect, provide support, and secure and improve the product. We do not sell your data or your customers' data, and we do not use it for advertising.

Service emails go to your organization's owners and admins, and only to addresses that have been confirmed: a daily alert when something needs attention, a weekly summary on Mondays, and, while you are on a free trial, one reminder three days before it ends. The one exception is the confirmation email itself, sent to a new address that needs confirming. Invitations are not emailed — you share the invite link yourself.

4. Sharing you control

Some features publish data only when you choose to. Share links, investor updates, the open-startup page, and its embeddable MRR badge show your organization's name and aggregate metrics — never customer-level data — with your company profile if you set one; an investor update also shows the notes you write for it. The open-startup page is public, and once your organization has real synced revenue it is listed for search engines.

A share link can't be withdrawn early: it stops working at the expiry you choose when you create it (7, 30 or 90 days). The open page stops resolving the moment you disable it; a badge image that was already displayed may stay cached for up to 10 minutes.

If you add a Slack or Discord webhook, we post a one-line weekly summary there: your organization's name, MRR and its change over the week, and new and churned MRR. Teammates you invite see your organization's reports, including customer-level detail, according to the role you give them, and anyone holding one of your API keys can read your organization's reports until you revoke it.

5. Our role (controller vs processor)

For your account information, we are the data controller. For the billing and customer data we ingest from your providers, we act as a data processor on your behalf — you remain the controller and are responsible for having a lawful basis to share it with us.

6. How we protect your data

The credentials you connect — provider API keys, webhook secrets, OAuth tokens for ad and Stripe App connections, store and traffic credentials, saved report links, and your Slack or Discord webhook — are encrypted at rest with AES-256-GCM, and we never display more than the last four characters of a key. Metrics API keys are stored as one-way hashes. The data imported from your providers, and everything computed from it, is isolated per organization by row-level security in the database; the remaining tables are filtered by organization in the application, and access is restricted to systems that need it. If we become aware of a security incident affecting your data, we will notify you without undue delay. More detail is on our security page.

7. Cookies and browser storage

We use only the cookies the service needs to work:

  • your sign-in session, which lasts 7 days and renews while you use the service;
  • which organization you are working in, plus a random value that stops a tab still showing a different organization from changing it — set when you switch organizations or accept an invite, and kept for a year;
  • short-lived cookies that protect sign-in and the flows that connect your accounts; they expire within 10 minutes.

The app also keeps a few settings in your browser's local storage: your light or dark theme, whether you've finished the welcome tour, and reminders you've snoozed. Google Analytics' own cookies are covered in §8.

8. Analytics

We use Google Analytics on our marketing pages — the home page, pricing, integrations, comparisons, methodology, the MRR calculator, the API documentation, and our about, security, privacy and terms pages — to understand how they are used (pages visited, approximate location, device type). It never loads in the app, on the sign-in page, or on share, invite and open-startup pages. Google Analytics sets its own cookies and processes data under Google's terms. We do not use analytics data for advertising, and your billing data and your customers' data are never sent to analytics. You can block analytics cookies in your browser without affecting the service.

9. Sub-processors

We run the service on our own server infrastructure and rely on a small number of providers to operate it: Stripe (payment processing for our own plans); Google (Gmail SMTP, for service emails, and Google Analytics on our marketing pages); Sentry (error monitoring — reports carry technical details such as the page and organization involved, with link tokens, email addresses, cookies and request bodies removed); and Cloudflare (network routing in front of our servers). Exchange rates come from the Frankfurter API; no personal data is sent to it.

Separately, the services you choose to use with Honest MRR — the service you sign in with, billing providers (Stripe, Paddle, Lemon Squeezy, RevenueCat, Superwall, Polar, Patreon, Whop, Qonversion), app-store reporting accounts (Apple App Store Connect, Google Play), ad platforms (TikTok, Meta, Google Ads, Microsoft Advertising), traffic sources (Google Analytics, Google Search Console, Bing Webmaster), the sites your saved report links point to, and any Slack or Discord channel you send summaries to — are your own service providers, not our sub-processors: data flows between them and us at your instruction. This list is current as of the date above; we update it here when it changes.

10. Data retention & deletion

We keep your data while your account is active.

  • Disconnecting a billing, ad or traffic source deletes the credentials we stored for it and stops syncing; the data it already brought in stays in your reports. When disconnecting a billing provider, your organization's owner can choose to delete that provider's imported data as well. Removing a report link stops future reads; what it already imported stays. App-store connections and uploaded reports can't yet be removed one by one — email us or delete the organization.
  • When imported data is deleted, the integrity journal keeps each removed record's identifier and a one-way fingerprint of it — never its contents — so the deletion stays verifiable.
  • Deleting your organization removes its connections, credentials, imported and uploaded data, reports, integrity journal and everything derived from them — from our database at once, and from our backups within 14 days, which is how long backups are kept.
  • Your sign-in account — your name, email and sessions — is not deleted with an organization (a new, empty organization is created for you), and Stripe keeps its own records of payments for our plans. Email us to delete your account.

11. Your rights

Depending on your jurisdiction, you may have rights to access, export, correct, or delete your data. Contact us to exercise them. You can also export your organization's data from within the app: the export holds its connections' details, imported records, reports, uploads, team and settings — with the raw provider records and files as a separate download — and never includes credentials or keys.

12. Children

The service is for businesses and is not directed to children under 16. We do not knowingly collect personal information from children.

13. International transfers

We host the Service on our own infrastructure, and your data may be stored and processed in countries other than your own. Where required by applicable law, we rely on appropriate safeguards for such transfers, such as standard contractual clauses.

14. Changes

We may update this policy; material changes will be reflected by the "last updated" date above and, where appropriate, a notice in the app.

15. Contact

Questions about privacy? Contact us by email.