Privacy Policy
First 100 is an independent solo project operated from Chicago, Illinois, United States. This policy explains what we collect, why, and how to get it removed. We don't sell data and we don't run ads.
1. What we collect about you
- Account. When you sign in with Google we receive your email address, name and a user id. We don't receive your Google password and we don't get access to your Google account.
- What you put in. Project names and handles, the website URL you ask us to read, any example posts you paste, your customer profile text, images you upload or generate, captions, schedules, and the 👍/👎 corrections you make.
- Usage and cost records. A ledger of billable AI calls (which kind, token counts, cost) used to enforce your plan's limits and our own spend caps.
- Billing. A Stripe customer id and your subscription status. We never see or store your card details — Stripe handles those directly.
- Technical. Standard server logs from our host (IP address, browser, timestamps, error traces), kept briefly for security and debugging.
2. Posts by people who aren't our users
This is the part most policies skip, so we'll be direct. To find potential customers, the service retrieves posts that people published publicly on third-party platforms (currently Reddit) and stores the parts needed to show you a result: the title, the text, the community it came from, a link to the original, and the model's assessment of it.
- Why we're allowed to. We rely on legitimate interests: helping a very small business identify people who have publicly asked about a problem it solves. We only ever process content the author chose to publish in public, and we link back to the source rather than passing it off as ours.
- We minimise it. We no longer store post authors' usernames — nothing in the product needs them. We don't collect email addresses, profiles, follower lists or any contact details for these people, and we never message them.
- We don't keep it forever. After 180 days, a scheduled job strips the human-written content from these records, leaving only the classification and the link. Deleting a project erases its records entirely.
- Removal on request. If something you wrote appears in our system and you want it gone — including if you deleted it at the source — email support@first-100-users.com with the link and we'll remove it. You don't need an account with us and you don't need to explain why.
3. Why we process it
- To run the service you signed up for — that's performance of our contract with you.
- To enforce plan limits and prevent runaway costs and abuse — our legitimate interest.
- To take payment and keep tax records — contract and legal obligation.
- To email you about your account (trial ending, payment problems, material changes). Marketing email, if we ever send it, will be opt-in and easy to leave.
We do not sell personal information, share it for cross-context behavioural advertising, or profile you for ads.
4. Who else processes it
We keep the list of third parties short and it is all infrastructure — none of them are advertising companies:
- Vercel — hosting and server logs.
- Supabase — database and private image storage.
- Google — sign-in only.
- Stripe — payments and the billing portal.
- Anthropic — the AI that classifies posts and drafts captions. It receives your customer profile, the posts being classified, and your drafting prompts.
- fal.ai — AI image generation, when you choose to generate an image.
- Tavily — the search provider used to retrieve public posts.
We use these providers on terms that state your content is not used to train their models by default. We may also disclose information if the law genuinely requires it.
5. How long we keep things
- Your projects and content — for as long as your account exists.
- Deleted projects — recoverable for 60 days, then permanently erased, images included.
- Found posts — content stripped after 180 days (see section 2).
- Billing and usage records — up to 7 years, because tax records require it.
- Server logs — short-term, per our host's defaults.
6. Cookies
We set what the app needs to work: a sign-in session cookie, and (for admins) a preference cookie. These are essential and carry no tracking.
There are no advertising or third-party tracking cookies today. If we add website analytics, we'll ask for your consent before anything loads, and this page will say so.
7. Security
Traffic is encrypted in transit. Images live in a private bucket served only through an authenticated proxy that checks ownership on every request, and every database query is scoped to the signed-in owner at a single enforced choke point. No system is perfect; if a breach ever affects your data, we'll tell you promptly and plainly.
8. Your rights
Whoever and wherever you are, you can ask us to show you what we hold, correct it, export it, or delete it. Email support@first-100-users.com and we'll act within 30 days. You can also delete any project yourself from Settings.
- UK/EU residents. You have the GDPR rights of access, rectification, erasure, restriction, portability and objection — including the right to object to our legitimate- interests processing described in section 2 — and the right to complain to your data protection authority.
- California residents. You have the right to know, delete, correct and opt out under the CCPA/CPRA. We do not sell or share personal information, so there is nothing to opt out of, and we will never discriminate against you for exercising a right.
9. International transfers
The service is operated from the United States and your data is stored on US-based infrastructure. If you use it from outside the US, you're sending your data there.
10. Children
First 100 is not for anyone under 18. We don't knowingly collect data from children; if we learn we have, we'll delete it.
11. Changes and contact
If this policy changes materially we'll notify you in the app or by email. Questions, requests and complaints all go to the same place — a real person reads them.
See also our Terms of Service.