Privacy Policy
Last updated: 27 September 2026
Productus (productus.ai) is operated by Elio Keddisseh, an individual acting in his own name, pending the incorporation of Productus as a company in Singapore. In this policy, “we” and “us” mean Elio Keddisseh.
Elio Keddisseh is the data controller for the personal data described here, on a temporary basis. Once the Singapore company exists, it will take over as operator and controller. We will update this page and email every account holder before that happens.
You can reach us about anything in this policy at hello@productus.ai, or by post at 10 Rue de Provence, 31400 Toulouse, France. There is no data protection officer, because the law does not require one for these activities; Elio handles every request personally.
Who this policy covers
This policy covers three groups of people.
- Visitors to productus.ai.
- Account holders: people who sign up to Productus, and the teammates they invite.
- People whose feedback a customer brings into Productus: for example a customer's users who leave a note in the feedback widget, or whose reviews, tickets and emails a customer imports. For this group, our customer decides what is collected and why, and is the data controller. We process that data only on the customer's instructions, as their processor. If you are in this group, contact the customer first; if you write to us instead, we will pass your request to them and help them answer it.
What we collect, and why
Account data. When you sign up we collect your email address, the name your sign-in provider shares with us (Google or GitHub), the name of your workspace and the product context you choose to enter (a product name, a description, your goal, your target users, and any product document you upload for context). We use it to run your account, to send you the emails the service needs (sign-in codes, invitations, confirmations) and to support you. When a teammate invites you, we receive your email address from them. Legal basis: performing our contract with you. If you joined the waitlist before Productus opened, your email address is kept only to contact you about the launch; write to us and we delete it.
Sign-in and security. You sign in with a code sent to your email, or through Google or GitHub. Sign-in forms and the feedback widget are protected by Cloudflare Turnstile, which looks at your IP address and browser signals to check that a request comes from a person. We also keep short-lived server logs (IP address, the page or endpoint requested, time) to keep the service secure and to fix errors. Legal basis: performing our contract with you, and our legitimate interest in keeping the service secure.
The feedback and revenue data you bring in. This is the heart of the product: feedback text you paste or upload as a CSV, reviews pulled from a connected app store listing, emails you forward to a Productus address, notes left in your feedback widget, and the customer names, emails and revenue figures you enter or upload so that a theme can show the paying customers tied to it. Depending on the source it can include names, email addresses, user identifiers, the page a note was left on, and whatever people wrote. You decide what to bring in; we process it to give you themes and priorities, and to produce the anonymised aggregate statistics described under “How the AI processing works”. For this data our customer is the controller and we are the processor (see “Data we process on your behalf” in the Terms of Service). We never sell it, never use it for advertising, and never share it with other customers.
Connected sources. When you connect an app store listing, we store the credentials you give us in an encrypted vault and use them only to fetch reviews for your workspace.
Usage analytics. We use PostHog, hosted in the European Union, to understand how the site and the app are used: pages viewed (with their full address, including any parameters), buttons clicked, actions taken in the app, where on a page people click, page loading performance, browser and device type, and an approximate location derived from your IP address, which PostHog discards before storing the event. Once you sign in, events are tied to your user ID rather than your email address, and the campaign details described below are attached to that ID. We do not record sessions and do not replay screens. PostHog also records the text of what you click, which can include text shown on screen, such as your email address in the account menu or a feedback item in a list. Legal basis: our legitimate interest in understanding and improving the product.
Where you came from. If you arrive on productus.ai through a campaign link (a link carrying utm parameters or a ref parameter), we store the campaign details, the referring site and the landing page in a cookie named pd_first_touch for 90 days. If you then create a workspace, we save those details on the workspace so we can tell which channels bring real users. Nothing is stored if you arrive without such a link. Legal basis: our legitimate interest in knowing which channels bring real users.
Emails we send you. We only send emails the service needs: sign-in codes, a welcome message, invitations, plan changes, and confirmations when a workspace or an account is deleted. We do not send marketing email today. If we ever start, it will be opt-in and every message will carry an unsubscribe link.
Support. When you write to us, we keep the conversation for as long as we need it to help you and to keep a record of what was agreed.
We make no decision about you by automated means that has legal or similarly significant effects on you.
How the AI processing works
Productus reads feedback with AI models run by two providers.
- Classification and theme naming run on Anthropic's Claude models. Before text is sent, we strip email addresses, card numbers, bank account numbers, phone numbers and IP addresses from it with automated rules. Three steps send text without this stripping: splitting a pasted block of text (up to about 32,000 characters) into separate items, reading the first rows of a CSV to detect which column holds what, and the product context you entered, which is sent as written so the models understand your product. Anthropic does not use this data to train its models and deletes it within 30 days, unless it has been flagged for a breach of Anthropic's usage policy. Anthropic stores API data in the United States, and its processing may run in the United States or in other countries.
- Embeddings (the numeric representation that lets us group similar feedback) are computed by Google's Vertex AI, using the same stripped text, on servers within the European Union. Google does not use this data to train its models.
The themes, summaries and priorities you see in Productus are generated by these models from your data. They can be wrong. The “revenue at risk” figure on a theme is the summed current revenue of the paying customers we could match to it: a floor, not a total, and never a prediction. Always read it with the match rate shown next to it.
We may use aggregate, anonymised statistics across all workspaces (how many items fell into each category, how often a suggested category was corrected) to improve classification. No feedback text, no theme names, no names, no email addresses and no embeddings ever leave your workspace for that purpose.
Where your data lives
Your workspace data is stored in Frankfurt, Germany, in a Supabase database, and the application runs on Vercel servers in Frankfurt. Daily backups are kept for 7 days. Usage analytics are stored in Frankfurt by PostHog. Because Vercel and Cloudflare operate worldwide edge networks, a request you make may pass through a location closer to you before it reaches Frankfurt, and the check that you are signed in runs there.
Some processing happens outside the European Union: AI classification by Anthropic, email delivery by Resend (United States) and background job scheduling by Inngest (United States; the messages it carries contain only record identifiers, never feedback text). For every transfer outside the EU we rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, on the EU-US Data Privacy Framework.
Our subprocessors
These are the companies that handle personal data for us. We will update this list and email account holders before adding one, and account holders can object by closing their account.
| Provider | What it does for us | Where | Safeguard for transfers |
|---|---|---|---|
| Supabase Pte. Ltd. (Singapore) | Database, sign-in, encrypted credential vault | Stored in Frankfurt (EU) | Standard Contractual Clauses |
| Vercel Inc. (United States) | Hosting and running the application | Frankfurt (EU) for the application, global edge network for delivery | Standard Contractual Clauses, EU-US Data Privacy Framework |
| Anthropic (Anthropic Ireland, Limited for EU customers) | AI classification of feedback text | Stored in the United States; processing in the United States or other countries; deleted within 30 days | Standard Contractual Clauses |
| Google Cloud (Google Cloud France) | AI embeddings | Within the EU | Standard Contractual Clauses, EU-US Data Privacy Framework |
| PostHog, Inc. (United States) | Usage analytics | Frankfurt (EU) | Standard Contractual Clauses, EU-US Data Privacy Framework |
| Plus Five Five, Inc., trading as Resend (United States) | Sending our emails, and receiving the feedback emails you forward to Productus; email content is kept for 30 days | United States | Standard Contractual Clauses, EU-US Data Privacy Framework |
| Inngest Inc (United States) | Scheduling background jobs | United States | Receives record identifiers only, no content |
| Cloudflare, Inc. (United States) | Bot protection on sign-in and the feedback widget | Global | Standard Contractual Clauses, EU-US Data Privacy Framework |
If you sign in with Google or GitHub, that provider processes your sign-in under its own privacy policy, as an independent controller.
Paid plans are not on sale yet. When they open, a payment provider will be added to this list before the first charge.
Cookies and browser storage
Productus sets few cookies, and none on the feedback widget your customers see: the widget sets no cookie and loads no analytics.
| Name | Set by | Purpose | Lifetime |
|---|---|---|---|
Cookies beginning with sb- | Supabase | Keep you signed in | Up to 400 days; removed when you sign out |
pd_first_touch | Productus | Remember the campaign link you arrived through | 90 days |
ph_ followed by a project key and _posthog | PostHog | Tell one visitor's events from another's for usage analytics | 365 days |
PostHog keeps a copy of its identifier in your browser's local storage too. The app also keeps a few settings there (for example your light or dark theme choice and cards you have dismissed). They never leave your browser and are not used for tracking.
We do not show a cookie consent banner. You can delete or block cookies in your browser at any time. Blocking the sb- cookies signs you out; blocking the others has no effect on the service.
How long we keep your data
- Your account and workspace data stay for as long as your account exists. You can delete a workspace, or your whole account, from Settings. Deletion is immediate and permanent: the feedback, the themes, the customers, the revenue figures, the embeddings, the invitations and the stored credentials are erased together, with no grace period and no undo. We send one confirmation email, then hold nothing except the items below. Deleting your account removes you from a workspace that other members still use; that workspace, and the feedback you added to it, stay with them.
- Backups of the database roll over every 7 days, so a deleted workspace disappears from backups within a week.
- Records kept after deletion. We keep a minimal financial audit trail (plan events, keyed to the workspace identifier, with no personal data). Usage analytics keep your user ID without your email address; write to us and we will erase them.
- Usage analytics are kept for as long as we need them to understand how the product is used, and deleted on request. Server logs are kept by our hosting provider for a matter of days.
- At our providers. Email content is kept by Resend for 30 days. Text sent to Anthropic is deleted by Anthropic within 30 days.
- Free workspaces with no sign-in for 12 months may be deleted after we have emailed you at least 30 days in advance.
- Emails you send us are kept for as long as we need them to answer you and to keep a record of what was agreed.
Your rights
Under the General Data Protection Regulation you can ask us to access, correct, erase or export the personal data we hold about you, to restrict or object to how we use it, and to withdraw a consent you gave. Write to hello@productus.ai. We answer within one month. You can also complain to the French data protection authority, the CNIL (cnil.fr), or to the authority of the EU country where you live.
Two shortcuts need no email: you can export your feedback data as a CSV file from Settings at any time, and you can delete a workspace or your account from Settings. To erase one person's items from a workspace, write to us and we will do it within 30 days.
If your data reached Productus through one of our customers (their widget, their imports), please ask that customer: they hold your data and we act on their instructions. We will help them respond.
Security
Data is encrypted in transit and at rest. Connected-source credentials are stored in an encrypted vault and are never shown again once saved. Each workspace is isolated from every other, and every request is checked against the workspace it belongs to. Access to production data is limited to the founder, and only for support and operations. No system is perfectly secure; if we ever learn of a breach that affects you, we will tell you and the authorities as the law requires.
Children
Productus is a tool for people who build products, and is not intended for anyone under 18. We do not knowingly collect data from children.
Changes to this policy
When we change this policy in a way that matters, we will email account holders before the change takes effect and update the date at the top. The change of operator described at the top of this page will be announced the same way.
Contact
Elio Keddisseh, 10 Rue de Provence, 31400 Toulouse, France. Email: hello@productus.ai. Phone: +33 6 35 24 83 41. Publication director: Elio Keddisseh. The site is hosted by Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, United States, privacy@vercel.com; Vercel publishes no phone number.