Privacy Policy
Effective 2026-07-12
FrictionLens is an independent project operated by Chetan Jonnalagadda. This page describes, plainly, what data the service handles and why.
What we collect
- Account data — your email address, via email/password or Google sign-in (handled by Supabase Auth). We never see your Google password.
- Your Gemini API key, if you add one — encrypted at rest with AES-256-GCM, decrypted only server-side to run your analyses, never logged, and never sent to the browser.
- Analysis data — the app reviews you upload or that we pull from public app-store listings, and the reports generated from them.
- Usage analytics — aggregate product analytics via PostHog (page views, feature usage). No analytics data is sold or shared for advertising.
How it's used
- Review text is sent to Google's Gemini API to generate your analysis — using your own key when you've added one.
- If you enable monitoring, we re-pull public reviews for your tracked apps on your chosen schedule and email you a digest. You can mute any app with one click.
- Reports are private to your account unless you explicitly make one public, which creates a shareable URL.
Third-party services
FrictionLens runs on: Supabase (database and authentication), Vercel (hosting), Google Gemini (AI analysis), Resend (email delivery), Upstash (caching), and PostHog (analytics). Each processes only the data needed for its role.
Cookies
We use authentication session cookies (required for sign-in) and PostHog's analytics cookie. No third-party advertising cookies.
Data retention & deletion
Your data is retained while your account exists. To delete your account and all associated data (analyses, tracked apps, encrypted keys), open an issue or contact us via GitHub. Deletion requests are honored within 30 days. You can remove your stored API key yourself at any time from Settings.
Changes
If this policy changes materially, the effective date above will be updated. Continued use after a change constitutes acceptance.
See also the Terms of Service.