Privacy
Privacy Policy
This policy explains the limited personal data Datyo uses to provide accounts, workspaces, billing, security, the affiliate program and the optional newsletter. Datyo is operated independently by Arthur M.
Last updated: September 2, 2026
1. Data Datyo processes
Account data includes your name, email address, profile image, account dates and sign-in provider. Password accounts store only a one-way password hash, never the readable password.
Product data includes Watchlists, saved SaaS, ads and pages, folders, notes, team memberships, preferences, API-key metadata and usage counters. Full developer API keys are shown once; Datyo stores a cryptographic hash plus display fragments.
Billing data includes Stripe customer, subscription, price, status and invoice-event identifiers. Card and bank details are handled by Stripe and are not stored by Datyo. Affiliate data can include referral links, a pseudonymous visitor hash, coupon attribution, commission amounts and payout status.
Anonymous product analytics includes page views, referrers and coarse events such as signup, checkout start and password-reset completion. Password-reset tokens are random, expire after 30 minutes, work once and are stored only as a one-way hash.
If you subscribe to the newsletter, Brevo processes your email address, signup source, the version and time of your consent request, confirmation and unsubscribe status, and email delivery and interaction data. Newsletter signup is optional and separate from a Datyo account.
2. Why the data is used
Datyo uses this data to authenticate you, provide and secure the product, enforce quotas, synchronize billing, support team collaboration, attribute referrals, prevent abuse and meet legal obligations. Datyo does not sell your personal data.
With your consent, Datyo sends a weekly newsletter with SaaS research and product updates. You confirm your address through an email link before it joins the newsletter list.
3. Service providers
Datyo relies on Vercel for application hosting and cookie-free Web Analytics, managed PostgreSQL infrastructure for account data, Stripe for payments, Brevo for account emails and the optional newsletter, and Google when you choose Google sign-in. Tolt is contacted only when its optional affiliate integration is enabled. Discord processes data when you choose to join the Datyo community. Each provider processes data under its own terms and security practices.
4. Retention and security
Account and workspace data is retained while your account is active and as needed for security, billing and legal records. Datyo uses access controls, hashed credentials and encrypted network connections, but no online service can guarantee absolute security.
A deletion request starts a 30-day recovery period. You can cancel it during that period. After the recovery date, eligible accounts are processed with workspace, subscription and affiliate-ledger safeguards. Records that must be retained for billing, fraud prevention or legal compliance are separated from the deleted account and kept only as required.
5. Your controls
Settings lets you correct your name, change a Datyo password, export a JSON copy of account data, or request and cancel account deletion. You can also manage billing through Stripe and remove saved workspace content directly in the product.
Every newsletter includes an unsubscribe link. Unsubscribing stops newsletter campaigns; it does not delete your Datyo account or stop necessary account emails. Brevo retains suppression information to honor your unsubscribe choice. For requests about newsletter data, reply to a newsletter.
Depending on where you live, you may also have rights to access, correct, restrict, object to or erase personal data. The in-product export and deletion controls are the fastest way to exercise the main account rights.
6. Policy changes
This page will be updated when Datyo’s data practices materially change. The date above identifies the current version.