MRRChat Privacy Policy
Effective date: September 14, 2026
Controller: BrayLabs, LLC
Website: https://www.mrrchat.com
Privacy contact: privacy@mrrchat.com
This Privacy Policy explains how BrayLabs, LLC ("MRRChat," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information when you visit MRRChat, create an account, connect a revenue provider, publish a profile, appear on a leaderboard, participate in the community, or contact us.
1. Scope and roles
This policy covers the MRRChat Service. It does not cover a revenue provider, linked website, or other third party operating under its own privacy policy.
MRRChat controls the member account, verification, publication, community, moderation, and technical data described here. Revenue providers independently control their services. When you connect a provider, you direct MRRChat to retrieve and process information needed to produce and maintain your verification reading.
2. Public and private surfaces
Members can participate in the Pre-revenue and Public Rooms without connecting a revenue provider. Revenue rooms require current verification and the applicable room access. Pre-revenue is a self-declared stage, not a verified zero-revenue reading. Connecting an account does not automatically create a public profile or leaderboard entry. Verified members separately choose whether to publish a public profile and whether to appear on a ranked public leaderboard.
Your current verified monthly figure appears with your community activity when you have live verification. Members without current verification display their community stage instead of a verified revenue figure. If you enable a public profile or leaderboard placement, your exact verified figure also appears there. Identity visibility is a separate setting. Anonymous leaderboard placement is off by default and requires express opt-in if offered.
Public Room posts and limited comment previews are visible to visitors without an account, independently of your public-profile setting. Pre-revenue room content is available to completed members, and revenue-room content is available only to members with the applicable access. Public pages may be indexed, copied, linked, quoted, archived, or scraped. When you withdraw a publication choice, we remove the information from MRRChat-controlled public pages, but we cannot remove independent copies, screenshots, archives, or search-engine caches. Authorized members can read and copy content available to them.
3. Information we collect
Information you provide
- Account data: email address, authentication identifiers, handle, display name, selected business stage, onboarding completion, verification history status, and Terms acceptance records.
- Venture data: venture name, business model, categories, platforms, domain, biography, social links, and other information you enter. These fields are self-declared unless expressly labeled as verified.
- Connection data: selected provider and account or project, account label, requested or granted permissions, encrypted credential or token, credential metadata, connection status, and provider errors.
- Ownership attestations: the statement and Terms versions, time, IP address, user agent, and connection involved.
- Publication choices: public-profile, leaderboard, and identity choices and the time and policy version associated with each choice.
- Member Content: posts, comments, likes, reports, appeals, profile text, and messages to us.
- Requests and disputes: privacy requests, copyright notices, ownership disputes, safety reports, account appeals, and correspondence.
Information from revenue providers
MRRChat supports Stripe, RevenueCat, Superwall, Paddle, and Polar at launch. The live connection screen identifies the permissions and method required before you submit a credential.
| Provider | Information accessed for verification | Reading method and limitation |
|---|---|---|
| Stripe | Account identity and branding; charges and refunds in the measurement window; product and file access used for validation or branding. Stripe charge and refund responses can technically include customer or payment-related fields even though MRRChat uses amount, currency, status, and date to calculate the reading. | Thirty-day sales calculated from successful captured charges minus successful refunds. It can differ from Stripe's dashboard and is not MRR. |
| RevenueCat | Projects, apps, and MRR chart metrics. | MRR reported through RevenueCat charts for the selected project. |
| Superwall | Projects, applications, chart definitions, and MRR chart data. | Provider-reported MRR, labeled as a floor because it may cover only Superwall-served paywalls. |
| Paddle | MRR metrics and active-product information used to validate access and retrieve a product image where available. | MRR reported by Paddle metrics. |
| Polar | Organizations, organization details, and MRR metrics. | MRR reported by Polar metrics for the selected organization. |
Provider API responses are processed in memory to validate a connection and produce the reading. We do not intentionally persist unrestricted raw responses. We retain normalized reading information such as amount, metric type, currency, converted amount, exchange-rate date, source, calculation method, completeness indicator, and capture time.
Information collected automatically
We and our infrastructure providers may collect IP address, request time, referring page, browser and device type, language, operating system, authentication and session information, security events, diagnostics, rate-limit events, and interactions needed to deliver requested features.
MRRChat uses browser storage for authentication, security, preferences, and intentionally saved draft or demo state. When deployed on Vercel, Vercel Speed Insights measures page route, URL, approximate country, browser, device and operating-system category, network speed, and Web Vitals. Vercel describes these measurements as anonymous and not tied to an identifiable visitor or reconstructed browsing session.
Another person may mention you in Member Content, report content involving you, submit a copyright notice, or contact us about an ownership or safety concern. We may also receive lawful requests from authorities and security or fraud signals from providers.
4. How and why we use information
We use personal information to:
- create and authenticate accounts;
- validate revenue connections, calculate readings, and maintain tier access;
- display information according to your publication and identity choices;
- provide community features;
- investigate reports, enforce rules, and decide appeals;
- secure the Service, protect credentials, and prevent fraud;
- communicate about accounts, connections, requests, and material Service changes;
- comply with law, protect people, and establish or defend legal rights; and
- measure and improve reliability, performance, and accessibility.
For people covered by EEA or UK data-protection law, the typical legal bases are performance of a contract or pre-contract steps for accounts, verification, tiers, and community features; consent for optional public profiles and leaderboard placement; legitimate interests in security, accurate verification, moderation, reliability, and legal defense; and legal obligations where applicable. We assess legitimate interests against user rights and do not use them to override an optional publication choice.
You can refuse optional publication without losing private forum access and can withdraw that consent as easily as you granted it. Withdrawal does not make earlier lawful processing unlawful.
We do not sell personal information, share it for cross-context behavioral advertising, use advertising cookies, fingerprint visitors, or use Member Content to train a third party's general-purpose AI model.
5. Credentials and connection security
Provider credentials are write-only: after submission, ordinary application clients cannot retrieve them. We use encryption, access controls, separation of duties, server-side redaction, credential fingerprints, and access logging designed to protect credentials. Do not send a provider secret by email or post it in the community.
Read-only means a connection cannot move money or modify a provider account; it does not mean every provider response is anonymous. In particular, Stripe charge and refund endpoints may return customer-associated information. MRRChat processes those responses transiently to extract the limited transaction components used for the reading and does not intentionally retain customer names, emails, telephone numbers, postal addresses, full payment-card information, or unrestricted transaction objects.
You may disconnect in MRRChat and should also revoke the credential or authorization in the provider dashboard. Local credential deletion occurs when the disconnect completes. Where supported, MRRChat attempts provider-side revocation.
6. Cookies, browser storage, and performance measurement
| Technology | Purpose | Duration |
|---|---|---|
| Authentication cookies | Maintain and refresh your signed-in Supabase/MRRChat session and complete authentication. | Session-based or until the authentication session expires, you sign out, or you clear browser data. |
| Security and request state | Protect sign-in redirects, requests, rate limits, and delivery of requested pages. | Usually the session or a short operational period. |
| Local storage | Preserve a theme, draft, explicit preference, or local demonstration state. | Until cleared by the feature or through browser controls. |
| Vercel Speed Insights | Collect anonymous route and Web Vitals measurements used to understand performance. | According to the applicable Vercel plan and retention settings. |
Browsers let you inspect, delete, or block cookies and local storage. Blocking authentication or security storage can prevent sign-in or break requested features. Clearing local storage can remove an unsent draft or reset preferences.
MRRChat does not use advertising cookies, cross-site behavioral tracking, retargeting pixels, or session replay at launch. Speed Insights reports performance data without using it to identify an individual visitor. Before adding advertising, cross-site tracking, or another technology requiring consent, we will update this policy and provide required choices before it operates.
7. How we disclose information
We disclose information only as described here:
- At your direction: when you publish selected information, submit Member Content, or direct a connection.
- Service providers: Vercel provides web hosting and performance measurement; Supabase provides database, authentication, and application infrastructure; Amazon Web Services provides cloud key-management infrastructure when configured for production; and transactional email or support vendors may deliver communications. These providers process information for us under their applicable agreements.
- Revenue providers: we send credentials, authorization requests, and identifiers to the provider you choose. Each provider handles information under its policy.
- Legal and safety reasons: when reasonably necessary to comply with valid law or process, respond to an emergency, protect a person, investigate fraud or security, enforce these Terms, or protect legal rights.
- Corporate events: in connection with financing, reorganization, merger, acquisition, bankruptcy, or transfer of relevant assets, subject to confidentiality and applicable law.
- Aggregated information: statistics designed not to identify a member. We will not describe a small cohort as anonymous when it can reasonably identify someone.
Copyright notices and counter-notices may be forwarded to the affected parties or shared with advisers, authorities, or transparency services. We do not disclose private Member Content to marketing systems or use it as public promotional copy without separate permission.
8. Retention
| Category | General retention period |
|---|---|
| Provider credential or token | While connected; deleted on disconnection or account closure. |
| Raw provider response | Processed transiently and not intentionally persisted. |
| Public listing | Removed promptly after withdrawal or account closure. |
| Normalized revenue and tier history | While needed for verification; up to 90 days after disconnection and ordinarily no more than 30 days after account deletion. |
| Account and venture profile | While active; deleted or de-identified within 30 days after a valid deletion request. |
| Posts and comments after account closure | May remain under a neutral deleted-member identity to preserve discussion context, subject to content controls and applicable erasure rights. |
| Ordinary technical and security logs | Up to 12 months unless an incident requires longer investigation. |
| Moderation and abuse evidence | Up to three years, de-identified where practical, or longer for an active legal matter. |
| Terms, consent, and ownership-attestation records | Up to six years after account closure. |
| Backups | Removed through the applicable backup cycle, targeted at no more than 35 days. |
We may keep limited information longer for a legal obligation, litigation, legal hold, fraud or safety investigation, or defense of rights. We may retain information that no longer identifies a person.
9. Account deletion and privacy rights
You may request account deletion at privacy@mrrchat.com. A self-service deletion control may also be available in account settings. Deletion removes MRRChat-controlled public listings, destroys held provider credentials, and unlinks your profile from retained contributions. Posts and comments may remain under a neutral deleted-member identity to preserve discussion context. You may ask us to review retained text that identifies you.
Depending on applicable law, you may have rights to access, correct, delete, or receive a portable copy of personal information; object to or restrict certain processing; withdraw consent; appeal a denied request; and complain to a data-protection authority. We offer reasonable access, correction, deletion, portability, consent-withdrawal, and appeal processes to all users where technically applicable.
Submit a request to privacy@mrrchat.com. We may verify control of the account or email and request only information reasonably needed to prevent unauthorized disclosure. An authorized agent must provide appropriate proof of authority. We respond within the time required by applicable law and explain any denial and available appeal route.
Deletion rights are not absolute. We may retain limited information where law permits or requires it, including to preserve freedom of expression, comply with law, establish or defend claims, maintain moderation integrity, or protect others.
10. International processing
MRRChat is operated from the United States. Our providers may process information in the United States and other countries whose laws differ from those where you live. Where applicable law requires a transfer mechanism, we rely on an applicable adequacy decision, contractual safeguards supplied by our vendors, or another lawful mechanism.
The Service may not be available in every jurisdiction. Offering an account in the EEA or UK requires operational measures beyond this policy, including any legally required local representative. MRRChat will limit availability where those measures are not in place.
11. Security and anonymity
We use administrative, technical, and organizational safeguards designed for the sensitivity of the information, including encryption in transit, credential encryption, least-privilege access, private database roles, server-side redaction, logging, rate limits, and separation of verification processing. No system is perfectly secure. Contact privacy@mrrchat.com if you believe an account, credential, or information is at risk.
Anonymous mode reduces information shown to members but cannot guarantee that identity will not be inferred. Revenue, tier, writing, context, timing, small cohorts, and outside information can narrow identity. Authorized personnel may access account mappings where necessary for security, moderation, support, or law. We review legal demands and may challenge invalid or overbroad requests, but cannot promise to defeat valid process or provide notice where prohibited.
12. Children
The Service is for people age 18 and older and is not directed to children. We do not knowingly collect personal information from a child. If you believe a child provided information, contact privacy@mrrchat.com so we can investigate and delete it as appropriate.
13. Changes
We will update this policy when practices change and identify the new effective date. If a change is material, we will provide reasonable advance notice through the Service or account email. We will request new consent before using information for a materially different purpose where required.
14. Contact
BrayLabs, LLC
5441 S Macadam Ave, Ste R
Portland, OR 97239, USA
Privacy and security: privacy@mrrchat.com
General support: support@mrrchat.com
Legal matters: legal@mrrchat.com