What we keep, and what we don't.
Written from what the app actually does. Short, because there is not much of it.
Last updated 6 August 2026
What we collect
An email address, so you have an account to come back to. If you sign in with Apple or Google we receive whatever that provider sends us — usually an email and a display name. Sign in with Apple can hide your real address behind a relay, and that works fine here.
The ideas you submit for validation, and the reports produced from them. These are yours; they exist so your history is there when you return.
Your chosen market focus — a city or country label such as "Bengaluru, India". This scopes the regional half of a report.
A push notification token, if you allow notifications, so we can tell you a run has finished.
Ordinary server logs: timestamps, error traces, and which endpoint was called. These are for keeping the service working.
What we do not collect
We do not collect your location. The app can offer to fill in your market focus from the device — if you tap that button and grant permission, the coordinates are turned into a city name on your phone and then discarded. The coordinates never leave the device; only the label, such as "Mumbai, India", is stored.
We do not see your payment details. Subscriptions are billed by Apple, who is the merchant of record. We receive only the fact that a subscription exists, its plan, and when the current period ends.
We do not use advertising SDKs, and we do not track you across other apps or websites.
We do not sell or rent personal data. There is no arrangement under which we could.
Voice input
If you describe an idea by voice, the recording is sent to Google's Gemini API to be transcribed, and is deleted from our server once transcription returns. We do not keep the audio. The transcript becomes the idea text, which is stored like any other.
Who else sees your data
Supabase hosts the database and handles authentication. Google Cloud runs the backend. Google's Gemini API performs the analysis, which means the text of your idea and the public material gathered about it are sent there for processing.
Firebase Cloud Messaging delivers push notifications. RevenueCat and Apple handle subscription state.
That is the full list. Each is a processor acting on our instructions, not a party we share data with for their own purposes.
What the app reads publicly
A validation run reads material that is already public: app store listings and their reviews, marketplace and crowdfunding pages, and community discussion threads. It reads them to analyse a market, and it attributes what it quotes. It does not attempt to identify the individuals who wrote them.
How long we keep it
Your reports and ideas stay until you delete them, either one at a time or by clearing your history. Deleting your account removes your account record, your reports, your tracked topics and your notification tokens.
Server logs are kept for a short operational window and then rotated out.
Your choices
Delete individual reports, clear your whole history, or delete your account outright — all from within the app, under Settings. Account deletion is immediate and is not reversible.
Turn notifications off in the app or in iOS Settings at any time.
If you would rather we did not hold something, or you want a copy of what we hold, write to the address below and we will sort it out.
Children
Validatyr is a tool for people evaluating business ideas and is not directed at children. We do not knowingly collect data from anyone under 13.
Changes
If this policy changes in a way that affects what we collect or who sees it, the date at the top of this page changes with it, and we will say so in the app.
Contact
Questions, requests, or corrections: bhaweshverma50@gmail.com.