Privacy Policy
Clear on what we collect. Clear on why.
Last updated: August 5, 2026
What this policy covers
This policy explains what personal information GarageExit collects, how we use it, the legal basis on which we process it, when we share it, and what rights you have.
GarageExit is a founder messaging and brand strategy product. This policy covers the marketing site, email subscriptions, legacy waitlist access, account access, invitations, checkout flows, and product experience.
The data controller is Rick Ovelar, trading as GarageExit, based in Paraguay. Contact details are at the bottom of this page.
Information we collect
Contact details, such as your email address when you subscribe, request access, receive an invitation, or contact us.
Account information, such as authentication identifiers connected to your sign-in and account status.
Product content, such as project inputs, answers, notes, and generated outputs you create inside GarageExit.
Payment and transaction data, such as purchase status, product tier, and transaction identifiers from our payment provider. We do not store your full payment card details ourselves.
Technical and usage information, such as browser, device, referrer, app state, and similar request or diagnostic data needed to run and secure the service.
Browser-side storage, such as local app state used to support onboarding, project continuity, and interface behavior.
How we collect information
Directly from you when you submit forms, subscribe, create an account, request access, make a purchase, contact us, or use the product.
Automatically through the operation of the website and product, including request metadata, service logs, and browser storage needed to make the app work.
From service providers involved in authentication, payments, email delivery, hosting, and AI-powered features.
Why we use information and the legal basis
To operate the website and product, create and manage accounts, process invitations, and deliver the service you ask for. Legal basis: performance of a contract with you.
To send subscription updates, access emails, and support responses. Legal basis: performance of a contract, consent, or our legitimate interest in communicating with people who have asked to hear from us. You may opt out of marketing communications at any time.
To process purchases, validate access, and handle billing. Legal basis: performance of a contract.
To prevent abuse, investigate issues, and keep the service secure. Legal basis: our legitimate interests in protecting the service and users.
To generate product outputs and AI-assisted suggestions when you use features that rely on our AI and research providers. Legal basis: performance of a contract.
To improve GarageExit, understand technical issues, and make product decisions. Legal basis: our legitimate interests in improving the service.
To comply with legal obligations such as accounting, tax, and regulatory requirements. Legal basis: compliance with a legal obligation.
Where we rely on legitimate interests, we have assessed that those interests are not overridden by your rights and interests. You have the right to object to processing based on legitimate interests — see the rights section below.
How we share information
We share information only with service providers and partners needed to run GarageExit, such as hosting, authentication, database, email, payment, and AI infrastructure providers.
Based on the current product stack, those providers may include Vercel, Supabase, Resend, Polar, OpenRouter, and Jina.
We may also disclose information when required by law, to protect rights or security, or in connection with a business transfer.
We do not sell personal information.
International data transfers
GarageExit is operated from Paraguay. Our service providers, including Vercel, Supabase, and OpenRouter, may process personal information in the United States or other countries outside the European Economic Area (EEA).
Where we or our providers transfer personal information from the EEA to countries without an EU adequacy decision, we rely on appropriate safeguards such as Standard Contractual Clauses approved by the European Commission, or equivalent mechanisms under applicable law.
You may request information about the specific safeguards in place for your data by contacting us using the details below.
Automated decision-making and AI-generated outputs
GarageExit uses AI-assisted systems to generate brand strategy outputs such as positioning, messaging, and launch copy based on information you provide.
These systems process your inputs to produce suggestions, but they do not make legally significant or similarly consequential automated decisions about you.
You are responsible for reviewing all outputs before relying on them in public, legal, financial, regulatory, or customer-facing contexts. We do not guarantee that AI-generated outputs are accurate, complete, or suitable for any particular use.
AI providers and ZDR routing
GarageExit uses OpenRouter and other AI providers to process relevant project inputs and generate AI-assisted outputs for the user-facing features you use.
For supported user-facing OpenRouter workflows, our account is configured to route eligible requests to endpoints marked Zero Data Retention (ZDR) where available. Some models may not have a ZDR endpoint, and provider availability and policies can change.
OpenRouter may retain limited technical metadata about requests, such as the selected model, token counts, latency, and request status. ZDR applies to provider inference routing; other providers, plugins, and tools may have separate data-handling policies.
Cookies and similar technologies
GarageExit uses essential browser-side storage and related technologies to keep core product flows working, such as sign-in state, onboarding continuity, recent project state, and cookie-preference memory.
For the current breakdown of cookies, local storage, optional analytics, and how to manage your settings, see the Cookie Policy.
We do not currently describe the service as using advertising cookies, cross-site behavioral tracking, or session replay tools. If that changes, we will update this policy and any required consent flow before those tools are turned on.
Retention
We keep personal information only for as long as needed for the purposes described in this policy, plus any period needed for legal, security, tax, accounting, or dispute-related obligations.
As a working guide: subscriber, legacy waitlist, and contact records are kept until no longer needed for product updates, support, or follow-up, and typically removed within 24 months of becoming inactive. Active account data is kept while an account remains in use. Transaction records are kept for up to 7 years for accounting and legal compliance. Technical logs are kept for shorter operational periods, typically up to 90 days.
Your rights
Depending on where you are located, you may have some or all of the following rights regarding personal information we control about you:
Right of access: you can ask for a copy of the personal information we hold about you.
Right to rectification: you can ask us to correct inaccurate or incomplete personal information.
Right to erasure: you can ask us to delete personal information about you, subject to legal or operational limits.
Right to restriction: you can ask us to pause certain processing of your data while a complaint is resolved.
Right to data portability: you can ask for personal information you provided to us in a structured, machine-readable format where processing is based on your consent or a contract.
Right to object: you can object to processing based on our legitimate interests or for direct marketing purposes. We will stop unless we have compelling legitimate grounds that override your interests.
Right to withdraw consent: where we rely on consent as a legal basis, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.
Right to lodge a complaint: you have the right to lodge a complaint with your local data protection authority (supervisory authority) if you believe we have not handled your data in accordance with applicable law. In the EU, you can find your local authority at edpb.europa.eu.
To exercise any of these rights, contact us using the details below. We will respond within the timeframe required by applicable law.
Data security
We use reasonable administrative, technical, and organizational measures intended to protect personal information. No internet service or storage system is perfectly secure, so we cannot guarantee absolute security.
If you use GarageExit, do not submit highly sensitive personal information unless we clearly ask for it and explain how it will be handled.
Children
GarageExit is built for founders and business users. It is not intended for children under 13, and we do not knowingly collect personal information from children under 13.
Changes to this policy
We may update this policy as the product, providers, or legal requirements change. When we make a material update, we will revise the date on this page.
Data controller and contact
The data controller for GarageExit is Rick Ovelar, trading as GarageExit, based in Asunción, Paraguay.
For privacy questions, data subject rights requests, or to ask about safeguards for international transfers, email [email protected] with the subject line Privacy Request.
You can also use the contact page.