Opening soon. The platform is live but new accounts cannot be confirmed yet, because email delivery is still being set up, and card payments are not available yet. Everything else works. Ask us anything.

Privacy policy

Effective 3 September 2026. Draft pending legal review. Written to be read, not skimmed: it lists exactly what we keep and why.

Who is responsible

The operator of earlyusers.io is the data controller. Contact for anything in this policy: hello@earlyusers.io.

What we collect and why

  • Account: email, password hash, role, sign-in times and IP addresses of sign-in attempts. To run your account and protect it from abuse.
  • Profile: a display name and country for early users; company name and website for startups; devices you can test on. To show startups who joined, and to know whether Stripe can pay you.
  • Campaigns and reports: what startups publish, what early users write, checklist answers, ratings, rejection reasons, appeals, and evidence files. This is the service.
  • Money: an append-only ledger of every reward, fee, refund and payout; Stripe identifiers (customer, payment, transfer, connected account). We never see card numbers or bank details: Stripe holds them.
  • Notifications: a log of emails we sent you, their delivery status, and bounces or complaints reported by our email provider.
  • Audit trail: who did what and when on the platform, including administrators, with IP addresses. To resolve disputes and detect abuse.
  • Analytics: cookieless page statistics on public pages through Tusua; IP addresses are hashed with a rotating salt and never stored with page views.

Legal bases

Performing our contract with you (accounts, campaigns, reports, payments); our legitimate interest in preventing fraud and keeping records of disputes; legal obligations around payments and accounting; and your consent for optional reminder emails, which you can withdraw in settings.

Who else processes it

  • Stripe (payments, refunds, payouts, identity checks for payout accounts).
  • Resend (transactional email).
  • Cloudflare (DNS, and R2 object storage for evidence files and encrypted backups).
  • Tusua (cookieless analytics, the contact form inbox, and monitoring of our backups).
  • Google, only if you choose to sign in with Google.

Startups see the reports and evidence of the early users in their campaigns and the display name, country and track record of participants. Early users see the startup's company name and the campaign content. We do not sell data.

How long

  • Evidence files: twelve months after the campaign ends, then deleted.
  • Reports, campaigns, ledger and audit trail: kept while the account exists and for as long as accounting and dispute rules require; on account deletion your personal details are removed and the records anonymised.
  • Sign-in attempts: 24 hours. Sessions: 30 days of inactivity.
  • Email logs: 12 months.

Your rights

You can see and change your profile in settings, export what you need by asking us, turn reminder emails off, and delete your account once nothing is pending (settings → delete account). You can also ask us to correct or erase data, restrict or object to processing, or take it elsewhere, and you can complain to your data protection authority. Write to hello@earlyusers.io; we answer within a month.

Security

Passwords are hashed with argon2id, secrets are encrypted at rest, evidence is private and served through short-lived signed links, backups are encrypted before leaving the server, and administrators can be required to use two-step verification. If we ever suffer a breach that affects you, we will tell you.

Cookies

One session cookie when you sign in, plus a short-lived cookie during Google sign-in. Nothing for tracking. Details in the cookie policy.

Changes

We will post changes here and, for material ones, email account holders.