Legal
Privacy Policy
Last updated: 2 July 2026
1. Who we are
This platform is operated by Rich Girl Systems Limited, a private limited company registered in England and Wales under company number 17227864, with its registered office at 40 Selhurst Place, London, SE25 5PY. We provide an online founder operating system for women building profitable businesses.
Rich Girl Systems Limited is the data controller responsible for your personal data. This privacy policy explains how we collect, use, and protect that data when you use our platform at app.richgirlsystems.com.
For any privacy-related questions, or to exercise your data rights, contact us at info@richgirlsystems.com or by post at Rich Girl Systems Limited, 40 Selhurst Place, London, SE25 5PY.
2. What data we collect
Account data. Your name, email address, country, timezone, and profile preferences (accountability style, productivity type, business experience level).
Business profile data. Information you provide about your business, including business name, website URL, social media handles (Instagram, TikTok, Pinterest, LinkedIn), business category and stage, country, key business dates (start date, registration date, first sale date, intended launch date), business registration number (if provided), revenue goal, target audience description, and products or services.
Usage and progress data. How you interact with the platform, including programmes started and completed, tasks marked done, task reflections and notes you write, milestones unlocked, XP earned, streak counts, and session activity.
Notes. Personal notes and reflections you write within the platform.
AI interaction data. Prompts and responses in your conversations with our Founder Intelligence AI assistant. To provide context-aware responses, your business profile, recent conversation history, and anonymised mood signals inferred from your inputs (for example, whether you have expressed time pressure or uncertainty) are included in requests sent to our AI provider. Conversation history is stored in your browser and is not saved to our servers.
Integration data. When you connect third-party services, we store the access credentials (OAuth tokens) and the data needed to power those integrations. See Section 6 for details of what each integration accesses.
Payment data. If you subscribe to a membership on the web, payment processing is handled by our payment provider (Stripe). If you buy a membership or a programme inside our iOS or Android app, the purchase is processed by Apple's App Store or Google Play's in-app purchase system and managed for us by RevenueCat, our subscription-management provider. In every case we do not receive or store your full card details.
Support enquiries. Name, email address, topic, and message content when you submit the contact form.
Activity log. A record of significant account events (such as logins and integration connections) for security and fraud prevention purposes. This log is retained for up to 180 days.
Push notification data. If you choose to turn on push notifications, we store the technical subscription details your browser or device provides (a push endpoint URL, its encryption keys, and your browser user-agent string) so we can send reminders and updates to that device. We use this only to deliver the notifications you have opted into. You can turn push notifications off at any time in the app or in your browser or device settings, which removes the stored subscription.
Data stored on your device. Some information is kept in your browser's local storage on your own device rather than on our servers. This includes your cookie choice, your AI assistant conversation history, and a local working copy of app preferences and progress (such as earned badges and your programme schedule and tasks) so the app loads quickly and works offline. Your authoritative account data is also held securely in your account. Clearing your browser data removes the on-device copy. See our Cookie Policy for the full list.
3. How we use your data
- ◆To operate and deliver the platform. Your account, programmes, tasks, and tools depend on us storing your data.
- ◆To personalise your experience. Your progress, momentum, business profile, and programme history shape what the platform shows you and how the AI assistant responds.
- ◆To power AI features. Your business context is sent to our AI provider (Anthropic) to generate Founder Intelligence responses. Anthropic processes this data as a processor on our behalf.
- ◆To display integration data. Data from connected services is fetched and displayed within your dashboard. We do not use integration data for any purpose other than showing it to you.
- ◆To communicate with you. Service updates, account notifications, and, with your consent, product updates and push notifications (such as reminders) to devices where you have opted in.
- ◆To improve the platform. Aggregated, anonymised usage patterns help us understand what works and what to build next.
- ◆For security and fraud prevention. Activity logs are used to detect and prevent unauthorised access.
4. Legal basis for processing
- ◆Contract. We process your account and usage data to fulfil our agreement with you.
- ◆Legitimate interest. We analyse platform usage to improve the product and maintain security logs to protect all users.
- ◆Consent. For any marketing communications and for optional analytics cookies. You can withdraw consent at any time.
5. Third-party processors
We use the following providers who process data on our behalf:
- ◆Supabase. Our database infrastructure and authentication provider. Stores all account and progress data.
- ◆Anthropic. The AI infrastructure behind our Founder Intelligence feature. Receives your business profile and conversation context to generate AI responses.
- ◆Vercel. Our hosting and content-delivery provider. Operates the servers that run the platform and processes technical request data (such as IP address) needed to serve it securely.
- ◆PostHog. Product analytics, active only if you accept analytics cookies. Receives anonymous-by-default usage events, linked to your account once you are signed in, so we can understand and improve how the platform is used. Processed in the United States.
- ◆Resend. Our email delivery provider. Receives your email address and message content to send transactional and account emails (such as sign-in, notifications, and updates).
- ◆Stripe. Payment processing for membership subscriptions purchased on the web.
- ◆Apple. When you buy a membership or programme inside our iOS app, Apple processes the payment through the App Store's in-app purchase system and provides the purchase and subscription status we need to unlock your access. Apple's handling of your payment is governed by Apple's own privacy policy.
- ◆Google Play. When you buy a membership or programme inside our Android app, Google processes the payment through Google Play's billing system and provides the purchase and subscription status we need to unlock your access. Google's handling of your payment is governed by Google's own privacy policy.
- ◆RevenueCat. Our in-app purchase and subscription-management provider for the iOS and Android apps. It receives your store purchase and subscription events, together with an app-specific user identifier, so we can unlock the correct membership or programme access and keep it in sync across your devices. Processed in the United States.
- ◆Google. When you connect Google Calendar or Google Analytics. Data is accessed only for the purposes described in Section 6.
- ◆Meta (Instagram). When you connect your Instagram business or creator account. Accesses your account profile and read-only account and post insights (reach, views, profile views, saves).
- ◆TikTok. When you connect your TikTok account. Accesses basic profile information and video statistics.
- ◆YouTube. When you connect your YouTube channel. Accesses channel and video analytics.
- ◆Microsoft. When you connect Outlook Calendar or Teams. Accesses calendar events and meetings.
- ◆Zoom. When you connect Zoom. Accesses scheduled meetings.
- ◆Calendly. When you connect Calendly. Accesses scheduled events.
- ◆Shopify. When you connect your Shopify store. Accesses store metrics, order counts, and product counts to display in your dashboard.
- ◆Pinterest. When you connect your Pinterest account. Accesses basic profile information and read-only account and pin analytics for display in your dashboard.
- ◆Klaviyo. When you connect your Klaviyo account. Accesses read-only email-marketing metrics (such as list size and campaign performance) for display in your dashboard.
- ◆Mailchimp. When you connect your Mailchimp account. Accesses read-only email-marketing metrics (such as audience size and campaign performance) for display in your dashboard.
- ◆WooCommerce. When you connect your WooCommerce store, we use the store URL and API credentials you provide to read store metrics, order counts, and product data for display in your dashboard. The connection is to your own store; we do not share your data with the WooCommerce project.
- ◆Judge.me. When you connect your Judge.me account. Accesses read-only product-review metrics (such as review counts and ratings) for display in your dashboard.
- ◆Google Business Profile. When you connect your Google Business Profile. Accesses read-only listing and review data for display in your dashboard.
- ◆Apify. A web-scraping infrastructure provider used to power our Autopilot “Rival Mission” / Dawn Brief feature. It collects publicly available competitor and trend signals from public web sources on our behalf. It receives only the public search terms derived from your business niche, never your account credentials or personal data. Processed in the United States.
We require all processors to handle your data securely and in accordance with applicable law.
6. Third-party integrations: data accessed
When you connect an integration, we access only what is needed to power that feature. Here is what each integration accesses:
- ◆Google Calendar. Upcoming calendar events (title, time, location) for the next 14 days. Used to display your schedule in the dashboard.
- ◆Google Analytics. Sessions, users, page views, and top pages from your own connected GA4 property. Used to display your website analytics in the dashboard.
- ◆Instagram. Your Instagram account ID, username, account type, follower count, and media count; 30-day account insights (reach, views, and profile views); and per-post insights (reach, saved, and views). Used to display your social performance in the dashboard. We request read-only access via the instagram_business_basic and instagram_business_manage_insights permissions, and never publish, modify, or post on your behalf.
- ◆Shopify. Store name, 30-day order count, revenue metrics, and product count. We also receive order data via webhooks when customers purchase your products. This may include your customers' email addresses and order details.
- ◆WooCommerce. Store metrics, order counts, and product data read from your own store using the URL and API credentials you supply. Used to display your store performance in the dashboard.
- ◆TikTok, YouTube, Microsoft, Zoom, Calendly, Pinterest, Klaviyo, Mailchimp, Judge.me, Google Business Profile. Basic profile information and relevant performance, scheduling, email-marketing, review, or listing data for display in your dashboard.
Autopilot: Rival Mission & Dawn Brief
When you switch on Autopilot, our Growth Mission reads publicly available trend and competitor signals from public web sources (via our sub-processor Apify) to build your daily brief. This uses only public search terms derived from your business niche. It does not access any competitor’s private data, and it never sends your account credentials or personal data to the scraping provider. You can switch Autopilot off at any time in Settings.
Google API Limited Use
Use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained via Google APIs is used solely to provide the features described above and will not be used for any other purpose, transferred to third parties, or used to serve advertising.
YouTube API Services
This application uses YouTube API Services. By connecting your YouTube channel, you also agree to be bound by the Google Privacy Policy at policies.google.com/privacy.
Meta Platform Data
Use of information received from the Instagram Platform and Meta APIs adheres to the Meta Platform Terms and Developer Policies. Instagram data obtained through these APIs is used solely to display your own account and content insights to you within your dashboard. It is never sold, transferred to third parties, or used to serve advertising. You can revoke access at any time by disconnecting Instagram in Settings, which deletes the stored access tokens, or by submitting a data deletion request.
OAuth access credentials (tokens) for each integration are stored securely in our database. We access your connected accounts only to fetch data for display in your dashboard and never for any other purpose. You can disconnect any integration at any time from Settings, which removes all stored credentials and ceases all data access for that service.
7. Data retention
We retain your data for as long as your account is active. If you close your account, we delete or anonymise your personal data within 90 days, except where we are required to retain it for legal or accounting purposes.
Security and activity logs are retained for up to 180 days and then automatically deleted, even if your account remains active.
AI conversation history is stored in your browser only and is cleared when you clear your browser data or use the clear history option in the AI assistant.
8. Your rights
Under UK GDPR, you have the right to:
- ◆Access your personal data.
- ◆Correct inaccurate data.
- ◆Delete your data (right to be forgotten).
- ◆Restrict or object to processing.
- ◆Data portability (download a copy of your data).
- ◆Withdraw consent where consent is the legal basis.
To exercise any of these rights, visit your Data & Permissions page when signed in, or email info@richgirlsystems.com. We will respond within 30 days.
You can download a copy of your data directly from your Data Export page when signed in.
If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
9. Your United States privacy rights
This section applies if you are a resident of the United States. Depending on the state you live in, US state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) may give you the following rights over the personal information we hold about you:
- ◆Right to know and access. Request the categories and specific pieces of personal information we have collected about you, and how we use and disclose it.
- ◆Right to delete. Request that we delete the personal information we hold about you, subject to legal exceptions.
- ◆Right to correct. Request that we correct inaccurate personal information.
- ◆Right to opt out of the sale or sharing of your personal information. You have the right to direct us not to sell or share your personal information.
- ◆Right to non-discrimination. We will not discriminate against you for exercising any of these rights.
We do not sell or share your personal information
Rich Girl Systems does not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA. We have not done so in the preceding twelve months. Because we do not sell or share, there is no “Do Not Sell or Share My Personal Information” action for you to take, but you can still exercise every other right described above.
To exercise any of these rights, visit your Data & Permissions page when signed in, download your data from the Data Export page, or email info@richgirlsystems.com. We will verify your request against your account and respond within the timeframe required by law. You may use an authorised agent to submit a request on your behalf. If we decline your request you may appeal by replying to our response, and you may also complain to your state Attorney General or, in California, the California Privacy Protection Agency.
10. International transfers
Some of our processors (including our hosting, AI, payment and analytics providers) are based outside the UK, primarily in the United States and the European Economic Area. Where personal data is transferred internationally, we rely on an appropriate safeguard recognised under UK GDPR: a UK adequacy decision where one exists, or otherwise the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment.
You can ask us which safeguard applies to a specific provider by contacting us using the details in section 1.
11. Changes to this policy
We may update this privacy policy from time to time. We will notify you of significant changes by email or by displaying a notice in the platform.
