Last updated: 2026-09-20
Privacy Policy
This Privacy Policy describes how Cutero (“we”, “us”) processes personal data when you use the Early Access product at app.cutero.app and the marketing site at getcutero.com.
This document reflects how Cutero currently works. It is not legal advice. Owner-review fields that must be completed before treating this policy as final are marked in square brackets.
1. Controller / contact
Data controller:
Jacopo Penazzi, operating Cutero
Privacy contact:
privacy@getcutero.com
2. Data we process
Account data
- Email address
- Password hash (passwords are never stored in plaintext)
- Email verification timestamps
- Authentication session data (HTTP-only cookie containing a signed session token)
- Optional acquisition metadata (first-touch UTM parameters captured at signup)
Subscription data you enter
- Service name and optional URL
- Price and billing / renewal information
- KEEP / CUT decision state
- Related timestamps and activity metadata used to operate the product
Feedback data
- Rating
- Optional free-text feedback
- Previous-solution survey answers (when provided)
Operational data
- Account and activity timestamps (for example last active, activation)
We do not claim to collect data categories that Cutero does not process.
3. Purposes
- Create and secure your account
- Provide subscription tracking and KEEP / CUT review features
- Send essential service emails (verification, password recovery)
- Prevent abuse (rate limiting, Cloudflare Turnstile on registration)
- Measure product usage and acquisition with privacy-conscious analytics
- Improve Early Access based on feedback
4. Legal bases
Where applicable (for example under the GDPR), we rely on: performance of a contract / steps prior to a contract (providing the service you request); legitimate interests (security, abuse prevention, product improvement in Early Access); and consent where required for specific optional processing. Exact jurisdictional framing will be confirmed by the controller after legal review.
5. Password handling
Passwords are not stored in plaintext. We store a one-way password hash and use it only to verify sign-in and password-change requests.
6. Analytics
Cutero uses self-hosted Umami analytics on
analytics.cutero.app
for
getcutero.com
and
app.cutero.app. Umami is configured for cookieless, privacy-conscious usage
and acquisition measurement. Application analytics intentionally avoids sending email
addresses, user IDs, passwords, tokens, or subscription content such as service names.
We do not describe this analytics as absolutely “anonymous” in a legal sense. It is privacy-conscious product analytics.
7. Cloudflare Turnstile
Registration uses Cloudflare Turnstile to help prevent bots and abuse. Cloudflare may process technical information necessary to provide that anti-abuse service. Turnstile is not used as marketing analytics.
8. Email
We use email for:
- Email verification
- Password recovery
- Essential account / service communications
We do not operate a marketing newsletter at this Early Access stage unless separately announced.
9. Hosting and processors
Depending on configuration, processing may involve:
- Hetzner (application hosting)
- MongoDB Atlas (application database)
- Namecheap / cPanel SMTP (transactional email delivery)
- Cloudflare Turnstile (registration abuse prevention)
- Self-hosted Umami (privacy-conscious analytics)
We do not invent contractual processor details here. Ask privacy@getcutero.com for processor questions.
10. Retention
Data is retained for as long as necessary to provide the service and comply with applicable obligations. There is currently no automatic account-deletion schedule in the product.
11. Your rights and deletion
Depending on applicable law, you may have rights to access, correction, deletion, restriction, objection, portability, and complaint to a supervisory authority.
Cutero does not currently offer self-service account deletion in the product. To request access, correction, or deletion of your account data, contact privacy@getcutero.com from the email address associated with your account.
12. Security
We use industry-common safeguards appropriate to Early Access, including HTTPS, hashed passwords, hashed one-time tokens for email verification and password reset, and HTTP-only session cookies. No method of transmission or storage is perfectly secure.
13. International processing
Infrastructure and processors may process data in the EU and/or other regions depending on provider configuration. Details will be confirmed by the controller as part of owner review.
14. Policy updates
We may update this Privacy Policy as Cutero evolves. The “Last updated” date at the top will change when we do. Material changes may also be communicated through the product or email when appropriate.
15. Contact
Questions about privacy: privacy@getcutero.com