Privacy Policy
Effective date: 16 September 2026
Last updated: 16 September 2026
This Privacy Policy explains how personal data is collected, used, disclosed and protected in connection with the website trendread.com and the Trendread application (together, the "Service").
Please read this Policy together with our Terms of Service and Cookie Policy, which form part of the agreement between you and us.
1. Who we are (Data Controller)
For the purposes of the EU General Data Protection Regulation ("GDPR"), the UK GDPR, and comparable laws, the controller of your personal data is:
Iaroslav Meshchanov, operating as a sole trader
Email: trendread.deal@gmail.com
In this Policy, "we", "us" and "our" refer to the above. "You" refers to any person who visits the website, creates an account, or otherwise uses the Service.
We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. All privacy enquiries should be sent to the email address above.
2. Scope of this Policy
This Policy applies to personal data we process when you:
- visit trendread.com or any subdomain;
- create, access or use a Trendread account;
- purchase, subscribe to, or trial any paid plan;
- participate in our affiliate or referral programme, where offered;
- subscribe to our emails, newsletters or trend reports;
- contact us for support, sales or any other reason.
This Policy does not apply to third-party websites, platforms or services that we do not control, including TikTok, Instagram, Meta, Google, or any site you reach through a link from the Service. Their own privacy policies govern your use of them, and we accept no responsibility or liability for their practices.
3. Personal data we collect
We collect the following categories of data.
3.1 Data you provide directly
| Data | Examples | When collected |
|---|---|---|
| Account data | Name, email address, password hash, profile image | Registration |
| Authentication data | Google account identifier, email, basic profile fields, where you sign in with Google | Sign-in via Google OAuth |
| Billing data | Name, billing email, country, purchase and subscription history, invoices | Purchase or subscription |
| Content and inputs | Niches, keywords, prompts, briefs, account handles, and any other information you submit to generate Outputs | Use of the Service |
| Communications | Emails, support messages, survey and interview responses, feedback | When you contact us |
| Affiliate data | Payout details, referral activity, tax information where required | Affiliate enrolment, where offered |
3.2 Data collected automatically
| Data | Examples |
|---|---|
| Device and technical data | IP address, browser type and version, operating system, device type, screen size, language, time zone |
| Usage data | Pages viewed, features used, buttons clicked, session duration and frequency, referring URL, in-product events, error logs |
| Cookies and similar technologies | Cookie identifiers, pixel and local-storage identifiers, session tokens — see our Cookie Policy |
| Marketing attribution data | UTM parameters, advertising click identifiers, referral source, affiliate code |
3.3 Data we do not collect
- We do not collect or store payment card numbers, CVV codes, or bank credentials. All payment card data is collected and processed directly by our payment provider (see §6). We receive only transaction confirmations and limited billing metadata.
- We do not knowingly collect special categories of personal data under Article 9 GDPR (such as health, biometric, political, religious or sexual-orientation data). Please do not submit such data to the Service. If you do so, you do so voluntarily and at your own risk, and you consent to its processing as part of your submitted content.
- We do not knowingly collect data from children (see §12).
3.4 Publicly available third-party content
The Service analyses publicly available content published on third-party social media platforms (including TikTok and Instagram) — for example public videos, captions, public account handles, publicly displayed engagement metrics and publicly posted commentary — in order to identify trends and generate insights and scripts.
This content may, in some cases, contain personal data relating to persons other than you (for example, the handle of a public content creator). Where it does:
- we process such data only in aggregated or analytical form, for the purpose of trend identification and content-idea generation;
- our legal basis is legitimate interests (Article 6(1)(f) GDPR) in operating an analytics and content-ideation service, balanced against the limited, public and professional nature of the data;
- we do not use such data to build profiles of, contact, market to, or make automated decisions about the individuals concerned;
- we do not circumvent access controls, log-in walls, or technical restrictions in order to obtain it;
- any person whose public content has been processed may request erasure or object to processing by writing to trendread.deal@gmail.com, and we will honour such requests in accordance with §10.
You are solely responsible for ensuring that your own use of any Output generated by the Service — including any reference to third-party accounts, content, trademarks or persons — complies with applicable law and with the terms of the platform on which you publish.
4. How and why we use personal data (purposes and legal bases)
| Purpose | Categories used | Legal basis (GDPR / UK GDPR) |
|---|---|---|
| Creating and administering your account | Account, authentication | Performance of a contract — Art. 6(1)(b) |
| Providing, operating and delivering the Service, including generating Outputs | Account, content and inputs, usage | Performance of a contract — Art. 6(1)(b) |
| Processing payments, subscriptions, trials, renewals and refunds | Billing | Performance of a contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) |
| Providing customer support and responding to enquiries | Account, communications | Performance of a contract — Art. 6(1)(b); legitimate interests — Art. 6(1)(f) |
| Securing the Service, preventing fraud, abuse, bot traffic and unauthorised access | Technical, usage | Legitimate interests — Art. 6(1)(f); legal obligation — Art. 6(1)(c) |
| Analysing and improving the Service, debugging, measuring feature performance | Usage, technical | Legitimate interests — Art. 6(1)(f); consent where required for analytics cookies |
| Improving the quality, accuracy and safety of our models, prompts and Outputs | Content and inputs (see §5) | Legitimate interests — Art. 6(1)(f) |
| Sending service and transactional emails (receipts, security alerts, product notices) | Account, billing | Performance of a contract — Art. 6(1)(b); legitimate interests — Art. 6(1)(f) |
| Sending marketing emails, newsletters and trend reports | Account, marketing | Consent — Art. 6(1)(a); or legitimate interests for existing customers where permitted (soft opt-in) |
| Advertising, remarketing, conversion measurement and audience creation | Technical, marketing, usage | Consent — Art. 6(1)(a) where required |
| Operating the affiliate and referral programme, including attribution and payouts | Affiliate, billing | Performance of a contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) |
| Establishing, exercising or defending legal claims; complying with law, tax, accounting and chargeback obligations | Any relevant | Legal obligation — Art. 6(1)(c); legitimate interests — Art. 6(1)(f) |
| Corporate transactions (merger, acquisition, financing, reorganisation, asset sale) | Any relevant | Legitimate interests — Art. 6(1)(f) |
Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that our interests do not override your rights and freedoms. You may request further information about this assessment, and you may object to such processing as described in §10.
5. Your content and artificial intelligence
The Service uses third-party large language models and data APIs (see §6) to generate trend insights, content ideas and scripts ("Outputs"), as further described in our Terms of Service.
- Your inputs are transmitted to third-party model providers in order to generate Outputs. Do not submit confidential information, trade secrets, credentials, or personal data of third parties that you are not lawfully entitled to share.
- We may use your inputs, Outputs and usage patterns in de-identified or aggregated form to monitor quality, debug failures, improve prompts, measure performance, and develop the Service. Aggregated and de-identified data is no longer personal data and may be used and retained without restriction.
- Outputs are generated automatically and may be inaccurate, incomplete, outdated, non-original, or unsuitable for your purpose. We make no representation or warranty as to the accuracy, originality, non-infringement, performance or commercial results of any Output. You are responsible for reviewing, editing, fact-checking and clearing any Output before use or publication.
- We do not make decisions producing legal or similarly significant effects concerning you based solely on automated processing within the meaning of Article 22 GDPR. Generation of content suggestions is not such a decision.
- Model providers process data under their own terms. We select providers that contractually undertake not to train their foundation models on customer API data, but we do not control and cannot guarantee their practices, and we accept no liability for their acts or omissions beyond what is required by applicable law.
6. Third parties, processors and disclosures
We do not sell your personal data. We share it only as described below.
6.1 Service providers (processors and sub-processors)
We engage the following providers. Each processes data on our documented instructions under a data processing agreement, or as an independent controller where indicated.
| Provider | Function | Data involved | Location |
|---|---|---|---|
| Vercel Inc. | Application hosting, delivery, logs | Technical, usage | USA / global edge |
| Supabase Inc. | Database, authentication, storage | Account, content, usage | USA (us-east-1) |
| Google LLC (OAuth) | Authentication via Google sign-in | Authentication | USA / global |
| Google LLC (Gemini API) | Generation of Outputs | Content and inputs | USA / global |
| Cloudflare, Inc. | Bot protection, security (Turnstile), network | Technical | USA / global edge |
| ScrapeCreators | Public social-media content data | Public third-party content | USA / global |
| LAVALANE LTD (lava.top) | Payment collection and processing | Billing | Cyprus / EU |
| Resend | Transactional and marketing email delivery | Account, communications | USA / EU |
| PostHog Inc. | Product analytics, session and event data | Usage, technical | USA |
| Google LLC (Google Analytics 4) | Website analytics | Usage, technical | USA / global |
| Meta Platforms, Inc. | Advertising, conversion measurement, remarketing | Marketing, technical | USA / global |
This list may change as our providers change. The current list, together with the role each provider takes, is maintained at trendread.com/subprocessors.
Roles. Most providers above act as our processors. LAVALANE LTD (lava.top) acts as an independent controller and as our payment agent in respect of payment data, under its own terms. Meta Platforms, Inc. acts as an independent or joint controller for advertising purposes, and Google LLC may do so in respect of advertising services, in each case under its own terms and policies.
6.2 Other disclosures
We may also disclose personal data:
- to professional advisers — lawyers, accountants, auditors and insurers, bound by duties of confidentiality;
- to authorities — where required by applicable law, regulation, court order, subpoena, tax obligation or other legal process, or where we believe in good faith that disclosure is necessary to protect our rights, property or safety, or those of our users or the public;
- in connection with a corporate transaction — if we are involved in a merger, acquisition, financing, reorganisation, bankruptcy or sale of assets, personal data may be transferred as part of that transaction, subject to this Policy or a materially equivalent successor policy;
- to payment and dispute participants — including banks and card schemes, where necessary to process a payment, refund, chargeback or dispute;
- with your consent or at your direction, including where you choose to connect a third-party service.
7. International transfers
We operate internationally, and the providers listed above are located in a number of countries including the United States. Where personal data is transferred outside the European Economic Area, the United Kingdom, or your country of residence, we rely on one or more of the following safeguards:
- Standard Contractual Clauses approved by the European Commission (and the UK Addendum / UK IDTA where applicable);
- adequacy decisions of the European Commission, including in respect of certified participants in the EU–US Data Privacy Framework;
- derogations under Article 49 GDPR, including where the transfer is necessary for the performance of a contract with you.
You may request a copy of the relevant safeguards by writing to trendread.deal@gmail.com. Copies may be redacted to protect commercial confidentiality.
You acknowledge that no cross-border transfer mechanism can eliminate all risk, and that laws in recipient countries may permit access to data by public authorities.
8. Cookies and tracking
We use cookies, pixels, SDKs and similar technologies for authentication, security, analytics and advertising. Where required by law, non-essential cookies are set only after you give consent through our cookie banner, and you may withdraw or change your consent at any time via Cookie settings in the site footer.
Full details — including categories, named providers, purposes and durations — are set out in our Cookie Policy.
We do not currently respond to browser "Do Not Track" signals, as no common standard has been adopted. We honour Global Privacy Control (GPC) signals where applicable law requires it.
9. Data retention
We retain personal data only for as long as necessary for the purposes described in this Policy, and thereafter as required for our legal, accounting, tax and dispute-resolution obligations.
| Data | Retention period |
|---|---|
| Account data | For the life of the account, then up to 12 months after deletion or closure |
| Content and inputs, generated Outputs | For the life of the account, then up to 12 months, unless deleted earlier by you |
| Billing, invoices and transaction records | 7 years from the transaction, as required by tax and accounting law |
| Support communications | 24 months from last contact |
| Marketing contacts and consent records | Until you unsubscribe, then 24 months as proof of consent |
| Analytics and usage data | Up to 26 months |
| Security, access and error logs | Up to 12 months |
| Data relevant to an actual or anticipated legal claim | Until the claim and any appeal period is finally resolved |
Aggregated, anonymised and de-identified data may be retained indefinitely.
10. Your rights
Depending on where you live, you may have some or all of the following rights.
10.1 EEA, UK and comparable jurisdictions
- Access — obtain confirmation of whether we process your data and a copy of it.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have your data deleted where one of the grounds in Article 17 GDPR applies.
- Restriction — have processing restricted in the circumstances set out in Article 18 GDPR.
- Portability — receive data you provided to us in a structured, commonly used, machine-readable format.
- Objection — object to processing based on legitimate interests, including profiling; and object at any time and absolutely to processing for direct marketing.
- Withdraw consent — at any time, without affecting the lawfulness of processing before withdrawal.
- Complain — lodge a complaint with your local supervisory authority. In the UK this is the Information Commissioner's Office (ico.org.uk). We ask that you contact us first so we can try to resolve the matter.
10.2 California residents (CCPA/CPRA)
California residents may request disclosure of the categories and specific pieces of personal information collected, the sources, the business purposes, and the categories of third parties to whom it is disclosed; request deletion or correction; and opt out of any "sale" or "sharing" of personal information for cross-context behavioural advertising.
We do not sell personal information for money. Our use of advertising cookies and pixels may nonetheless constitute "sharing" under the CPRA. You may opt out via Cookie settings or by sending a GPC signal.
We will not discriminate against you for exercising any privacy right.
10.3 How to exercise your rights
Write to trendread.deal@gmail.com. We will respond within one month (extendable by two further months for complex or numerous requests, with notice to you).
We must verify your identity before acting on a request, and may ask for information sufficient to do so. Where a request is manifestly unfounded, repetitive or excessive, we may charge a reasonable fee or refuse to act, giving reasons. An authorised agent may submit a request on your behalf with written proof of authorisation.
Certain rights are qualified, not absolute. We may decline a request in whole or in part where an exemption applies — for example where retention is required by law, where the data is needed to establish, exercise or defend legal claims, or where compliance would adversely affect the rights and freedoms of others.
11. Security
We implement technical and organisational measures appropriate to the risk, including encryption in transit (TLS), access controls and authentication, bot and abuse protection, hosting with providers that maintain recognised security certifications, and the principle of least privilege for administrative access.
No method of transmission or storage is completely secure. While we work to protect your personal data, we cannot and do not guarantee its absolute security, and any transmission is at your own risk. You are responsible for maintaining the confidentiality of your account credentials and for all activity under your account, and must notify us immediately at trendread.deal@gmail.com of any suspected unauthorised access.
Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority, and where required, affected users, in accordance with Articles 33 and 34 GDPR.
12. Children
The Service is intended for business and professional use and is not directed to persons under 18. We do not knowingly collect personal data from anyone under 18.
By using the Service, you represent that you are at least 18 years old and have the authority to enter into this agreement. If you believe a minor has provided us with personal data, contact trendread.deal@gmail.com and we will delete it promptly.
13. Third-party links and integrations
The Service may contain links to, and integrations with, third-party websites, platforms and services. We do not control them, are not responsible for their content, security or privacy practices, and their inclusion does not imply endorsement. Any data you provide to a third party is governed by that party's own policies, and you should review them before proceeding.
14. Marketing communications
Where required by law, we send marketing emails only with your consent. Where you are an existing customer, we may send you information about similar products and services on the basis of legitimate interests, in reliance on the applicable soft opt-in.
You may unsubscribe at any time using the link in any marketing email or by writing to trendread.deal@gmail.com. You cannot opt out of transactional and service messages (receipts, security alerts, material changes to terms), as these are necessary to operate your account.
15. Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices, technology, providers or legal requirements. The "Last updated" date at the top indicates when it was last revised.
If we make material changes, we will provide notice by email to the address associated with your account, or by a prominent notice on the Service, before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the revised Policy. If you do not agree, you must stop using the Service and may close your account.
We recommend reviewing this Policy periodically. Prior versions are available on request.
16. Severability, no waiver and interpretation
If any provision of this Policy is held invalid, illegal or unenforceable, that provision shall be severed and the remainder shall continue in full force and effect. Our failure to enforce any provision does not constitute a waiver of it. Headings are for convenience only and do not affect interpretation.
This Policy is published in English. Where we provide a translation, the English version prevails in the event of any conflict, except where applicable local law requires otherwise.
17. Contact
For any question, request or complaint about this Policy or your personal data:
Iaroslav Meshchanov
Email: trendread.deal@gmail.com