Privacy Policy
Last updated: 17 August 2026.
What we collect
- Query content. The search terms, topic ids, regions, and time ranges you pass to a tool. This is the data we need to answer the request.
- Account data. If you connect an account: your email address, your plan, and a one-way hash of each API key you create. We store the hash, never the key itself.
- Usage records. For each billable call, the tool name, what it cost against your allowance, and when. These are linked to your account.
- Billing data. Your Stripe customer and subscription identifiers, your plan, and its status.
We do not receive or request your conversation history, message transcripts, files, memory, or account credentials, and we do not ask for health data or government identifiers. Card details are entered directly with Stripe and never reach us.
Query content is not linked to your identity
Worth stating plainly, because it is the question people actually have. Your search terms are never written to our database. The durable usage record holds only the tool name and what it cost — not your terms. Terms do appear inside cached responses, which echo them back, but those are stored under a hash and expire on a timer, and they carry no account identifier. Nothing in our storage connects an account to the things it looked up.
How we use it
Query content is used solely to fetch the corresponding search-trend data and to cache the result. Account data is used to authenticate you and to enforce your monthly allowance. Usage records support billing and allowance limits. Operational data is used to keep the service running and diagnose failures.
Who receives it
- Google. Search terms are sent to Google Trends to retrieve results.
- Decodo. Requests to Google are routed through their proxy network.
- Vercel. Hosting and runtime logs.
- Upstash. The Redis cache holding recent responses.
- Neon. The Postgres database holding accounts, plans, API key hashes, and usage records.
- WorkOS. Authentication. They hold your email address and sign-in credentials.
- Stripe. Payments and subscriptions, including your card details, which you provide to them directly.
These providers process data in the United States and the European Union. We do not sell your data, and we do not use it to build advertising profiles.
Retention
- Cached responses are stored under a one-way hash of the query, never the query itself, and expire on a timer — from 15 minutes for fast-moving data up to 14 days for topic lookups, which barely change. They are not linked to any account.
- Account data and usage records are kept while your account exists, and for as long afterwards as tax and accounting rules require for billing records.
- Runtime logs are retained for up to 30 days.
Your controls
You can see your plan, usage, and API keys on your account page, and revoke a key there at any time. To request a copy of what we hold, a correction, or deletion of your account, email dario@mory.dev. Deleting an account removes it along with its API keys, usage records, and subscription record; we may keep the minimum billing history the law requires.
Children
TrendFlow is not directed at children and we do not knowingly collect their data.
Changes
If this policy changes materially, the date above will change and the current version will always be published here.
