Privacy Policy

Last updated: March 14, 2026

Changelog AI ("we," "us," or "our") operates the Changelog AI web application and related services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

1. Information We Collect

Account Information

When you create an account, we collect your name, email address, and profile image (if you sign in via Google OAuth). If you register with a magic link, we collect only your email address.

Usage Data

We automatically collect information about how you interact with the service, including pages visited, features used, timestamps, browser type, operating system, and referring URLs. This data helps us improve the product and diagnose technical issues.

Content You Provide

When you use our AI changelog generator, the bullet points and notes you submit are sent to a third-party AI provider (Anthropic) for processing. The generated changelog entries, project names, labels, and any other content you create are stored in our database.

Payment Information

When you subscribe to a paid plan or purchase a Founders Edition deal, your payment details (credit card number, billing address) are collected and processed directly by Stripe. We do not store your full credit card number on our servers.

Cookies

We use cookies and similar technologies to maintain your authenticated session, remember your preferences, and understand how the service is used. You can control cookie settings through your browser, though disabling cookies may limit some functionality.

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Changelog AI service
  • Authenticate your identity and manage your account and workspace
  • Process payments and manage your subscription or Founders Edition deal
  • Generate AI-powered changelog entries from your input using the Anthropic Claude API
  • Send transactional emails such as subscription confirmations, magic link sign-ins, and changelog notifications to your subscribers
  • Improve the service based on usage patterns and feedback
  • Detect, prevent, and address security issues and abuse
  • Comply with legal obligations and enforce our terms of service

3. Third-Party Services and Data Sharing

We share data with the following third-party services, each of which is necessary for our product to function. We do not sell your personal information to third parties.

Stripe — Payment Processing

Stripe processes all payments for Changelog AI. When you subscribe or purchase a Founders Edition deal, Stripe receives your payment card details, billing address, and email address. We receive a Stripe customer ID and subscription status but never your full card number. Stripe's privacy policy is available at stripe.com/privacy.

Resend — Transactional Email Delivery

Resend delivers transactional emails on our behalf, including magic link sign-in emails, subscriber confirmation emails, and new changelog entry notifications. Resend receives the recipient's email address and the email content. Resend's privacy policy is available at resend.com/legal/privacy-policy.

Google — OAuth Authentication

If you choose to sign in with Google, we use Google OAuth to authenticate your identity. Google shares your name, email address, and profile picture with us. We do not access your Google contacts, calendar, or any other Google account data. Google's privacy policy is available at policies.google.com/privacy.

Anthropic — AI Changelog Generation

When you use the AI changelog generator, the bullet points and notes you provide are sent to Anthropic's Claude API to generate polished changelog entries. Anthropic processes this content according to their usage policies. We do not send your account information, payment details, or subscriber data to Anthropic — only the content you explicitly submit for AI generation. Anthropic's privacy policy is available at anthropic.com/privacy.

4. Data Retention and Deletion

We retain your account data and content for as long as your account is active. If you delete your account, we will remove your personal information and content from our active databases within 30 days. Some data may persist in encrypted backups for up to 90 days before being permanently deleted.

Payment records may be retained longer as required by tax and financial regulations. Anonymized usage data that cannot be linked back to you may be retained indefinitely for analytics purposes.

5. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access — Request a copy of the personal data we hold about you
  • Rectification — Request correction of inaccurate or incomplete data
  • Erasure — Request deletion of your personal data ("right to be forgotten")
  • Data Portability — Request your data in a structured, machine-readable format
  • Restriction — Request that we limit how we process your data
  • Objection — Object to the processing of your data for certain purposes

To exercise any of these rights, please contact us at the email address listed at the bottom of this page. We will respond to your request within 30 days.

6. California Privacy Rights (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) grants you additional rights regarding your personal information:

  • Right to Know — You may request that we disclose the categories and specific pieces of personal information we have collected about you, the sources of that information, the business purpose for collecting it, and the categories of third parties with whom we share it.
  • Right to Delete — You may request that we delete the personal information we have collected from you, subject to certain exceptions.
  • Right to Non-Discrimination — We will not discriminate against you for exercising your CCPA rights.

We do not sell personal information as defined by the CCPA. To submit a CCPA request, contact us using the information in the Contact section below.

7. Cookies and Tracking

Changelog AI uses the following types of cookies:

  • Essential Cookies — Required for authentication and maintaining your session. These cannot be disabled without losing access to the service.
  • Preference Cookies — Store your settings such as theme preference (light/dark mode).

We do not use third-party advertising trackers or sell data to ad networks. You can manage cookie preferences through your browser settings.

8. Children's Privacy

Changelog AI is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information promptly. If you believe a child under 13 has provided us with personal data, please contact us immediately.

9. Security Measures

We implement industry-standard security measures to protect your data, including:

  • Encryption in transit (TLS/HTTPS) for all data exchanged between your browser and our servers
  • Encryption at rest for database storage
  • Secure authentication using JWT-based sessions and OAuth 2.0
  • Payment data handled exclusively by Stripe, a PCI DSS Level 1 certified payment processor
  • Regular security reviews and dependency updates

While we strive to protect your personal information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to promptly addressing any security incidents.

10. International Data Transfers

Your data may be processed and stored in countries outside your own, including the United States, where our servers and third-party service providers are located. By using Changelog AI, you consent to the transfer of your information to these countries. We ensure that appropriate safeguards are in place to protect your data in accordance with this Privacy Policy and applicable data protection laws.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable laws. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you by email or through a notice in the application.

We encourage you to review this page periodically to stay informed about how we handle your data.

12. Contact Information

If you have any questions about this Privacy Policy, want to exercise your data rights, or have concerns about how your information is handled, please contact us at:

Email: support@changelogai.co

See also