Legal
Privacy Policy
This policy explains what Churnless collects, how we use it, and the controls available to customers and end users.
Last updated: August 1, 2026
Who we are
Churnless provides churn prevention, cancellation flow, payment recovery, analytics, and customer intelligence software for subscription businesses. In this policy, “Churnless,” “we,” “us,” and “our” refer to Churnless.
For customer data that a business sends to Churnless, that business is generally the controller or business, and Churnless acts as a processor or service provider under the customer agreement and any applicable data processing addendum.
Information we collect
- Account information, such as name, email address, company name, team membership, authentication events, and support requests.
- Billing and subscription information for Churnless customers, including plan, invoices, payment status, and tax or billing details handled through our payment providers.
- Product and integration configuration, such as connected products, cancellation flow settings, webhook endpoints, API keys, and restricted Stripe key metadata.
- Customer data provided by our customers, including customer identifiers, subscription status, billing events, invoices, payment failures, cancellation reasons, feedback, lifecycle events, and product usage signals.
- Usage and device information, such as pages viewed, feature usage, logs, IP address, browser, operating system, approximate location, referring URLs, and diagnostic events.
- When a customer enables session recording and an end user has granted analytics consent, privacy-masked interaction replay data such as navigation, clicks, scrolling, and rendered page structure. Form values are masked in all modes by default, and strict mode also masks ordinary page text. A customer may separately opt in to capturing text typed into recognized prompt or composer fields; sensitive fields such as passwords, emails, names, and payment details remain masked even then.
- Communications, including emails, support messages, responses to dunning or recovery emails, and related metadata.
How we use information
- Provide, secure, operate, and improve Churnless.
- Generate cancellation flows, save offers, health scores, analytics, payment recovery workflows, and customer insights.
- Authenticate users, administer accounts, provide support, and communicate service updates.
- Process payments, prevent fraud, enforce usage limits, and comply with legal obligations.
- Monitor reliability, debug errors, protect against abuse, and maintain audit logs.
- Train, evaluate, and improve Churnless product behavior using de-identified or aggregated information where appropriate. We do not use a customer's identifiable customer data to train public or shared AI models.
AI and customer data
Churnless uses AI systems to classify feedback, summarize customer signals, recommend retention actions, draft recovery messages, and help teams understand churn risk. These AI features are designed to act on the data a customer connects to its own Churnless workspace.
We do not sell customer data. We also do not use a customer’s identifiable customer data to train public or shared foundation models.
How we share information
- Service providers that help us host, secure, analyze, support, email, and operate Churnless.
- AI infrastructure subprocessors: model providers that process derived, PII-redacted context to generate analyses, and a managed memory service (supermemory.ai) that stores distilled, PII-redacted customer facts — never raw events, message bodies, or replay content — scoped per organization.
- Payment processors and billing providers used to process Churnless subscriptions.
- Integrations configured by a customer, such as Stripe, webhook destinations, Slack, email providers, or other connected tools.
- Professional advisers, auditors, or insurers where reasonably necessary.
- Authorities or third parties where required by law, to protect rights and safety, or in connection with a merger, acquisition, financing, or sale of assets.
Cookies and similar technologies
We use cookies and similar technologies for authentication, security, product analytics, preference storage, and site performance. Customers may also install Churnless tracking components in their own products to send usage events to Churnless for churn-risk analysis.
Session recording
Churnless session recording is optional and disabled by default for every product. Our customers are responsible for providing any notice and obtaining any consent required for recording in their products. Churnless uses the customer’s existing analytics-consent signal; recording stops and unsent replay data is discarded when consent is revoked or Do Not Track is enabled.
All modes mask form values by default and support exclusion markers for sensitive regions. Strict mode also masks ordinary page text. Customers may separately enable an opt-in setting that records text typed into recognized prompt or composer fields verbatim; fields recognized as sensitive (passwords, emails, names, payment details, and similar) remain masked even when that setting is on, and customers are responsible for disclosing the setting to their users. Canvas pixels, inline images, fonts, console output, and cross-origin iframe contents are excluded. Replay chunks are stored in private object storage, available only through authenticated workspace routes, and deleted after 30 days.
Data retention and deletion
We retain information for as long as needed to provide Churnless, comply with legal obligations, resolve disputes, enforce agreements, and maintain security. Customers may request export or deletion of workspace data, subject to contractual, security, and legal retention requirements.
Session replay data has a fixed 30-day retention period. Authorized workspace administrators can delete an individual replay sooner from the dashboard.
Your choices and rights
Depending on location, individuals may have rights to access, correct, delete, port, or object to certain processing of personal information. If your information was provided to Churnless by one of our customers, please contact that customer directly. We will assist customers in responding to valid requests where required.
To contact Churnless about privacy, email privacy@getchurnless.com.
Security
We use technical, administrative, and organizational safeguards designed to protect information, including encryption in transit, encryption at rest, access controls, audit logging, and least-privilege integration design. No system is perfectly secure, but we work to protect Churnless and our customers’ data.
More details are available on our Security page.
Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the date above and provide additional notice when appropriate.