Legal

Privacy Policy

Last updated: May 4, 2026

1. Data controller

The data controller is Sophie Attelann, publisher of VerticalClap (verticalclap.com). Contact: hello@verticalclap.com

2. Data collected

Account data: email address, provided at subscription via Whop.

Payment data: handled exclusively by Whop. VerticalClap stores no banking data.

Usage data: anonymous feature usage counters (via Upstash Redis). No generated content is retained on our servers beyond the session.

Saved series: if you enable cloud saving, your bibles and scripts are stored encrypted and linked to your Whop identifier.

3. Processing purposes

Your data is used to:

Manage your subscription and service access

Process payments via Whop

Send service-related transactional emails (welcome, reminders, cancellation)

Improve the service via anonymous usage metrics

4. Legal basis

Processing of your data is based on the performance of the subscription contract entered into with VerticalClap (Art. 6.1.b GDPR). Marketing emails are based on legitimate interest and/or your consent.

5. Retention period

Your data is retained for the duration of your subscription and 3 years after cancellation, in accordance with accounting and tax legal obligations.

6. Data sharing

Whop — for payment processing and subscription management.

Anthropic — for AI content generation (Claude). Prompts are processed without being retained, in accordance with their enterprise policy.

Resend — for transactional email delivery.

VerticalClap does not sell any personal data to third parties.

7. Your rights (GDPR)

Under GDPR, you have the following rights:

Right of access to your personal data

Right of rectification

Right to erasure (right to be forgotten)

Right to data portability

Right to object

To exercise these rights: hello@verticalclap.com

8. Cookies

VerticalClap uses only technical cookies necessary for service operation (session, preferences). No advertising or third-party tracking cookies are set.

9. Security

VerticalClap implements appropriate technical measures: HTTPS, encryption of data at rest, restricted database access. Security incidents are reported to the relevant supervisory authority within 72 hours if required.

10. Contact and complaints

For any questions: hello@verticalclap.com

You have the right to lodge a complaint with your local data protection authority (in France: www.cnil.fr).