Legal

Privacy Policy

Last Updated: March 13, 2026

Introduction

This Privacy Policy explains how Napkin, LLC, operating its marketing lab at naepkin.co, collects, uses, and protects information when you use our marketing experimentation platform.

This policy applies to all users of naepkin.co and the Napkin platform.

Information We Collect

Personal Information

When you create an account, we collect:

  • Your name
  • Your email address

Usage Data

As you use the platform, we collect:

  • Pages and features you visit
  • Experiments you create and run
  • Actions taken within the platform

We use this data to operate and improve the service. We do not sell it, use it for advertising, or share it with third parties except as described below.

How We Use Your Information

We use your information to:

  • Deliver and maintain the Napkin service
  • Send transactional emails — account notifications, experiment activity updates, and billing receipts (via Resend)
  • Respond to your support requests
  • Improve the platform based on how it is used

We do not use your data for advertising. We do not sell your data to anyone.

Cookies

Napkin uses a minimal set of cookies necessary to operate the service:

CookiePurposeType
next-auth.session-tokenKeeps you logged inFunctional
next-auth.csrf-tokenPrevents cross-site request forgeryFunctional

We use functional cookies for session management and authentication. No advertising or third-party tracking cookies are used.

Third-Party Services

We work with a small number of third-party services to operate Napkin:

Stripe

Handles all payment processing. When you subscribe, you enter your payment details directly into Stripe's secure interface — we never see or store your full card number. Stripe is PCI-DSS compliant.

Stripe Privacy Policy

Resend

Delivers transactional emails from Napkin (account confirmations, experiment notifications, billing receipts). Your email address is shared with Resend for this purpose only.

Resend Privacy Policy

Vercel

Hosts the Napkin platform and processes request metadata (including IP addresses) as part of standard infrastructure operation.

Vercel Privacy Policy

X (formerly Twitter)

Napkin allows users to connect their X account to create and publish social media posts.

When you connect your X account, we may access:

  • your public profile information (such as username and account ID)
  • authorization tokens required to authenticate and publish content on your behalf

We use this data solely to authenticate your account and enable you to publish posts through the platform. Data from X is accessed only with your explicit authorization through X's OAuth process.

We do not access or store:

  • direct messages
  • follower lists
  • private account data beyond what is required for posting
  • your X account password at any time

We do not sell or use X data for advertising.

Data Deletion (X)

We retain X data only as long as necessary to provide the service.

If you disconnect your X account from Napkin, or revoke access via your X account settings, we will delete associated X data within 30 days.

To request deletion of your X data at any time, contact legal@naepkin.co.

Your Rights

Depending on where you are located, you may have rights regarding your personal data:

  • Access — request a copy of the data we hold about you
  • Correction — request that we correct inaccurate data
  • Deletion — request that we delete your account and associated data
  • Portability — request your data in a machine-readable format

To exercise any of these rights, email us at legal@naepkin.co. We will respond within 30 days.

If you are in the European Union or California, these rights are provided under GDPR and CCPA respectively. We will honor them regardless of where you are located.

Data Retention

We retain your account data for as long as your account is active. If you request deletion, we will remove your personal data within 30 days, except where retention is required by law.

Changes to This Policy

If we make material changes to this policy, we will notify you by email or through the platform before the changes take effect. The "Last Updated" date at the top of this page reflects the most recent revision.

Contact

Napkin, LLC c/o Northwest Registered Agent 418 Broadway Ste N Albany, NY 12207

Email: legal@naepkin.co