Privacy Policy
Last updated: 31 August 2026
Product Pilot is built to hold as little of your data as possible. There are no accounts, no cookies, and no advertising trackers — only an anonymous, aggregate count of visits. Your work is kept in your own browser, your session lives only in memory for a couple of hours, and the only thing that leaves is the text you choose to send to the AI so it can write your plan.
1. Who this policy is about
This policy explains how Product Pilot (“Product Pilot”, “we”, “us”) handles information when you use the website and app. Product Pilot is operated by Julian Caspari, an individual based in Australia. We handle personal information in line with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
If you have any question about this policy or your information, contact us at productpilot@caspari.io.
2. The short version
- No accounts, no sign-up, no passwords. We don't ask who you are.
- No cookies, no advertising, no third-party trackers. We do count visits with a cookie-free, aggregate-only analytics tool that cannot identify you (see section 6).
- Your idea, your answers, and everything Product Pilot generates are saved in your own browser (local storage) so a refresh doesn't lose your work.
- While you're working, a copy of your session is held in our server's memory only, and is deleted automatically after about two hours of inactivity.
- The one time your content leaves your device is when it is sent to our AI provider to generate part of your plan. Please don't put confidential or personal information about yourself or others into your idea.
3. What information we handle
Content you enter
The idea you describe, the answers you give to clarifying questions, edits you make, and the artifacts Product Pilot generates from them (directions, personas, scenarios, value proposition, business model, and the final build plan). We treat this as your content. If you choose to include personal information in it, it is handled as described here.
Storage on your device
Product Pilot mirrors your working session to your browser's localStorage as you type, so you can refresh or come back without losing progress. This data stays on your device. It is not a cookie, it is not automatically transmitted to us, and you can clear it at any time (see the Cookie notice). Starting a new idea or resetting the app removes it.
Contacting us
If you email us, we receive your email address and whatever you write, and use it only to respond to you.
If you use the Feedback button, we receive the type you chose, your message, the page and step you were on, your browser type, and — only if you tick the box — the idea text from your session, plus your email address if you enter one. Feedback goes to our inbox (or, on a self-hosted copy, to a private log on the server), is used only to fix problems and improve Product Pilot, and is deleted once it has been dealt with.
Technical data
Product Pilot's application code does not write your idea or generated content to server logs. As with any website, the hosting and network infrastructure that delivers the site may process basic technical connection data (such as your IP address) for the short time needed to serve requests, keep the service running, and protect it from abuse. We do not use this to build a profile of you.
4. How your idea is processed by AI
To write your plan, Product Pilot sends the relevant parts of your content to an AI model. Requests are made from our server (never directly from your browser). Depending on how the service is configured, that request goes to one of two places:
- Directly to Google (the Gemini API), our primary AI provider; or
- Routed through OpenRouter, which forwards it to the language model selected for that step — used either because Google's service was unavailable for that one request, or because the deployment is configured to use it as the primary route. That model may be a free, third-party model or a paid Anthropic (Claude) model.
These providers process your content only to return a response, but they operate under their own terms and privacy policies, which govern any retention on their side. Our use of Google's Gemini API is configured on a billing-enabled basis, under which Google states it does not use prompts or responses submitted through the API to improve its products, and keeps them only briefly for abuse detection. Anthropic states that it does not use data submitted through its API to train its models by default; free or third-party models routed through OpenRouter may handle data differently and may retain inputs.
Because your content is sent to these providers, do not enter anything confidential, or personal information about yourself or other people, that you would not want processed by a third party.
5. Where data is kept, and for how long
- In your browser: until you clear it, start a new idea, or reset the app. We never see it unless it is sent to the AI as part of generating your plan.
- On our server: only in memory (RAM) while your session is active. There is no database and nothing is written to disk. Inactive sessions are evicted automatically after roughly two hours, and everything is lost if the server restarts.
- With the AI provider: for the time and purpose described in their policies, which we don't control.
6. Cookies and tracking
Product Pilot uses no cookies and no advertising trackers. The only browser storage we use is the strictly necessary local storage described above. See the Cookie notice for detail.
We do use one analytics tool, Vercel Web Analytics, so we can tell whether anyone uses Product Pilot and which pages they reach. It sets no cookies and records only aggregate statistics: the page visited, the site you came from, your country and region, your device type, browser and operating system, and the time. Visits are told apart by a hash of the request that is discarded after 24 hours; your IP address is not stored, no profile is built, and nothing follows you across other websites. Your idea and generated content are never part of this data. Details: Vercel Web Analytics — privacy and compliance.
7. Who we share information with
We do not sell your information and we do not share it for advertising. Your content is disclosed only to the AI provider needed to generate your plan — Google (directly) and/or OpenRouter, as described in section 4 — and to the infrastructure provider that hosts the service and runs the aggregate visit counting described in section 6 (Vercel). We may disclose information if required to do so by law.
8. Overseas processing
The AI providers and hosting infrastructure Product Pilot relies on may be located outside Australia, including in the United States. By using Product Pilot and sending content to be processed, you understand that it may be handled overseas by those providers under their own terms.
9. Your choices and rights
Because Product Pilot doesn't hold accounts, you are already in control of most of your data: it lives in your browser and clears when you reset or clear local storage, and your server-side session self-deletes after a short idle period.
Under the Australian Privacy Principles you may ask us for access to, or correction of, any personal information we hold about you, and you may make a privacy complaint. In practice we hold very little — usually only what you have emailed us — but you can reach us at productpilot@caspari.io and we will respond within a reasonable time. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.
10. Children
Product Pilot is intended for adults building products and is not directed at children. We do not knowingly collect information from children.
11. Changes to this policy
We may update this policy as the product changes. When we do, we'll revise the “Last updated” date above. Significant changes will be reflected on this page.
12. Contact
Questions about privacy? Email productpilot@caspari.io.