Startup Maya Legal
Privacy Policy
Last updated: May 21, 2026
Overview
Startup Maya is an early-stage MVP operated by an individual founder. It helps users explore startup ideas, create validation assets, publish simple public pages, and schedule meetings through Google Calendar and Google Meet.
This Privacy Policy explains what information Startup Maya collects, how it is used, and the choices available to users. For privacy or data requests, contact itusharbiswas@gmail.com.
Information We Collect
Startup Maya may collect and store the following categories of information:
- Account profile information from Kinde, such as name, email address, and authentication identifier.
- Startup, project, workspace, validation, brand, pitch, business-plan, notes, and public-page content users create in the app.
- Waitlist email addresses submitted on public startup pages hosted by Startup Maya.
- Meeting scheduler information, including founder booking handle, display name, availability, timezone, meeting duration, attendee name, attendee email, attendee message, meeting time, Google Calendar event ID, and Google Meet link.
- User-provided Groq API keys, stored encrypted at rest when users choose to add them.
- Google OAuth access and refresh tokens, stored encrypted at rest when users connect Google Calendar.
- Public or source-derived startup problem data, including problem candidates derived from public Reddit content and related public source references.
- Operational information such as logs, error reports, request metadata, and basic device/browser information needed to run, secure, debug, and improve the service.
How We Use Information
Startup Maya uses collected information to:
- Provide account access, workspace features, project management, AI-assisted generation, public startup pages, waitlists, and meeting scheduling.
- Create and maintain booking links, show available meeting slots, create Google Calendar events, and generate Google Meet links.
- Store user preferences, project progress, generated outputs, and published page settings.
- Operate, secure, troubleshoot, and improve the product.
- Respond to support, privacy, security, and legal requests.
Google Calendar and Google Meet Data
Startup Maya accesses Google Calendar data only after a user explicitly connects Google Calendar through the Google OAuth consent flow. Startup Maya currently requests access so it can check calendar free/busy availability, create calendar events for confirmed bookings, invite attendees, and generate Google Meet links. For event creation, Startup Maya uses the Google Calendar owned-events scope so it can create booking events on calendars owned by the connected user.
Startup Maya stores encrypted Google OAuth tokens so the connected calendar can continue working after the first authorization. Users can disconnect Google Calendar from the meeting scheduler settings.
Startup Maya does not sell Google user data, does not use Google Calendar data for advertising, and does not use Google Calendar data to train generalized AI models. Humans do not read Google Calendar data except where necessary for user-authorized support, security, debugging, legal compliance, or abuse investigation.
Startup Maya's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Third-Party Services
Startup Maya uses third-party services to provide parts of the product:
- Kinde for authentication and account sessions.
- MongoDB or database hosting infrastructure for application data storage.
- Google Calendar and Google Meet for calendar connection, availability checks, meeting invites, and video meeting links.
- Groq for AI-assisted generation when the feature is enabled and an API key is configured.
- Vercel or similar hosting infrastructure for deploying and operating the web application.
These providers process information according to their own terms and privacy policies. Startup Maya shares information with them only as needed to operate the service, secure the product, or provide user-requested features.
Security
Startup Maya uses HTTPS in production and encrypts sensitive credentials such as user-provided Groq API keys and Google OAuth tokens at rest. Access to operational systems is limited to what is needed to operate, debug, and secure the MVP.
No online service can guarantee perfect security. If you believe you have found a security issue, contact itusharbiswas@gmail.com.
Data Retention and Deletion
Startup Maya retains account, project, booking, and related operational data while an account remains active or while needed to provide the service. Users may delete their account in the app settings where available or contact itusharbiswas@gmail.com to request deletion.
Upon deletion, Startup Maya will delete or anonymize account data unless retention is required for legal, security, abuse-prevention, backup, or operational reasons. Backup and log data may persist for a limited period before being deleted through normal retention cycles.
Your Choices and Rights
Users may request access, correction, export, or deletion of their personal information by contacting Startup Maya.
- Disconnect Google Calendar from meeting scheduler settings.
- Delete the account from settings where available.
- Request privacy support by emailing itusharbiswas@gmail.com.
Children
Startup Maya is not intended for children under 13, and it does not knowingly collect personal information from children under 13.
Changes to This Policy
Startup Maya may update this Privacy Policy as the MVP evolves. The updated date at the top of this page will reflect the latest version.
Related Pages
Review the Terms of Service for additional rules that apply when using Startup Maya.