newma
  • How it works
  • Benefits
  • Pricing
Run free auditRun free audit
  • How it works
  • Benefits
  • Pricing
  • Run free auditβ†’

LEGAL Β· PRIVACY

Privacy Policy

Last updated: May 2026

Contents

  1. 01Who we are
  2. 02What this policy covers
  3. 03Data we collect
  4. 04How we use your data
  5. 05Third-party services
  6. 06Report access and security
  7. 07Cookies
  8. 08Data retention
  9. 09Your rights
  10. 10International data transfers
  11. 11Children
  12. 12Changes to this policy
  13. 13Contact

01Who we are

newma is operated by Shookin, a sole proprietorship registered in the Republic of Korea (Business Registration Number: 641-48-00948).

newma provides an AI-powered product-market fit audit tool for founders and small teams. We analyze publicly available data about your product and its market to generate actionable marketing insights.

Contact: πŸ“§ [privacy@newma.com]

02What this policy covers

This Privacy Policy explains what data we collect, how we use it, and your rights β€” when you visit our website (newma.com), run an audit, view a report, or use any paid module.

We keep this document in plain language on purpose. If something is unclear, email us and we'll explain.

03Data we collect

Data you provide directly

When you run an audit, you may provide:

  • Website URL (required) β€” the product you want us to analyze
  • Social media handles (optional) β€” X (Twitter) and/or Instagram handles
  • Two context questions (optional) β€” your customer types and the core problem your product solves
  • Email address (optional) β€” only if you opt in for report delivery or updates

When you purchase a paid module (fixkit), you provide:

  • Payment information β€” processed entirely by Lemon Squeezy (our payment provider). We do not store credit card numbers, bank details, or billing addresses on our servers. We receive only a transaction confirmation, the plan you purchased, and the email associated with the purchase.

Data we collect automatically

When you visit our website or view a report:

  • Standard log data β€” IP address, browser type, device type, operating system, referring URL, pages visited, and timestamps. This is standard web server data that every website collects.
  • Cookies and analytics β€” We use Google Analytics to understand how people use the site (which pages are visited, how long, where visitors come from). See the Cookies section below for details.

Data we collect through the audit process

When you run an audit, our system crawls and analyzes publicly available information:

  • Your website content β€” landing page, about page, pricing page, and blog (via Firecrawl API)
  • Your social media posts β€” public posts from the X and/or Instagram handles you provide (via Apify)
  • Reddit discussions β€” public posts and comments related to your product category (via Apify)
  • YouTube content β€” public videos and discussions related to your product category (via Tavily)
  • Competitor websites β€” publicly available landing pages, pricing pages, and positioning of detected competitors (via Firecrawl and Tavily)

All of this data is publicly available on the internet. We do not access any private accounts, direct messages, or content behind login walls.

04How we use your data

We use collected data for the following purposes:

  • To generate your audit report β€” analyzing your website, social presence, market positioning, and competitive landscape
  • To deliver paid modules β€” if you purchase a fixkit, we use your audit data to generate marketing assets tailored to your brand
  • To provide report access β€” your report is accessed via a unique URL with a secure token. No login required.
  • To improve our service β€” we analyze anonymized, aggregated patterns across audits to improve the accuracy and quality of our analysis engine
  • To communicate with you β€” only if you provide your email, and only for report delivery, service updates, or responses to your inquiries
  • To process payments β€” transaction handling via Lemon Squeezy

We do not:

  • Sell your data to third parties
  • Use your data for advertising or ad targeting
  • Share your individual audit results with anyone other than you
  • Train AI models on your specific audit data (we use Anthropic's Claude API, which does not retain or train on API inputs per their data policy)

05Third-party services

We use the following third-party services to operate newma. Each processes data as described:

ServiceWhat it doesData it receives
Anthropic (Claude)AI analysis engine β€” generates all audit insightsYour website content, social posts, Reddit/YouTube data, competitor data (sent via API; not retained by Anthropic for training per their API data policy)
FirecrawlWebsite crawlingURLs you submit and detected competitor URLs
ApifySocial media and Reddit scrapingSocial handles you provide; Reddit search queries based on your product category
TavilyWeb, YouTube, and competitor searchSearch queries derived from your product category
SupabaseDatabase hosting (PostgreSQL)All stored audit data
VercelWebsite and application hostingStandard web request data
InngestBackground job orchestrationAudit pipeline task data
Lemon SqueezyPayment processingPayment and billing data you provide at checkout
Google AnalyticsWebsite usage analyticsAnonymized browsing behavior (see Cookies section)

Each of these services has its own privacy policy. We select services that maintain industry-standard security practices and, where applicable, offer data processing agreements compliant with GDPR.

06Report access and security

  • Reports are accessed via a unique, unguessable URL containing a secure token (e.g., newma.com/report/[token]).
  • There is no user account, no login, and no password.
  • Anyone with the report URL can view the report. Treat your report URL like a password β€” do not share it publicly unless you want others to see your audit results.
  • For paid MCP server access, the same token-based URL model applies. Your MCP connection URL is your credential.

07Cookies

Essential cookies

We use minimal essential cookies for basic website functionality (e.g., maintaining your session state during an audit).

Analytics cookies

We use Google Analytics to collect anonymized data about website usage. Google Analytics uses cookies to track:

  • Pages visited and time spent
  • Traffic sources (how you found us)
  • General geographic region (country/city level, not precise location)
  • Device and browser type

You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on or by using your browser's cookie settings.

We do not use advertising cookies, retargeting pixels, or any social media tracking pixels.

08Data retention

  • Audit reports β€” retained for 12 months from creation date. After 12 months, reports are automatically deleted unless you have an active paid subscription.
  • Raw crawl data (website snapshots, Reddit posts, YouTube data) β€” retained for 90 days, then permanently deleted. The audit analysis derived from this data remains in your report.
  • Paid subscriber data β€” retained for the duration of your subscription plus 30 days after cancellation or expiration.
  • Payment records β€” retained as required by applicable tax and accounting laws (typically 5 years under Korean tax law).
  • Server logs β€” retained for 30 days, then automatically purged.
  • Google Analytics data β€” retained according to Google's data retention settings (we use the default 14-month retention period).

You may request early deletion of your data at any time (see Your Rights below).

09Your rights

Regardless of where you are located, we respect the following rights:

  • Access β€” You can request a copy of the data we hold about you.
  • Correction β€” You can request correction of inaccurate data.
  • Deletion β€” You can request that we delete your data. We will comply within 30 days, except where retention is required by law (e.g., tax records).
  • Data portability β€” You can request your audit data in a machine-readable format (JSON).
  • Objection β€” You can object to our processing of your data for any non-essential purpose.
  • Withdraw consent β€” Where processing is based on consent (e.g., analytics cookies, marketing emails), you can withdraw consent at any time.

For EU/EEA users (GDPR)

If you are in the European Economic Area, our legal bases for processing are:

  • Legitimate interest (Art. 6(1)(f) GDPR) β€” for generating audit reports based on publicly available data and for operating our service
  • Consent (Art. 6(1)(a) GDPR) β€” for analytics cookies and optional email communications
  • Contract performance (Art. 6(1)(b) GDPR) β€” for processing paid module purchases

You have the right to lodge a complaint with your local data protection authority.

For California users (CCPA)

If you are a California resident, you have the right to:

  • Know what personal information we collect and how it is used
  • Request deletion of your personal information
  • Opt out of the sale of personal information (we do not sell personal information)
  • Non-discrimination for exercising your privacy rights

For Korean users (Personal Information Protection Act)

Under the Republic of Korea's Personal Information Protection Act (PIPA), you have the right to access, correct, delete, or restrict the processing of your personal information. Send requests to the contact email above; we will respond within 30 days.

To exercise any of these rights, email us at [privacy@newma.com].

10International data transfers

newma's servers and third-party services are located in various countries, including the United States, the European Union, and the Republic of Korea. By using our service, your data may be transferred to and processed in countries outside your own.

Where required (particularly for EU/EEA users), we ensure appropriate safeguards are in place, including standard contractual clauses and reliance on adequacy decisions where applicable.

11Children

newma is not intended for use by anyone under the age of 16. We do not knowingly collect data from children under 16. If you believe a child under 16 has used our service, please contact us and we will delete the associated data promptly.

12Changes to this policy

We may update this Privacy Policy as our service evolves. When we make material changes, we will update the β€œLast updated” date at the top of this page. For significant changes, we will make reasonable efforts to notify users (e.g., a notice on our website).

We recommend checking this page periodically.

13Contact

For any privacy-related questions, data requests, or concerns:

πŸ“§ [privacy@newma.com]

newma is operated by Shookin
Business Registration Number: 641-48-00948
11 Yangjaedae-ro 2-gil, Seocho-gu, Seoul, Republic of Korea

NEWMA β€” PMF AUDIT FOR INDIE BUILDERSv0.1 Β· 2026

newma

Marketing that starts from your customer.

The audit is free and lives at the top of the page. Run it.

Built with Claude. Runs inside Claude, Cursor, ChatGPT β€” wherever you already work.

Β© 2026 newma. all rights reserved.PrivacyΒ·Termsmade by indie, for indie.