Last Updated March 4, 2026

Privacy Notice

This Privacy Notice describes how Listen LLC ("Listen," "we," "us," or "our") collects, uses, and protects your information when you use Cohorts by Listen at cohorts.listen.codes (the "Service"). By using the Service, you agree to the practices described in this notice.

1. What We Collect

Account Data

When you create an account, we collect your name, email address, and profile picture through Google or GitHub OAuth, or via email signup. We also store organization-level data (organization name, membership roles).

Transaction Data

When you upload CSV files, we store the transaction data you provide, which may include customer identifiers, transaction dates, cart values, and optional segment fields. We encourage you to use anonymized customer identifiers rather than personally identifiable information like email addresses.

Usage Data

We collect information about how you use the Service, including pages visited and features used, through PostHog analytics.

AI Usage Metadata

When you use our optional AI features, we log metadata such as the AI model used, token counts, and timestamps. We do not store the full content of AI responses.

2. How We Use Your Data

  • Provide the Service: Process your transaction data to generate cohort analytics dashboards
  • Process payments: Manage subscriptions and billing through LemonSqueezy
  • Send communications: Deliver service emails (account verification, organization invites) through Resend
  • Improve the platform: Analyze usage patterns through PostHog analytics
  • Optional AI analysis: When you actively request it, send relevant data to OpenAI for AI-powered analysis

3. What We Never Do

  • Sell your data. We will never sell your personal information or transaction data to anyone.
  • Use your data for benchmarking. Your data is never used to create aggregate benchmarks or industry comparisons.
  • Share your transaction data with third parties. Your transaction data is yours alone.
  • Access your dashboards without your permission. Your dashboards are private by default.
  • Use your data to train AI models. Your data is not used to train or fine-tune any AI models.

4. Share Data with Listen

Cohorts includes a completely optional "Share Data with Listen" feature:

  • Off by default. Listen has no access to your data or dashboards unless you explicitly opt in.
  • Dashboard only. When enabled, Listen's investment team can view the analysis dashboard generated from your dataset. They cannot access your raw transaction data.
  • Toggle anytime. You can enable or disable sharing at any time from your dataset settings.
  • Purpose: Listen is a consumer-obsessed venture firm. Shared dashboards help our team understand consumer value dynamics.

5. Third-Party Services

We use the following third-party services to operate the platform. Each has its own privacy practices:

  • Google Cloud (BigQuery): Analytics data storage and processing
  • LemonSqueezy: Payment processing and subscription management
  • PostHog: Product analytics and usage tracking
  • Resend: Transactional email delivery
  • UploadThing: File upload infrastructure
  • OpenAI: Optional AI-powered analysis features
  • Google & GitHub: OAuth authentication

6. Data Storage & Transfer

Your data is stored on US-based infrastructure. Account and organization data is stored in PostgreSQL. Transaction data from CSV uploads is stored in Google BigQuery. We implement standard security measures to protect data in transit and at rest.

7. Data Retention & Deletion

  • Data is retained for as long as your account is active and the Service is being used.
  • Deleting a dataset queues the associated BigQuery data for deletion and cascades the removal of related records.
  • Deleting an organization cascades the deletion of all related data, including datasets and membership records.
  • AI usage logs are retained for service improvement purposes.

8. Cookies & Tracking

  • Session cookies: Used by NextAuth for authentication and session management.
  • Analytics cookies: Used by PostHog for product analytics and usage tracking.

You can manage cookies through your browser settings. Note that disabling cookies may affect the functionality of the Service.

9. Communications

We send service-related emails (account verification, organization invites, and other essential notifications) through Resend. These communications are necessary for the operation of the Service and cannot be opted out of while maintaining an account.

10. Data Security

We implement multiple layers of security to protect your data:

  • Parameterized database queries to prevent SQL injection
  • Organization-scoped access control ensuring users can only access their own data
  • Role-based permissions (member, admin, super admin)
  • Rate limiting on API endpoints
  • HMAC webhook verification for third-party integrations

11. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate personal data
  • Delete your personal data and account
  • Export your data in a portable format
  • Opt out of analytics tracking

To exercise any of these rights, contact us at [email protected].

12. Children

The Service is not intended for users under the age of 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected data from a child under 13, we will take steps to delete it promptly.

13. Changes to This Notice

We may update this Privacy Notice from time to time. When we do, we will update the "Last Updated" date at the top of this page. Your continued use of the Service after any changes constitutes acceptance of the updated Privacy Notice.

14. Contact

If you have any questions about this Privacy Notice, please contact us:

  • Email: [email protected]
  • Address: Listen LLC, 406 N Sangamon, Suite 201, Chicago, IL 60642

Built with <3 by Listen in Chicago, IL.