What we keep, and who sees it.
Niche Heist is a one-person tool built by Neil Busque. It holds very little about you, and this page says exactly what that is in plain words. No cookie banner, because there are no cookies.
Last updated August 11, 2026
What we collect
Only what you type into the one form on the front page, plus what the report itself produces:
- Your email address. It is how we send you the link when your report finishes, and it is prefilled into checkout so you do not type it twice.
- Your niche and the three Instagram handles you entered. These are the inputs to the report. The handles are other people's public business accounts, not yours.
- Anything you put in the optional box. The one-line description of your business and the true stories or numbers you offer up. This is optional, it is only used to write your 30-day calendar, and whatever you put there is stored with your report.
- The report we generate. The scraped public post data, the transcripts, the extracted formula and the calendar all live on your report row.
- Your IP address, for rate limiting only. Every successful free preview writes one row holding your email and your IP address, so the limits (2 previews per email per week, 5 per connection per day) can be enforced. That row is not used for anything else, and it is never joined back to your report content.
There is no account, no password, and no profile. We never ask for your Instagram login and we could not use it if you gave it to us.
Your report link is unguessable, not private
Your report lives at a web address ending in twelve random characters. Nobody can guess it and it is not listed or linked anywhere. But it is not behind a password either, so anyone you send the link to can open it, and so can anyone they forward it to. We say that plainly rather than let you assume otherwise. If your optional business notes are sensitive, leave that box empty.
Who else touches it
A short list, and this is the whole list. Each one only receives the part it needs:
| Who | What reaches them |
|---|---|
| Supabase | Stores everything above, in a dedicated database on Amazon Web Services. Row level security is on and there are no public policies, so the database is reachable only by this app's server. |
| Vercel | Serves the site and runs the report pipeline. |
| Scrape Creators | Receives the competitor handles and the niche search terms, and returns public Instagram post data and transcripts. Your email and your business notes are never sent there. |
| DeepSeek | The AI model that reads the scraped posts and writes the formula and calendar. It receives your niche, the scraped public post data, and, if you filled the optional box, your business description and stories. Your email is never sent there. |
| Stripe | Takes the $39 payment on its own hosted checkout page. Your card details go to Stripe and never to us. Stripe tells us which report was paid for and gives us a session id, nothing more. |
| Mailgun | Delivers the one email that tells you your report is ready, or the one that tells you it failed. |
| Sonar | Counts visits. It is ours, described in full below. |
One more thing worth saying out loud: when a report sells or fails, the system emails Neil so a human knows. That alert contains your email address, your niche and your report link. It goes to one personal inbox and nowhere else.
How we count visits
We count visits with Sonar, an analytics tool Neil wrote and runs on his own server. There is no Google Analytics here, no advertising pixel, and nothing about your visit is sold, rented or handed to anyone else.
It keeps one thing on your device: a random ID stored in your browser under the name sonar_pid. It is 28 random characters generated on your first visit. There is no name in it and no email. Its only job is to tell us that whoever is reading this is the same person who clicked one of our links a week ago, so we can tell which of those were worth doing. It stays until you clear it, which makes it a persistent identifier. This site used to say “cookieless, no consent banner needed” and that stopped being true when the ID was added, so we changed it rather than let the word do quiet work for us.
Alongside it we record the address of the page you opened, the site or ad you arrived from, any campaign tags on that link, your country, and the broad type of device, browser and operating system you use. Your IP address is used for an instant to build a scrambled fingerprint that changes every day, which is how we count you once instead of six times. That IP is not stored by Sonar.
If you would rather not be counted
Open your browser console on any page here and run localStorage.setItem('sonar_ignore', '1'). We will skip that browser from then on. Clearing this site's data from your browser removes the random ID too.
How long we keep it
Honestly: until you ask us to delete it. Reports are kept so your link keeps working, and nothing here expires or is purged on a schedule. If that changes we will say so on this page before it happens, not after.
Deleting your data
There is no delete button, because there is no account to log into. Email busqueneil@gmail.com from the address you used, or send us the report link, and your report and its rate-limit rows are removed by hand. Ask for a copy of what we hold on you the same way. You will get a real person, because there is only one.
Two things survive a deletion. Stripe keeps its own record of the payment, because that is a financial record we do not control and are not allowed to erase. And if you asked us to stop emailing you, we keep your address on the do-not-email list, because deleting that would quietly opt you back in.
What we never do
We do not sell your data. We do not run ads. We do not add you to a marketing list because you bought a report. We do not train anything on what you wrote in the optional box. We do not let an outside analytics or advertising company watch what you do here.
Contact
Questions about any of this, or about a report: busqueneil@gmail.com.