Privacy, with the research boundary visible.
Effective date: August 13, 2026.
What we collect
We process the name and meeting context submitted by a customer; legally accessible public professional sources; identity candidates and the customer’s selection; account email, payment references and credit ledger; research questions, product analytics and rights requests. We also process a pseudonymous hash derived from request network information for abuse prevention and rate limiting; raw IP addresses are not stored in the application rate-limit table.
What reports exclude
Reports must not contain personal phone numbers, personal email addresses, home addresses, data-broker contact records, or sensitive attributes such as health, religion, sexual orientation and political affiliation. Excluded same-name records are reported only as a count, not as descriptions of other people.
Why we process data
Purposes include providing the purchased brief, resolving identity, preventing misattribution, maintaining evidence provenance, fulfilling payments, improving requested research fields, preventing abuse and responding to rights requests.
Sources and processors
Research uses legally accessible public pages, search indexes and official APIs. Service providers include Supabase for database and storage services, Stripe for payments, Resend for transactional email, Vercel for website and API hosting, Railway for the persistent research worker, Tavily for public search and OpenAI for structured synthesis. Provider availability and processing locations may change as the service evolves.
Retention
Reports, research jobs, report feedback and product analytics are normally retained for up to 12 months and are removed by the retention worker. Rate-limit records are normally removed within two days. Unpurchased identity sessions expire after 24 hours and are cleared after a short operational window. Credits expire 12 months after grant. Account, payment, accounting and rights-request records may be retained longer where law requires. Verified deletion requests, objections and legal holds take priority over ordinary retention.
Your choices and rights
Depending on location, a person may request access, correction, deletion, restriction, portability or objection to profiling. Submit a request without creating an account at /removal. We verify identity before revealing or deleting data.
Security and contact
Access keys stay server-side, database tables use row-level security, and report links should be treated as confidential. No online service can promise absolute security. Contact zonglin092@gmail.com.