Draft privacy notice for legal review. Launch jurisdictions, controller identity and vendor terms must be confirmed before publication.

Privacy, with the research boundary visible.

What we collect

We process the name and meeting context submitted by a customer; legally accessible public professional sources; identity candidates and the customer’s selection; account email, payment references and credit ledger; research questions, product analytics and rights requests.

What reports exclude

Reports must not contain personal phone numbers, personal email addresses, home addresses, data-broker contact records, or sensitive attributes such as health, religion, sexual orientation and political affiliation. Excluded same-name records are reported only as a count, not as descriptions of other people.

Why we process data

Purposes include providing the purchased brief, resolving identity, preventing misattribution, maintaining evidence provenance, fulfilling payments, improving requested research fields, preventing abuse and responding to rights requests.

Sources and processors

Research uses legally accessible public pages, search indexes and official APIs. Service providers may include Supabase for storage and database services, Stripe for payments, Resend for transactional email, Vercel for hosting, Tavily for public search and OpenAI for structured synthesis. Final vendor and international-transfer disclosures require counsel review.

Retention

Reports, research jobs, report feedback and product analytics are normally retained for up to 12 months and are removed by the retention worker. Unpurchased identity sessions expire after 24 hours and are cleared after a short operational window. Credits expire 12 months after grant. Account, payment, accounting and rights-request records may be retained longer where law requires. Verified deletion requests, objections and legal holds take priority over ordinary retention.

Your choices and rights

Depending on location, a person may request access, correction, deletion, restriction, portability or objection to profiling. Submit a request without creating an account at /removal. We verify identity before revealing or deleting data.

Security and contact

Access keys stay server-side, database tables use row-level security, and report links should be treated as confidential. No online service can promise absolute security. Contact zonglin092@gmail.com.