Privacy notice

Clear data boundaries for an early product.

Effective: September 1, 2026. Replace the operator identity and contact details before launch.

Information we process

Account identity and session data; workspace name and company ranges; vendor URLs, spend, quantity, renewal dates, and notes you enter; normalized public-page content and changes; audit request details; subscription identifiers from Stripe; alert destinations; and minimal first-party product events. We do not intentionally collect payment card numbers.

Why we process it

To provide monitoring, contextualize potential exposure, send requested alerts, operate billing, prevent abuse, improve activation and reliability, and respond to support or audit requests.

Analytics

The app records a small allowlist of acquisition, activation, and conversion events. It does not store raw IP addresses for analytics and respects the browser Do Not Track signal. Abuse prevention uses a salted one-way IP-derived identifier.

Service providers

Depending on configuration, data may be processed by Render and PostgreSQL hosting, Stripe, Resend, Slack, and Groq. AI classification is optional and receives a bounded normalized diff and vendor context—not credentials or full raw HTML. Groq requests carry only the bounded diff and vendor context shown above.

Retention and control

Deleting a vendor removes its associated snapshots and change events. Pricing history published as a verified public dataset is independent of customer-private records. During the pilot, contact the operator to request account export or deletion.

Security and transfers

We use access controls, encrypted secret fields, secure cookies, signed webhooks, request limits, and transport encryption. No internet service can promise absolute security. Hosting and subprocessors may process data in the United States.

Contact

Before launch, replace this section with the legal operator name, mailing address, privacy email, and any jurisdiction-specific disclosures required for your customers.