Privacy Policy

Your source analysis data is not sent to our server. This page explains operational data collection and browser storage.

Account service emails and temporary checkout storage

When email delivery is available, account-linked live purchases receive order, amount and access-period notices at the registered email. You may also request a one-time sign-in link. Review and expiry reminders require separate optional consent, which you can disable in the archive. Emails exclude memo contents and CSV data. The delivery queue retains only account, order or memo identifiers, schedules and delivery state for duplicate prevention while the account exists. Sign-in link records are hashed and valid for 10 minutes. Email provider, location and retention details are described in the international-processing section below. Clicking Pay temporarily saves your current work only in this browser. The copy is deleted after restoration or during the next cleanup after 24 hours. Clear all and turning device storage off also remove these temporary copies.

Service email provider and international processing

We use Resend (Plus Five Five, Inc.) to deliver service emails. At each send request, an encrypted TLS HTTPS connection transfers the recipient and sender email addresses, subject, message body (order ID, amount, access period or a one-time sign-in link), and delivery identifier. CSV data and decision memo contents are excluded. Sending is routed through Tokyo, Japan (ap-northeast-1), while message contents, delivery logs and account records are stored in the United States. Selecting Tokyo does not mean storage in Japan.

On standard plans, emails and logs are retained for 30 days and backups for 7 days. Remaining customer data is deleted within 90 days after the Resend service agreement ends. These periods are separate from statutory payment-record retention and the application delivery queue. Disable optional reminders in the archive or request that email processing stop or data be deleted through Contact. If you do not want email processing, email sign-in and notifications are unavailable, and you may request account deletion. Anonymous CSV analysis remains available. See Resend's data protection information for provider processing and deletion details.

Account decision storage (when available)

If you choose Google sign-in, we use your stable Google account identifier and verified email for identification, pass linking and one 7-day trial per account. The trial starts when explicitly requested during the first project or review save and does not charge automatically. Decision memos you review and select (action, conclusion, hypothesis, review date, review notes, target design, selected evidence summaries and observations) are stored on the server. Memos may include campaign names or figures you entered. Source CSVs, analysis datasets and local snapshots are excluded. Saving Pro column mappings stores only header names and field rules in the same account for reuse with CSV and Google Sheets on other devices. Source rows, value profiles and filenames are excluded. Delete individual or all rules in My account; reading, exporting and deleting remain available after expiry. Account deletion also deletes its mappings. Saving a Pro analysis setup by name stores only the tool, the setup name and the chosen setting words in the same account so you can load it on other devices. Settings containing data values (such as “Analyze Meta only”), source rows and file names are not included (if you split by a column you have not mapped, that column name is included). You can delete setups one by one or all at once in My account; they remain viewable, exportable and deletable after the pass expires, and are deleted with the account. When you choose a source data currency (KRW or USD) while signed in, only that choice is stored in your account and used as the default on other devices. No amounts or file details are included, and it is deleted with the account. Account memos are separate from the 90-day device policy and are not deleted merely because a pass expires. Delete individual memos in the archive or request account deletion through Contact. Account identity, email and trial-start records are retained while your account exists. Sessions are valid for 30 days; pending login information is valid for 10 minutes. Marketing consent is collected separately through newsletter signup. Railway hosts the account service; the operational PostgreSQL database is in Amsterdam, Netherlands (EU West). Account information and selected memos are processed when you sign in or save to your account, with retention and deletion governed by this section. Google sign-in information is subject to Google’s worldwide processing and retention policies. We request only openid and email permissions and send no CSV data or decision memos to Google. If you do not want account processing, do not use sign-in or account storage; anonymous analysis remains available. Saving reviews, including local review storage, requires sign-in.

Report-pass payments and recovery

To process purchases, refunds and access recovery, the server stores the order ID, product, amount, approval/cancellation status, access term and a hash of the recovery code. NICEPAY payment requests also include the signed-in account email to identify the transaction. Payment details are entered and processed on the selected payment provider’s screens (NICEPAY or Toss Payments); the app does not store full card numbers or passwords. Payment and supply records are retained for the statutory five-year period, separately from the 90-day browser analysis-data policy. Access recovery uses a cookie and a local entitlement cache. CSV files, analysis results, project names and filenames are never included in payment requests. Contact customer service below to request access, correction or deletion; statutory retention requirements may limit deletion during that period.

Uploaded data

CSV files and source analysis rows are processed in your current browser and are not transmitted to or stored on our server. Source data uploaded for analysis is not collected in an application-side database.

Information stored in your browser

For convenience, this device may retain theme, language, display preferences, column-mapping recipes, and recently connected public Google Sheets URLs in localStorage or IndexedDB. With active Pro access (including the 7-day trial) and device storage enabled, source CSV/XLSX files you upload yourself, their file names, headers and mappings, plus decision-record summaries are kept in this browser's IndexedDB/localStorage until 90 days after their last use. Free analysis alone does not automatically retain new analysis files on this device. Source files are never sent to our server. Turning storage off immediately removes stored source files and the persistent copy of decision records; the current session can remain visible until you refresh or close it. Use Stored on this device to remove one file, remove all files, or change this setting.

External requests from advanced analysis

Some tools' advanced analysis (regression, Random Forest, MMM challenger) downloads the WebR runtime and R packages from an external CDN so R code can run in your browser. Only those file requests leave your device — your uploaded CSV, column mapping, and results are never transmitted. All computation finishes inside this browser. If you would rather avoid the external requests, simply do not run advanced analysis; the standard analyses work without them.

Analytics and advertising

Google Analytics, Google Tag Manager, and Google AdSense may process cookies, device identifiers, and visit information. This processing is subject to Google's policies and your browser and consent settings.

Regardless of your region, you can turn visit analytics and ad measurement off below. The choice is stored in this browser and does not affect how the analysis tools work.

Analytics and ad measurement are on

Stored in this browser only. It does not affect the analysis tools or CSV processing.

Email subscriptions

If you subscribe and consent to receive emails, Buttondown processes your email address, consent version, and signup source. We use it only for new posts and analysis insights. You can unsubscribe through the link in each email. Source analysis data is never sent to the subscription service.

Contact

Send privacy requests through the Contact page or email gondry.montauk@gmail.com.