Privacy
Personal data is hashed by default.
The API is built to decide on weak signals, not to collect personal data. What we receive is hashed unless a plan explicitly opts into raw PII.
What we receive
By default, subject fields (email, IP, user agent) are sent as SHA-256 hashes and the API returns verdicts, not profiles. Raw PII is accepted only on the Pro plan and up, and never stored beyond the retention window of the plan.
Retention
Free: 30 days. Pro: 90 days. Design Partner: negotiated. Event data is retained to close the feedback loop (what happened after the verdict), which is what makes the product improve.
Site visitors
We do not track, analyze, or advertise on site visitors: no visitor analytics, no ad scripts, no third-party trackers. The footer promise is the policy.
Usage data
Metering counts verify events per account for billing and the usage dashboard. It is product usage, not visitor tracking, and it is never shared.
Auth and billing
Sign-in is handled by Clerk, which stores your account credentials under its own privacy policy. Payments run through Stripe; we never see or store card numbers.
Questions: privacy@chitmark.com.