Effective August 10, 2026

Privacy Policy

Prefometry minimizes personal data and keeps tenant evidence private, traceable, exportable, and deletable.

Data we process

We process account identity, organization membership, billing state, submitted public domains, configured brands and prompts, provider responses, citations, Action Packs, and operational audit events.

Public abuse controls store only keyed hashes of network addresses in short-lived rate-limit buckets; raw addresses are not stored in the product database for this purpose.

Purpose and subprocessors

Data is used to authenticate users, run requested collections, preserve evidence lineage, bill accounts, send operational messages, prevent abuse, and support the service.

Optional first-party product analytics is disabled until the visitor allows it through the Cookie Notice controls. Prefometry does not use advertising cookies.

Configured deployments may use Supabase, Hetzner, Cloudflare, Bright Data, OpenAI, Creem, Resend, Google integrations, and configured observability services. Stripe is an optional payment adapter for alternative deployments. Provider prompts contain the configured question and sampling context; OpenAI receives answer text plus the confirmed brand and competitor allowlist for structured extraction with API storage disabled.

The current operational subprocessor list and each service purpose are published on the Subprocessors page. The operator evaluates transfer terms and gives contractual notice of material changes where required.

Retention and control

Result links expire, rate-limit rows are removed after their window, and private raw evidence is retained for 7 days on Free, 90 days on Solo, 365 days on Growth, and 730 days on Agency or Enterprise. Owners can export workspace data and schedule deletion from Settings.

First-party product funnel events are retained for no more than 400 days. They contain event names and account context, not raw prompts, responses, evidence text, customer URLs, or email addresses. Workspace deletion removes tenant-linked events; personal account deletion removes the user identifier.

Deletion immediately makes the workspace read-only, remains reversible for seven days, then cancels linked subscriptions and removes tenant rows and private evidence objects. A non-reversible keyed tombstone records completion without retaining the organization identifier.

Client-encrypted disaster-recovery snapshots are isolated from normal product access and used only to restore the service after an incident. Deleted primary data is scheduled to age out of the 14-daily/8-weekly backup rotation within 70 days; backup failures are monitored, and an incident restore re-applies deletion records before customer access is reopened.

Every member can separately schedule deletion of their personal account. After a seven-day recovery period, Prefometry removes the Supabase login identity, memberships, personal notifications and preferences, pending OAuth state, and assignments while retaining shared workspace evidence for remaining collaborators. The last active Owner must first transfer ownership or schedule that workspace for deletion.

Security and requests

Tenant rows use role-based authorization and row-level security. Sensitive routes verify origin, webhooks verify signatures, and public URL fetching blocks private networks and unsafe redirects.

Contact the operator identified in your order or deployment agreement for access, correction, deletion, objection, or data protection requests.