Privacy Policy
What we collect, what we never touch, who processes it, and how to get it deleted.
Overview
This Privacy Policy explains what personal data ConflictScore ("we", "us") — operated by [COMPANY LEGAL ENTITY] — collects when you use the Service, what we deliberately do not collect, who processes it on our behalf, how long we keep it, and the rights you have over it.
The short version: we collect your email address to run your account, minimal usage data to keep the Service working, and nothing about your payment card — that never touches our systems.
What we collect
- Account data — your email address (used for passwordless one-time-code sign-in; we never store passwords), your user identifier, and if you set one, a display name.
- Subscription state — your plan tier, billing status, and identifiers that link your account to your Stripe customer record (never card details).
- Usage data — which pages and features you use, timestamps, and basic technical request data (browser type, approximate request origin) needed to operate and secure the Service.
- Communications — if you email us (support, corrections, data requests), we retain the message thread.
We do not sell personal data, and we do not run advertising trackers.
How we use data
We process personal data to: operate and provide the Service; create and secure your account; manage subscriptions and billing (through Stripe); deliver transactional email (through Resend); diagnose problems and improve the Service; prevent abuse and fraud; and comply with law. We do not use your data for third-party advertising.
Third-party processors
We use a small number of processors to run the Service. They process personal data on our instructions, and their own privacy policies describe their practices in detail:
- Stripe — payment processing and subscription state (card data is captured on Stripe’s systems, never ours): https://stripe.com/privacy
- Supabase — authentication and hosting of our application database, including your account row: https://supabase.com/privacy
- Resend — delivery of transactional email (sign-in codes, billing notices): https://resend.com/privacy
Our public-data pages (scores, trades, methodology) also link to government sources — the House Clerk, the Senate, SEC EDGAR, and congress.gov. Visiting those sources is subject to their own terms and policies.
Data retention
Account data (email, subscription state) is kept while your account is active. If you ask us to delete your account, we delete the associated personal data within 30 days, except where we must keep it longer under law or for legitimate disputes, and except that backups (rolling, roughly 30 days) may retain copies until they age out.
Billing records are retained as long as tax and accounting rules require (typically several years); those records live in Stripe’s systems under Stripe’s own retention policies. Operational logs (pipeline runs, error logs) are kept on the order of 90 days.
Your rights
You may ask us to: give you a copy of the personal data we hold about you (access); correct inaccurate data; delete your data (subject to the retention rules above); export it in a portable format; and object to or restrict certain processing.
To exercise any of these, email [PRIVACY_EMAIL] from your account’s address so we can verify you. We respond within 30 days. There is no self-serve account-deletion button yet — email us and we will handle it (draft: consider adding self-service deletion).
Children’s privacy
The Service is not directed at children under 13, and our Terms require users to be at least 18. We do not knowingly collect personal data from children under 13. If you believe a child has provided us personal data, contact [PRIVACY_EMAIL] and we will delete it.
Security
We use transport encryption (TLS) for all traffic; database access is protected by row-level security so users can only read their own account rows; privileged (service-role) keys are held server-side only and never shipped to the browser; payment data is isolated entirely inside Stripe; and we keep access to production systems limited. No security measure is perfect, and we cannot guarantee absolute security, but we design so that the most damaging classes of data (card numbers) never exist on our systems at all.
International visitors
The Service is operated from the United States and our processors are global. If you access the Service from outside the U.S. (for example the EU/EEA, the UK, or California), additional or different rights may apply to you under your local law, and you can exercise them by contacting us at [PRIVACY_EMAIL].
We will update this section — and our processor agreements — as needed to honor those rights.
Changes to this policy and contact
We may update this Privacy Policy as the Service evolves. For material changes we will notify you by email or a notice in the Service before they take effect. The "Last updated" date at the top reflects the current version.
For any data request, correction, or question: [PRIVACY_EMAIL].
Data requests and privacy questions: [PRIVACY_EMAIL].
See also: Terms of Service · Disclaimer