Privacy

Privacy and data retention

What happens to a file you upload, what we keep afterwards, and what reaches an AI model. Where this describes someone else’s terms it quotes them and links to them, because a summary of a term is not the term.

Your file is not stored

The Pre-Flight Report is written from your upload, and the upload is deleted in the same request that created it. There is no copy on our servers to leak, to hand over, or to forget about.

You can see this from the outside: the file is uploaded again for each step rather than held between screens. That is not an oversight in the design. It is what not keeping it looks like.

What we do keep

Five things, and this is the complete list.

Your account — an email address, and nothing beside it. There is no password: signing in is a one-time emailed link, or Google. If you use Continue with Google, we ask Google for two things and receive exactly two things: your email address, and the permanent account identifier Google uses for you. Not your name, your profile picture, your contacts, or anything in your Google account — we request the openid and email scopes and not the profile scope, which is what the consent screen shows you before you agree. We store that identifier so that a change to your Google email address does not lock you out of your own workspace. We keep no Google token: we ask Google who you are once, at sign-in, and never call Google on your behalf afterwards.

Your Supplier Profiles — column names and the field each one was mapped to. No cell of your data is in them. A profile records that your column called Wholesale holds cost prices; it does not record a cost price. This is the saved work that makes the second file from a supplier one click. There is no delete button for them yet; section 7 is how you have one removed today, and it is done by hand.

One row per free check, so we can count how many files get checked. It holds a random identifier stored in a first-party cookie, a SHA-256 fingerprint of the bytes, and three numbers: rows read, products found, blockers found. The fingerprint is a hash and does not reverse into a file; it is there so that one person re-running one spreadsheet counts once instead of fifty times. No filename, no cell, no column name, no IP address and no user agent is recorded, and there is no third-party analytics or session-replay script anywhere on this site.

The launch list, if you asked to be on it — an email address, whether it has confirmed, and the hash of the one-time token in the confirm and unsubscribe links. Nothing else. It is not joined to the file you checked, or to the report, or to your visit: there is no column that could do it, which is a stronger statement than a promise not to look. Section 9 is what it is for and how to leave.

A daily count of six things that happened on this site — the tool page being loaded, a file being uploaded, a report being produced, an upload being refused, the pricing page being loaded, and an email address confirming that it wants launch updates. It is a date, the name of the step and a number, and that is the whole table: there is no identifier in it of any kind. Not your cookie id, not an IP address, not a user agent, not a page path. We can see that a hundred people loaded the tool and four produced a report; we cannot see whether those four were among the hundred, and we did not build the version that could. It exists so we can tell “nobody arrives” apart from “people arrive and the upload breaks”, which are different problems and were previously the same silence.

What reaches an AI model, and what never does

Only these fields are ever sent, and only for the cells our deterministic checks could not resolve:

Title · Vendor · Type · Tags · Option names and values · Description · SEO title · SEO description · Image alt text

Your cost prices, SKUs, barcodes, supplier identifiers and prices of any kind are never sent to any model. That is enforced by an allowlist in code, which refuses to send a field that is not on the list — rather than by a filter that has to think of everything in advance. The difference matters: an allowlist fails closed on a field nobody thought about.

What does leave is your product titles, descriptions and option vocabulary. We are not going to pretend that is nothing. It is why the rest of this page exists, and why section 5 is a switch rather than a promise.

Our model provider is Google, on paid terms

We use the Gemini API on Google’s Paid Services. Three things follow, and the third is the one most policy pages leave out.

Google does not train on it. Under the paid terms Google does not use prompts or responses to improve its products, and no human reviewer reads them.

Google does log it, for a period Google has not published. The terms say, in full:

“For Paid Services, Google logs prompts and responses for a limited period of time, solely for detecting and preventing violations of the Prohibited Use Policy to maintain the safety and security of the Services, and any required legal or regulatory disclosures. This data may be stored transiently or cached in any country in which Google or its agents maintain facilities.”

Gemini API Additional Terms of Service, effective March 23, 2026. Read 2026-09-06.

“A limited period of time” is not a number, and we are not going to invent one. Google sets that period and does not state it; we do not control it and cannot tell you what it is. What we can tell you is what it is for — abuse detection and legal disclosure — and that it is not training.

It is not confined to the EU. If you are asking whether your catalogue stays inside the European Economic Area, the honest answer is no. Google may hold this data in any country where it operates. That is true of the paid terms we are on, and it would be true of any tier.

If that is not acceptable for your catalogue, switch it off

AI enrichment is a single control on your account page, and it takes effect immediately. With it off, nothing from your workspace is sent to any model — the request stops on our side, before a provider is contacted.

Everything else keeps working exactly as it did. The Pre-Flight Report, the column mapping, the validator and the export never called a model in the first place. Fields that enrichment would have written are simply left blank. You can switch it back on whenever you like.

The free Pre-Flight Report has no path to a model at all. There is nothing to switch off there, because there is nothing to switch.

Your rights, and how to use them

These are your rights whether we list them or not. They are listed because a page that makes you look them up elsewhere is not really offering them.

  • Access. Ask what we hold about you and we will tell you all of it. It is a short answer.
  • Rectification. Correct anything wrong, which in practice means your email address.
  • Erasure. Have your account, your Supplier Profiles and everything joined to them deleted. Your uploaded file is not on the list because it was never stored — that request is already satisfied.
  • Portability. Take your Supplier Profiles with you in a machine-readable form.
  • Restriction and objection. Tell us to stop a particular use while a question is open.
  • Withdraw consent. The enrichment switch, at any time, without explaining yourself. It does not affect anything already run.
  • Complain. To your own supervisory authority. You do not have to come to us first, and we would rather you had both routes than one.

If California law applies to you, the same requests answer the CCPA and CPRA: know, delete, correct, and opt out of sale or sharing. That last one is trivial for us to honour — see the next section, where the answer is that there is nothing to opt out of. We will not discriminate against you for asking; we have no mechanism to, and no interest in one.

Every one of these goes to the same address as section 7 and is done by hand. We are one person, so a request gets a person rather than a queue, and we will not promise a turnaround we have not measured.

What we will never do with it

A privacy page that only describes what a company does leaves the reader to guess at the rest. These are commitments, and each one is checkable against the site rather than taken on trust.

  • We do not sell your data, and we do not share it for advertising. Not for money, not for a partnership, not as an asset in a sale. There is no advertising network anywhere on this site, which is checkable from your own browser in about ten seconds.
  • We do not train models on your catalogue. Not our own, and the one provider that sees any of it is on terms that forbid it training on ours — quoted and linked in section 4 rather than summarised.
  • We do not build a profile of you. We record no IP address, no user agent, no page path and no session replay. There is nothing to profile with.
  • We do not run third-party scripts. The page where you upload a file containing supplier cost prices is the last page on the internet that should be running somebody else’s JavaScript.
  • We do not read your catalogue ourselves. There is no internal tool for browsing customer files, because there are no customer files.

The launch list, and how to leave it

After a Pre-Flight Report has rendered, we offer to tell you when checkout opens. It is optional, it is below an answer you already have, and skipping it costs you nothing — the report is free, needs no account, and is never held back for an address.

Nothing is sent to an address that has not confirmed. You type an address, we send one mail with a link, and until that link is clicked the address is a pending row and not a subscriber. Anyone can type anyone’s address into a public form, so a typed address is not evidence that its owner wants anything.

What we store is the address, whether it confirmed, and a hash of the one-time token in the confirm and unsubscribe links. There is no column joining it to a file you checked, to a report, or to the free-check count — not a setting, a missing column. Every mail we send carries an unsubscribe link, and following it removes the address on the way in: no sign-in, no confirmation step, no offer to send less instead. An unsubscribe that asks a question is a dark pattern, and we publish a refusal of that exact pattern.

The launch offer is 50% off the first month of a subscription, and subscribers hear first when checkout opens. The list is used for that and for nothing else. It is never sold, rented, or shared — section 8 covers that and it covers this too.

Cookies, and why there is no banner

We set three, all first-party, all HttpOnly so no script can read them, and all strictly necessary to something you asked for. That is the complete list, generated from the code that sets them rather than written out here.

ir_session
Keeps you signed in. There is no password, so this is the whole of your session. Lasts 30 days, and is set only if you start that flow.
ir_visitor
A random identifier that counts your free checks, so one file re-run five times counts once. It is not linked to you and holds nothing about the file. Lasts 1 year.
ir_oauth
Carries the one-time values that prove a Continue with Google round trip came back from the same browser that started it. Set only if you click that button. Lasts 10 minutes, and is set only if you start that flow.

None of them needs your consent, so you are not asked for it. A cookie required to deliver what you requested is exempt, and we have no others — no analytics, no advertising, no measurement. A banner here would be theatre: it would ask you to approve something we are not doing, train you to click through the next one, and leave you no better informed.

This is not a stance we can quietly drop. Adding a cookie that needs asking about changes the sentence above automatically, and a test in our build refuses to ship a page whose cookie list disagrees with the code.

Where in the world this happens

The server is a machine we rent in Falkenstein, Germany. Your account, your Supplier Profiles and the per-check counts are on that disk and nowhere else. We are not a company with regions and a routing policy; there is one server.

What leaves it, and where it goes:

Google (Gemini API)
Any country in which Google or its agents maintain facilities. Their terms offer no regional confinement and we do not imply one. Enrichment, on Paid Services terms.
Google (Sign-in)
United States, and wherever Google operates. Continue with Google, if you use it.
Cloudflare
United States. The archives are encrypted before they leave this server. DNS, and encrypted offsite backups in R2.
Resend
United States. Transactional email.
Hetzner Online GmbH
Germany (Falkenstein, Saxony). Inside the EU. The server this runs on.

Some of that is a transfer outside the EEA, and we are not going to bury it. Those transfers rest on the European Commission’s Standard Contractual Clauses in each provider’s own data-processing terms, and on the EU–US Data Privacy Framework where the provider is certified under it. We did not negotiate those terms; we accepted them, which is what a one-person business does, and saying so is more useful to you than implying we have leverage we do not have.

The switch is how you opt out of all of it. Enrichment is the only path that sends a cell anywhere, it is a single control that takes effect immediately, and with it off the request stops on our side before a provider is contacted — section 5. On a paid workspace it starts on, because it is the feature the plan is sold for; the free report never reaches a provider either way.

References

Read on 2026-09-06. Terms carry effective dates and these will change; where they do, this page is wrong until it is corrected, and correcting it is our job.

Asking us about your data, or asking us to delete it

Write to [email protected]. A person reads it. There is no ticket form and no separate privacy address to remember — one inbox, monitored.

What we can do from that email: tell you everything we hold that is connected to you, delete your Supplier Profiles, correct your email address, or close your account and remove it all. Today every one of those is done by hand rather than by a button, so say which one you want and we will do it and confirm when it is done.

Your uploaded file is not on the list, because there is nothing to delete. It never reached our storage — section 1. A deletion request for it is already satisfied.

And one thing we honestly cannot do, which we would rather say here than in a reply to you: the per-check row from section 2 is not linked to your identity. It holds a random cookie identifier and a hash, and there is no column in it that says who you are — so we cannot find yours to show you, and we cannot find yours to delete. That is a consequence of collecting as little as possible, not an excuse for keeping something back. If you clear the ir_visitor cookie in your browser, the link between that identifier and your next visit is gone at your end too.

We are not going to promise a turnaround time we have not measured. It is one inbox read by the person who built this, and it gets answered.

Last updated 9 September 2026 · last reviewed 9 September 2026 against the running product. This page describes the product as it is built today, not as it is planned. If a future feature stores an upload, this page changes before that feature ships.