─── legal / privacy

Privacy Policy

Last updated: February 2026

1. What We Collect

To operate the Service we collect the minimum information needed:

  • Account data: email, hashed password (bcrypt), optional display name, subscription tier.
  • Usage data: scrape jobs you submit, bandwidth consumed, target zip codes you monitor, IP pivots performed.
  • Billing data: Stripe customer identifier and transaction ledger. Your card number is stored by Stripe, not by us.
  • Technical data: request timestamps, error logs, aggregated latency — retained 30 days.

2. What We Do Not Collect

We do not sell, rent, or share your personal data with advertisers. We do not build behavioral profiles. We do not use third-party ad trackers. We do not read the content of pages you scrape — only the byte count for billing.

3. Cookies & Sessions

We use a single first-party httpOnly session cookie for authentication. This cookie is not readable by JavaScript and is transmitted only over TLS. We do not use analytics cookies without your consent.

4. Third-Party Processors

  • Stripe, Inc. — payment processing; subject to Stripe's Privacy Policy.
  • Upstream proxy providers (BrightData/Oxylabs/Smartproxy) — traffic routing.
  • Public data APIs — NOAA/IEM, San Antonio Open Data, Austin Socrata, Regrid. These receive only your zip queries.
  • OpenAI/Sora — only if you use the Sora Studio module; prompts are transmitted to OpenAI's Sora 2 endpoint via the Emergent Universal Key.

5. Data Retention

Account and billing data are retained for the life of your account plus seven (7) years for tax purposes. Scrape job records and technical logs are retained for 30 days by default. You may request full deletion at any time.

6. Your Rights

If you are a resident of California (CCPA), the European Union (GDPR), or another jurisdiction with equivalent rights, you may (a) request a copy of the data we hold about you, (b) request correction, (c) request deletion, (d) opt-out of any future non-essential processing. Contact privacy@sintinelintel.net and we will respond within 30 days.

7. Security

Passwords are hashed with bcrypt. Session tokens are httpOnly, Secure, SameSite=Lax cookies. All traffic is TLS. We follow least-privilege database access and rotate secrets on a defined cadence. No system is perfect — if you suspect a breach, email security@sintinelintel.net immediately.

8. Children

The Service is not directed to individuals under 18. We do not knowingly collect data from children.

9. Changes

We may update this policy. Material changes will be announced via email to the address on file at least 14 days before taking effect.

10. Contact

Data protection contact: privacy@sintinelintel.net

Made with Emergent