Actuary

Data practices

What we store, and what we refuse to.

No cookies, no identifiers, nothing written to your device at all. What follows is the complete list of what we hold — not a summary of a longer list kept somewhere else.

What we store

From the forms

Whatever you type into them: your name, your email, and the free text. If you sign up for alerts we also keep what you asked to be alerted about, whether you have confirmed yet, and two long random links — one to confirm, one to unsubscribe.

From tenants

Just the score itself and a few short labels around it. Never your prompts, never the model’s outputs, and never anything belonging to your users.

We keep it so we can get you set up and send the alerts you asked for. It lives in a single Postgres database in the EU, encrypted at rest.

Retention

Deleted when you ask, and eventually even if you don’t.

If you enquired and nothing came of it, we delete that record whenever you ask, and automatically after twelve months of silence. Unsubscribing stops the email at once; we keep the dormant record only so that we remember not to write to you again, and we delete that too on request. Your scores can be exported and then deleted whenever you want. Your data is never part of the public record.

Measurement

We measure two things, and neither of them can identify you.

The counter is one endpoint on our own server: an event increments a single integer in a bucket for that day, so what is stored cannot describe a person even in principle. Page views and explicit, metadata-only interactions go to a hosted product, PostHog, reached through a path on this origin — no other host receives a request from your browser, and no other host is permitted by the policy that governs what this page may load. Neither measurement sets a cookie or writes anything to your browser’s storage.

What is counted

Named browser interactions, from a fixed list written out in the counter’s source: whether the demo was broken, how far the methodology page was read, which call to action was clicked, and one coarse page category per load. When a form row is stored, the server increments a separate server-only success bucket. PostHog receives one page view per load, named interactions, the type and fixed id of clicked controls, same-site destination paths, form kind and a fixed form-placement id for submission attempts and stored conversions, and browser or resource failure occurrences. It receives no field values, email addresses, element text, or rejection values. The page view also carries the page’s address, the site that linked you, and your browser, operating system and screen size. PostHog is sent your IP address to place the view in a country, and is configured to discard it rather than keep it. Confirmation and unsubscribe capabilities are removed from the browser address before analytics starts.

What is not counted

Returning visits, still. The analytics client keeps its identifier in memory alone, so it is gone when the page closes and the next visit arrives a stranger: our own dashboard cannot tell one reader from two. We would rather have the gap in our numbers than the identifier on your device.

Where: the counter’s tallies in the same EU Postgres instance as everything else; page and interaction analytics in PostHog’s EU region.

Erasure

Asking us to show you, or delete, what we hold.

Send the request through the intake form — it reaches a person directly, and today that person is the one who built this. Say what you would like us to do, and we will confirm in writing once it is done. If you would rather have a named contact address than a form, tell us and we will publish one.