Privacy & security

What happens to your list, step by step.

You are uploading real people's contact details. This page is the commitment, in plain words, with the timings attached.

On upload
Encrypted and isolated

The file arrives over TLS and is written to storage scoped to your workspace. It is not indexed, sampled or copied anywhere else.

Before verifying
You see the cost first

We count the rows and quote the exact credits. Nothing is charged and no address leaves our system until you confirm.

While verifying
Scoped to your workspace

Rows are processed under your workspace's isolation boundary, enforced by the database itself. No address is added to any shared dataset.

On completion
Results are yours

The full file, a deliverable-only file, a suppression list and a JSON summary of exactly what was counted and charged.

At retention
Automatic deletion

The upload and every results file are destroyed at the end of your retention window. Only the ledger summary survives: counts, credits and timestamps, no addresses.

Any time
Delete now

A control on every list destroys the upload and the results immediately, without waiting for the retention window.

Never sold, shared or rented

Your addresses are not used to build a known-good database, a suppression list, a training set, or any product other than your own results file.

Isolated per workspace

Isolation is enforced inside the database with row-level security, not only by application code — so a bug in a query cannot expose another workspace's data. Results are never pooled or cross-referenced between accounts.

Result reuse, and how to turn it off

If you verify the same address twice inside your retention window we return the stored result instantly. That cache is keyed to your workspace and is never read by another. You can switch it off in Settings, which also deletes what is already stored.

Encryption

TLS in transit and encrypted storage at rest. Provider credentials are sealed with a separate rotating key that is not stored with the application configuration.

Your rights

GDPR and CCPA access, export and erasure requests answered within 30 days. A DPA is available before you upload anything.

Audit trail

Every consequential action — a list started, a file downloaded, data deleted, credits adjusted — is written to a tamper-evident log, so we can answer questions about your data with records rather than recollection.

Subprocessors

We publish the categories of infrastructure we rely on — cloud hosting, transactional email, payments, and the verification providers whose capacity we resell — and notify account owners before any change that affects data handling.

Request a DPA

Tell us the entity name and we will send a countersigned copy. No sales call attached.