Privacy
First-party data only. Cloudflare sees request metadata as any CDN would.
What we store
- Account email, role, and optional company ownership after a domain-matched claim
- Magic-link hashes that expire in 15 minutes
- Newsletter email + confirm timestamp (double opt-in)
- Reviews and community nominations you publish (and a retraction timestamp if you remove them)
- Daily view and outbound-click counters per company
- Prepaid ad spend, click fingerprints (hash of campaign + IP + UA + day), job apply counts
- Stripe event ids so webhooks are not applied twice. We never see card numbers
What we do not do
- No third-party ad pixels, no Google Analytics, no session replay
- No selling of emails or reviews
- No client-side database SDK
Processors
Cloudflare (hosting, D1, Turnstile). Stripe (payments). Resend (transactional mail) when configured.
LinkedIn and AI Danger Score
Optional LinkedIn sign-in retrieves your app-specific member ID, name and profile photo. We keep these in an encrypted, HTTP-only cookie for 30 minutes. Disconnecting clears this cookie. This connection does not create a site account, request your email or grant posting access, and its access token is discarded after retrieving your profile.
You can choose to include your LinkedIn name and photo when generating a roast. Your submitted public profile link and career information are used to generate the roast with xAI. The resulting score, name, photo, profile link and roast are stored and available at a public result URL. Your app-specific LinkedIn member ID is not included in that result. Posting a result to LinkedIn uses a separate authorization flow.
Retention and deletion
Retract a review or nomination from the company page. Email contact to delete an account or listing you own. Magic links are single-use.