# Privacy Policy

> Canonical: https://discry.ai/legal/privacy · Markdown mirror: https://discry.ai/legal/privacy.md

Effective 2026-09-22 · Version 1 · Version tag 2026-09-22.1

Operator: Discry LLC, a New York limited liability company. Legal contact: legal@discry.ai.

**Defined terms used.** This policy defines **Controller**. It uses Discry, Site, Scan, Directory, Index, Band, Fix Kit and Account as defined in the Terms of Use; Order and Deliverables as defined in the Fix Kit Terms; Correction Request and Takedown Notice as defined in the Directory and Benchmark Policy; and Index Data and Badge as defined in the API, MCP and Data License Terms. The role labels in section 2.1 (Visitor, Scan submitter, Account holder, Purchaser, Waitlist applicant, Handoff recipient, Listed-company representative, Machine client) describe who this policy is talking about and are used in this policy only. This policy is a notice incorporated by the Terms of Use. Disputes about it are governed by Terms of Use §14.

## 1. Who is responsible for your data

1.1 The **Controller** of the personal data described in this policy is Discry LLC, a New York limited liability company, with its office at 418 Broadway, Suite 10855, Albany, NY 12207. "We" and "us" in this policy mean the Controller. Discry has the meaning given in the Terms of Use; where this policy says Discry holds, sends or deletes data, it means the Controller.

1.2 The contact person for privacy matters is Ben Gibert, reachable at legal@discry.ai. Write to that address for every request, question or complaint under this policy. The address hello@discry.ai is a commercial enquiry address and is not monitored for privacy requests.

1.3 Discry has appointed no data protection officer; none is required for processing of this scale and nature. Discry has not appointed a representative in the European Union or the United Kingdom under Article 27 of the GDPR or UK GDPR. If you are in the EU or UK, contact the Controller directly at the address in 1.2.

1.4 Discry LLC has no parent or affiliate companies as of the Effective date; its sole member is a natural person. It is operated by the Controller alone and shares no data with any other company.

## 2. Who this policy covers

2.1 The Site at https://discry.ai is used by several kinds of people, and the data we hold depends on which you are. The sections below refer to these roles:

- **Visitor**: anyone who loads a page.
- **Scan submitter**: a visitor who submits a URL to the free Scan, with or without an email address.
- **Account holder**: someone who signs in with GitHub, Google or an emailed magic link.
- **Purchaser**: someone who buys a Fix Kit.
- **Waitlist applicant**: someone who joins the Fix Kit or repo product waitlist.
- **Handoff recipient**: a person whose email address a Purchaser nominates to receive a Fix Kit.
- **Listed-company representative**: a person who works for or represents a company whose API appears in the Directory.
- **Machine client**: a program, agent or crawler that calls a machine surface such as `/api/v1/*`, `/api/mcp`, `/api/index.csv` or a Badge.

2.2 The Directory publishes scores, bands, evidence and reasons about **companies and their APIs**, not about people. Scan evidence is fetched public documentation. Where a fetched document contains a person's name or contact details (for example an author line), that fragment can be stored in scan evidence and, in short excerpts, displayed. The source of any such data is the publisher's own public website or repository, not the person; we obtain it by fetching the documentation, and this policy is the notice about it (section 6.1). Section 10 explains the rights that apply.

## 3. What we collect, where it comes from, and why

3.1 **Visitors.** We collect no cookie, local storage key or persistent identifier from a visitor who does not sign in. Two things happen server-side on every request: our hosting provider records the request in its logs (section 4.1), and our own telemetry records the request's route class and user agent (section 4.2). Our analytics provider receives cookieless page events (section 5).

3.2 **Scan submitters.** When you submit a URL, we store the domain, the Scan result and its status, and, if you enter one, your email address, in our `scans` table. If you enter an email address on a result page, an `email_captured` event stores that address a second time, both in a dedicated column and inside the event properties. Purpose: to run the Scan, to show you the result, and to email you the top fix when at least one task failed. Providing an email address is optional; without it you still see the result on the page but receive no email.

3.3 **Account holders.** Sign-in offers GitHub, Google or a magic link; there are no passwords. We request no scopes beyond the provider's default sign-in grant. That default grant delivers your email address, display name, avatar URL and the provider's user ID for you, which our auth provider stores in your account's user metadata; our own code reads none of it beyond your user ID and email address. Submitting an email address for a magic link can create an Account if none exists. Your session is held in first-party authentication cookies set by our auth provider; they last 30 days from your last visit, and the Account page has a "Sign out" control that clears them. When you claim a Scan, we store your user ID, the slug and the time, up to 25 claims. Purpose: a signed-in Account that keeps the Scans you claim (performance of the Terms of Use).

3.4 **Purchasers.** A Fix Kit checkout runs on a page Stripe hosts for Sold through Link, LLC, the merchant of record (section 7.2). That page collects your name, billing address, email address and payment details; your name and address are always required because tax depends on them. You give your payment details to Stripe and Link, not to us. Stripe shares your order data with us, and we store the Stripe session, payment-intent and refund identifiers, your user ID where you are signed in, the target slug and domain, the price version, and payment, delivery and refund timestamps. The run record stores your email address in clear text, a hash of your delivery token (never the token itself), the evidence used, and any internal failure code. Purpose: to take payment for, generate, deliver, refund where due and, on request, confirm your Order (performance of the Fix Kit Terms), and to keep the transaction record tax and accounting law require. Link issues receipts.

3.5 **What we send to the model provider.** Generating a Fix Kit sends the target's public documentation, its scan provenance and failures to the Anthropic API. The prompt does **not** contain your email address, name or account identifier. Anthropic also runs the comprehension tasks of every Scan, on the fetched public documentation only, as section 7.1 records.

3.6 **Waitlist applicants.** The waitlist stores your email address, the gate you joined through, the domain, the Scan it relates to, the time, and, for the repo product, your stated primary need and any resource URL. The repo waitlist rejects personal-email domains and requires a work address. The same submission writes a `repo_waitlist_joined` event carrying the same fields. Purpose: to confirm your place and to contact you about the product you asked about (steps taken at your request before a contract).

3.7 **Handoff recipients (data we did not get from you).** A Purchaser may enter a third party's email address to have a Fix Kit shared with them. We use that address once, to send the email "A Discry fix pack for {slug} was shared with you". The send is rate limited per purchase. Source of the data: the Purchaser, not you. Purpose: to deliver the Purchaser's Deliverables to the person they chose (our legitimate interest in delivering what the Purchaser bought; you can object under section 10). Our email provider processes the address to deliver the message.

3.8 **Listed-company representatives.** We hold no dedicated record about you. If you write to us about a listing, we hold your correspondence. If your name appears in fetched documentation, section 2.2 applies.

3.9 **Machine clients.** Every MCP tool call writes an `mcp_tool_call` event recording the tool name and the caller's full arguments. If your agent passes personal data in a tool argument, we store it there. Machine surfaces have no authentication, API key or rate limit.

3.10 **Legacy records.** A `subscriptions` table holds Stripe identifiers for the retired Defend plan, kept for historical orders only, and a legacy `artifacts` table holds generated file content from earlier Scans.

3.11 **What we do not collect.** No table stores an IP address and no code path writes one. We collect no sensitive personal information in the CPRA sense and no special-category data in the GDPR sense; we do not ask for any special-category data and do not use any that a Machine client sends. Card details go to Stripe (3.4).

3.12 **Fonts.** The Site serves its typefaces from its own domain, so loading a page contacts no third-party font host.

## 4. Server logs and agent telemetry

4.1 **Hosting logs.** The Site runs on Vercel, whose serverless functions record request logs as part of hosting. Those logs are held by Vercel under its own retention settings; we do not extend them or copy them into our database.

4.2 **Agent telemetry.** Our middleware writes an `agent_hit` event for every request that is not a static asset or one of our own beacon endpoints, recording a user-agent class, a route class, the request path truncated to 200 characters, the raw user-agent string truncated to 160 characters, and the sample rate. No IP address is stored. Telemetry never blocks a request; if the write fails, the request proceeds. Purpose: to measure which kinds of agents and crawlers consult the Index and which routes they use (legitimate interest, section 6). Source: the request itself.

## 5. Analytics: PostHog in cookieless mode

5.1 PostHog is our only analytics provider. There is no Google Analytics, Google Tag Manager, Meta pixel or advertising tag on the Site.

5.2 PostHog runs **without cookies and without persistent identifiers**: its state is held in browser memory only, and it writes no cookie, local-storage or session-storage key. Each page load starts fresh, so PostHog cannot recognise you across visits. Session replay is disabled: no recording of your screen, clicks or typing is made. Autocapture is off. Query strings and hash fragments are removed from the page URL and referrer before any event leaves your browser. Only ten named event properties, holding strings, booleans or string arrays, are mirrored to PostHog; our own database remains the record of events.

5.3 Events are sent to PostHog's United States cloud. PostHog receives the IP address of each request and discards it before storing the event: the project's "Discard client IP data" setting is on. PostHog's own enrichment step may still derive an approximate location from the address before it is discarded and hold that under PostHog's settings; we do not read or store the address or the location.

5.4 Basis: legitimate interest in understanding how the Site is used, on the balance that the data carries no cookie, no cross-session identifier, no replay and no URL parameters, so the intrusion on you is minimal (section 6). Because nothing is stored on your device, there is nothing for a consent banner to gate, and the Site shows none. If you object anyway, section 10 applies; we can honour an objection only prospectively, because we hold no identifier that would let us find your past events.

## 6. Lawful bases

6.1 Where the GDPR or UK GDPR applies, we rely on the following bases.

| Purpose | Data | Basis |
|---|---|---|
| Running a Scan and showing the result | Domain, result, status | Contract (Terms of Use) |
| Emailing the top fix you asked for | Email address | Contract (you requested the email) |
| Providing an Account and claimed Scans | Provider identity, session cookie, claims | Contract (Terms of Use) |
| Taking payment for, generating, delivering, refunding and confirming a Fix Kit | Purchase and run records | Contract (Fix Kit Terms) |
| Keeping transaction records | Purchase records, Stripe identifiers | Legal obligation (tax and accounting law) |
| Waitlist confirmation and follow-up | Waitlist fields | Steps at your request before a contract |
| Sending a Fix Kit to a handoff recipient | Nominated address | Legitimate interest (delivering the Purchaser's Order) |
| Agent telemetry | Route and user-agent classes | Legitimate interest (measuring machine use of the Index) |
| Analytics | Cookieless page events | Legitimate interest (understanding Site use) |
| Recording MCP tool calls | Tool name and arguments | Legitimate interest (operating and debugging the machine surfaces) |
| Fetching, storing and publishing public API documentation, which may contain author names and contact details | Scan evidence, reports, excerpts | Legitimate interest (operating the Index; balancing in 6.2). Because the data are collected from public documentation rather than from the individuals, providing individual notice would involve disproportionate effort; we rely on Article 14(5)(b) and make this policy publicly available as the notice |
| Answering requests and complaints | Correspondence | Legal obligation and legitimate interest |

6.2 **Balancing summary for legitimate interests.** For telemetry, analytics and MCP logging we weighed our need to know how the Index is used against the effect on you: the interest is real (the Index exists to be consulted by agents), the data is the minimum that serves it (no IP address, no persistent identifier, no replay, truncated paths), and a reasonable visitor expects a website to count its requests. For handoff emails, the Purchaser chose the recipient to receive something the Purchaser paid for, and the recipient can stop further contact by replying. For fetched documentation: the interest is operating an independent public benchmark of API documentation; the necessity is that the documentation must be fetched and quoted to evidence the score; the impact is on incidental author names and contact details the site owner has already published, with exposure limited to short excerpts and evidence files, no profiling of the person, and an erasure route in 10.5 and the Crawler and Acceptable Use Policy §9.7; we conclude the interest is not overridden. You can object to any legitimate-interest processing (section 10.2).

6.3 **Consent** is not currently used as a basis for anything on the Site, because nothing is stored on your device without your action and no marketing email is sent.

6.4 **Whether you must provide data.** No statutory requirement obliges you to give us anything. Contractually, a Scan needs a URL, an Account needs a provider identity or email address, and a Fix Kit needs payment through Stripe; without those we cannot provide the respective service.

## 7. Who receives your data

7.1 **Processors (act on our instructions).**

| Provider | What it does | Data it handles | Region | Transfer mechanism from the EEA, UK and Switzerland |
|---|---|---|---|---|
| Vercel Inc. | Hosts the Site and its functions | Request logs, everything the Site processes in flight | United States | 2021 EU Standard Contractual Clauses and the UK International Data Transfer Addendum, incorporated in Vercel's Data Processing Addendum |
| Supabase (Supabase, Inc. or Supabase Pte. Ltd. per its Data Processing Addendum) | Database and authentication | Every table in section 3; auth identities; session cookies | United States (project region us-west-2) | EU Standard Contractual Clauses (Module Two) with UK and Swiss addenda, incorporated in Supabase's Data Processing Addendum |
| PostHog, Inc. | Analytics | Cookieless page events (section 5) | United States | EU Standard Contractual Clauses, incorporated in PostHog's Data Processing Agreement |
| Plus Five Five, Inc. (Resend) | Transactional email | Recipient address, email content | United States | EU-US Data Privacy Framework and its UK Extension (certified), with EU Standard Contractual Clauses and the UK Addendum in its Data Processing Addendum |
| Anthropic, PBC | Runs the comprehension tasks of every Scan and generates Fix Kit content | Fetched public documentation (which may contain incidental author names, section 2.2) and scan provenance; no visitor, Account or buyer identity | United States | EU Standard Contractual Clauses (Module Two) with UK and Swiss addenda, incorporated in Anthropic's Data Processing Addendum |
| Discry's own worker (a Mac mini) | Runs the scanner, the publish job, the Fix Kit confirmation worker, a loop tick and a database keep-warm on a schedule | Scan targets and Fix Kit run state, reached through a bearer-authenticated internal endpoint , and the scan corpus (fetched public documentation and evidence files) on its local disk | United States (Brooklyn, New York), operated by the Controller | None needed: this is the Controller's own equipment, not a third party |

7.2 **Independent controllers (decide their own purposes).**

- **Stripe, Inc.** processes your payment and also acts as an independent controller for fraud prevention, regulatory compliance and its own services. Stripe is certified under the EU-US Data Privacy Framework, its UK Extension and the Swiss-US Data Privacy Framework and falls back on Standard Contractual Clauses. Stripe's own privacy policy governs what it does with your data.
- **Sold through Link, LLC**, an affiliate of Stripe, is the merchant of record for Fix Kit payments. It runs the checkout, sends receipts, calculates and remits tax, and handles transaction support, refunds and disputes, using your data as Stripe determines for those purposes. Link's privacy policy at https://link.com/privacy governs that use. If you ask Link to delete your purchase data, Link deletes it across Stripe's systems, including what we stored there, and tells us; a request you send us covers our own records (section 10.3).
- **GitHub, Inc.** and **Google LLC** act as identity providers when you sign in with them. What they record about the sign-in is governed by their own policies; we receive only the default grant described in 3.3.

7.3 **Nobody else.** We do not sell personal information, share it for cross-context behavioural advertising, or give it to data brokers, advertisers or affiliated companies; Discry LLC has no parent or affiliate companies. We disclose data outside this list only if the law compels it, and then we tell you unless legally prevented.

7.4 **Public disclosure of scan data.** Scan results about a domain, including the domain, scores, bands, statuses and evidence, are published in the Directory and the machine exports as Index Data. The published columns are the slug, name, category, status, scores, band and docs URL. No email address, user ID or purchase record is ever published. This publication is not a sale or sharing: no consideration is received and it is not for advertising.

## 8. International transfers

8.1 We are established in the United States and every processor in section 7 stores data there. If you are in the EEA, the UK or Switzerland, your data is transferred to the United States when you use the Site.

8.2 For each processor, the safeguard is the mechanism named in the table in 7.1: the European Commission's 2021 Standard Contractual Clauses with the UK Addendum or International Data Transfer Addendum and, where the provider is certified, the EU-US Data Privacy Framework and its UK Extension. The providers' published data processing agreements incorporating the clauses are linked from their websites, and we will point you to each on request to legal@discry.ai.

8.3 We do not transfer personal data to any other country.

## 9. How long we keep data

9.1 We state retention honestly. **No scheduled deletion or retention job exists for any table today.** The rule for each store is therefore one of two things: "until you ask us to delete it, or until we implement scheduled deletion", or a specific legal reason to keep it longer.

| Store | Personal data | Retention today |
|---|---|---|
| `scans` (submitted email) | Email address | Until you ask us to delete it, or until we implement scheduled deletion. |
| `events` (`email_captured`, `repo_waitlist_joined`, `agent_hit`, `mcp_tool_call`) | Email address, user agent, MCP arguments | Until you ask us to delete it, or until we implement scheduled deletion. |
| `waitlist` | Email, domain, stated need | Until you ask us to delete it, or until we implement scheduled deletion. |
| `purchases` and `subscriptions` | Stripe identifiers, user ID, target | Until you ask us to delete it, except the minimum transaction record that tax and accounting law require us to keep, which we keep for the statutory period. |
| `fix_pack_runs` and `confirmation_runs` | Buyer email, token hash, run state | Until you ask us to delete it, or until we implement scheduled deletion. |
| `claimed_scans` | User ID, claimed slug | Deleted automatically when your auth record is deleted; otherwise until you ask. |
| Auth record held by Supabase | Provider identity, email | Until you ask us to delete your Account. You can sign out yourself, but no self-service deletion exists. |
| `scan_reports` | Third-party documentation evidence; may contain incidental names | **Append-only by database trigger: rows cannot be edited or deleted in place.** Erasure of a personal identifier in this table is performed by anonymising the linked identifiers in the tables that point at it and, where the fragment sits inside the report itself, by taking the affected row out of the published Index and, if needed, dropping and rebuilding the table. |
| `generation_usage`, `rescan_tokens`, `scan_queue` | None beyond a purchase key | Not personal data; kept indefinitely. |
| PostHog events | Page events; the request IP address and any location PostHog derives from it (5.3) | Held by PostHog under its own retention settings; we hold no identifier that lets us find a person's events. |
| Vercel request logs | Request metadata | Vercel's own retention period; not extended by us. |
| Stripe and Link records | Payment and order data | Their own retention as independent controllers. |
| Email correspondence with legal@discry.ai | What you send us | Until the matter is closed and any limitation period has run. |

9.2 When we implement scheduled deletion, we will state the periods here and increment the version.

## 10. Your rights (GDPR and UK GDPR)

10.1 If you are in the EEA, the UK or Switzerland, you have the right to: access your data and get a copy; have inaccurate data corrected; have data erased; restrict processing; receive data you gave us in a portable format; object to processing based on legitimate interests; and, where consent were ever used, withdraw it without affecting earlier processing.

10.2 **Right to object.** You may object at any time to processing based on our legitimate interests (telemetry, analytics, MCP logging, handoff emails). We will stop unless we show compelling grounds that override your interests. For analytics the objection can only work prospectively, because we cannot identify your past events.

10.3 **How to exercise a right.** The Account page lets you sign out, but there is no self-service endpoint, account-deletion button or export tool on the Site. Send your request to legal@discry.ai from the email address we hold for you, or tell us which address, domain or purchase key it concerns. We verify identity by matching the sending address to our records, by asking you to reply from that address, or for a Purchaser by asking for the Link receipt or purchase key. We never ask for identity documents for an ordinary request. An authorised agent may act for you with your written authority.

10.4 **Timing.** We respond within **30 days** of receiving a verifiable request. If a request is complex, we may take up to two further months, and we will tell you within the first 30 days why.

10.5 **What erasure means here.** For most stores it means deleting the row (9.1). For `scan_reports` it means anonymising the linked identifiers as described in 9.1, because the table cannot be edited in place. Erasure never removes a published score about a company, because that is not personal data about you; a Correction Request or Takedown Notice about a listing follows the Directory and Benchmark Policy. A person named or identifiable on a fetched documentation page may also use the erasure route in the Crawler and Acceptable Use Policy §9.7, which reaches the same address and is handled under this section.

10.6 **Complaints.** You may complain to a supervisory authority: in the EU, the authority of the member state where you live, work or where the issue arose; in the UK, the Information Commissioner's Office (ico.org.uk); in Switzerland, the Federal Data Protection and Information Commissioner. You may write to legal@discry.ai first, but you do not have to.

## 11. US state privacy rights

11.1 This section applies if you live in California, Virginia, Colorado, Connecticut or another US state with a comprehensive privacy law. Some of these laws apply only above thresholds Discry may not meet; we offer these rights anyway.

11.2 **Categories of personal information collected in the last 12 months.**

| Category | Examples we hold | Source | Purpose | Disclosed to | Retention |
|---|---|---|---|---|---|
| Identifiers | Email address, user ID, provider identity, purchase key | You; your identity provider | Scans, Accounts, Orders, waitlist | Supabase, Resend, Stripe, Sold through Link, LLC | 9.1: `scans`, `events`, `waitlist`, auth record |
| Commercial information | Fix Kit purchases and status | You; Stripe; Sold through Link, LLC | Orders and records | Stripe, Sold through Link, LLC, Supabase | 9.1: `purchases`, `fix_pack_runs` |
| Internet or network activity | Route class, user agent, cookieless page events, MCP arguments | Your request | Telemetry, analytics | Supabase, PostHog, Vercel | 9.1: `events`, PostHog events, Vercel logs |
| Professional information | Work email domain, stated primary need (repo waitlist) | You | Waitlist follow-up | Supabase, Resend | 9.1: `waitlist`, `events` |
| Identifiers of a third party (handoff recipient) | Email address a Purchaser nominates | The Purchaser, not the recipient | One delivery email | Resend | Used for one send (3.7) |
| Approximate geolocation | None held by us; PostHog discards the request IP address at ingestion and may derive one before discarding it (5.3) | Your request | Analytics | PostHog | PostHog's own settings |
| Sensitive personal information | None | | | | |
| Precise geolocation, biometric, inferences, protected classifications | None | | | | |

11.3 **Sale and sharing.** We have not sold personal information and have not shared it for cross-context behavioural advertising in the last 12 months, and we do not do so now. We use no advertising technology. We do not knowingly sell or share the personal information of anyone under 16. Because we do not sell or share, there is no "Do Not Sell or Share" link to offer.

11.4 **Global Privacy Control and Do Not Track.** We do not currently read the Global Privacy Control signal or a Do Not Track header. This makes no difference to you: we do not sell or share personal information, we use no cross-context behavioural advertising, and our analytics sets no cookie or identifier, so a GPC signal would have nothing to act on. If we ever begin selling, sharing or targeted advertising, we will honour the signal before doing so and update this section.

11.5 **Your rights.** You may ask us to confirm whether we process your personal information and to access it; to correct it; to delete it; to give you a portable copy; and to opt out of sale, sharing, targeted advertising and profiling with legal or similarly significant effects (none of which we do). We collect no sensitive personal information, so the right to limit its use has nothing to apply to. We will not discriminate against you for exercising a right.

11.6 **How to exercise them.** Email legal@discry.ai. Verification follows 10.3. An authorised agent may submit a request with your signed permission; we may ask you to confirm it directly. We respond within **45 days**, extendable once by a further 45 days where reasonably necessary, and we will tell you if we extend. California residents may also write to the office address in 1.1.

11.7 **Appeals.** If we decline a request, we will tell you why. You may appeal by replying to our decision, marking it "appeal". We decide appeals within 45 days with written reasons. If we deny your appeal, you may complain to your state attorney general, and our response will include that contact route.

11.8 **Financial incentives and metrics.** We offer no financial incentive for data and no loyalty programme, and we are below the threshold that requires publishing request metrics.

## 12. Emails we send and how to stop them

12.1 Every email we send is transactional and follows an action the recipient took, except the handoff email in 3.7, which follows an action the Purchaser took. We send no newsletter or marketing email. The emails are: the scan-result email with your top fix (sent only when you enter an address on a result page and at least one task failed), the waitlist confirmation, the handoff email, and, for retired products only, the ready and failure emails of the legacy kits and a subscription welcome. Apart from the handoff email you ask for, the Fix Kit sends no email of its own; Link sends your purchase receipt and any refund notice in its own name.

12.2 They are sent from scans@contact.discry.ai. Each footer prints a mailing address for the Controller, which may differ from the office address in 1.1 until we update it.

12.3 **How to stop them.** The only opt-out mechanism is to **reply to the email with the word "unsubscribe"**. There is no unsubscribe link and no automatic suppression list; a person reads your reply and removes your address by hand. Because the emails are transactional, stopping them may mean we cannot deliver something you asked for, such as a Fix Kit download link; we will tell you if so.

## 13. Automated decision-making and profiling

13.1 We make no decision about **you** by automated means that has a legal or similarly significant effect. The scores, Bands and rankings we publish are automated assessments of **companies' API documentation**, not of individuals, and they are described in the Methodology and the Directory and Benchmark Policy. Fix Kit content is generated by a model from public documentation; the model is instructed not to predict a score, and no prediction of score lift is asserted. We build no profile of visitors: analytics carries no identifier and telemetry records classes, not people.

## 14. Children

14.1 The Site is not directed to anyone under 18, and we do not knowingly collect personal data from anyone under 18. If you believe a person under 18 has given us data, write to legal@discry.ai and we will delete it.

## 15. Security

15.1 Row Level Security is enabled on every application table with deny-by-default policies; the browser holds only a public key and the service key is server-only. Only your claimed Scans are readable by you directly; every other read goes through a server route. Fix Kit delivery tokens are stored only as a SHA-256 hash and compared in constant time, and unknown, wrong or not-ready requests all return the same not-found response. Fix Kit artifacts cannot be read by direct table access. Stripe webhook signatures are verified. Internal worker endpoints are bearer-authenticated. Sign-in redirect targets are sanitised.

15.2 Honest limits: public machine surfaces have no authentication or rate limit; the one rate limit that exists is in process memory and does not survive a restart; the internal workers share one token; and the database is on a tier that pauses when idle.

15.3 **Breaches.** We will tell the competent authority within 72 hours of becoming aware of a personal-data breach unless it is unlikely to result in a risk to you, and tell you without undue delay where it is likely to result in a high risk, as the GDPR and UK GDPR require. US state breach-notification laws apply in parallel.

## 16. Cookies

16.1 The only cookies the Site sets are the first-party authentication cookies that hold a signed-in session; a visitor who does not sign in receives none. Our hosting provider may set infrastructure cookies that we do not configure. The Cookie Policy lists them and is the authority on that subject.

## 17. Changes to this policy

17.1 We may change this policy. A change increments the version number and effective date at the top, and the previous version is kept unchanged in Discry's legal archive and is available on request to legal@discry.ai. If a change reduces your rights or adds a purpose, we will post notice on the Site and, where we hold your email address, email you before it takes effect.

## 18. Contact

18.1 Discry LLC, 418 Broadway, Suite 10855, Albany, NY 12207. Privacy contact: Ben Gibert, legal@discry.ai.
