Back to Signless
Signless

Privacy Policy

Last updated August 24, 2026

This policy explains what Signless collects and what happens to it. The short version: the Service is designed so that almost nothing about you is stored on our servers.

1. What stays on your device

  • Your session token and cached profile are stored in your browser's localStorage.
  • Map position, scan history preferences, and your “extra requirements” notes are also stored locally.
  • Notification permission state is managed by your browser.

2. What our servers store

  • Your account: email, name, a salted password hash (never the password), plan, and Stripe customer/subscription IDs.
  • Build jobs tied to your account: business name, category, prompt text, status, timestamps, and the generated files at a random UUID address.
  • Short-lived caches of map scans, geocode results, and Places lookups to respect third-party rate limits.

3. Third parties that receive data when you use the Service

  • OpenRouter — business name, category, and your prompt text are sent to generate websites (and may be processed by the underlying model provider).
  • DuckDuckGo & Openverse — search queries initiated by the agent during research.
  • Google Maps Platform — business name and coordinates are sent to fetch public ratings/reviews when Google enrichment is enabled.
  • OpenStreetMap ecosystem — map bounding boxes are sent to Overpass API mirrors and Nominatim for POI and address lookups.
  • CARTO — serves the basemap tiles; standard tile requests include your IP address.
  • Stripe — processes subscriptions and payments; we receive your customer ID and subscription status, never card details.

These providers process data under their own privacy policies.

4. Cookies & tracking

We don't use cookies, ads, or cross-site tracking. Payments run through Stripe Checkout on Stripe's own page. Hosting is deployed on Vercel, which collects cookieless, aggregated web analytics (page views, referrers, approximate location at country level) — no individual profiles. LocalStorage is used only for the features listed in §1.

5. Retention & deletion

Job records and generated sites persist until deleted (you can remove finished builds from the Builds tab) or until the operator resets the deployment. Clearing your browser's site data removes everything stored on your device.

6. Your rights

Depending on where you live (e.g. EU/UK GDPR, CCPA), you may have rights to access, correct, export, or delete personal data. Since current accounts live only in your browser, exercising most rights means clearing local data. For server-stored build data, contact us and we will handle it.

7. Contact

Privacy questions or deletion requests: maria.a.hall.112@gmail.com.