Privacy
What we store, and what you can do about it
In effect 2026-09-17
What we hold
- Your account — email address, name, password hash, and the sessions and API keys you create.
- Your research — the question you asked, every step the run took, the pages it fetched and the text extracted from them, the facts it established with the quotes behind them, and what it refused and why.
- Your ledger — credits bought, spent and refunded, and the Stripe customer that paid.
Where it lives
Research data is held in the region your account belongs to — today that is Australia — and is read under row-level security, so one account's runs are not visible to another by construction rather than by a filter someone has to remember to write.
Payments
Card details never reach us. Checkout and the customer portal are Stripe's, and what we keep is the customer identifier, the amount and the credits it bought.
Models and the pages we read
A run sends the question and the text of the pages it reads to model providers to be summarised and checked. Pages are fetched from the public web and stored so that a quote can be shown back to you in the context it came from.
Getting it back
Export. The account screen returns everything we hold for you as one JSON document: runs, the full event log, claims, refusals and the ledger.
Closing the account. Closing deletes your identity — the account, its sessions and its API keys — and detaches your research from you. The run logs themselves are append-only and are not erased; after closing they belong to nobody and cannot be read by any account, including a new one with the same email address.
Asking us
Anything else, including a request to erase a specific run: support@iontrack.ai.