AnteproofLegal › Privacy policy

Privacy policy

The whole of what Anteproof collects about you, why, for how long, who processes it for us, and what you can ask us to do.

Draft of 4 September 2026.

Draft, under counsel review, effective on publication. This text is a draft. It has not taken effect; it is being reviewed by counsel and becomes effective on the day it is published here without this notice. Questions: [email protected].

1. Who we are 2. What we collect 3. Why, and on what basis 4. Product analytics 5. Cookies 6. Sub-processors 7. International transfers 8. Retention 9. Your rights 10. Security 11. Children 12. Changes 13. Contact

1. Who we are

Recoilix LLC, a Delaware limited liability company operating from North Carolina and doing business as Anteproof ("we", "us"), is the controller of the personal data described here. Contact: [email protected], or by post at Recoilix LLC, 4030 Wake Forest Road STE 349, Raleigh, NC 27609, United States. This policy covers anteproof.com, api.anteproof.com, the MCP server, the weekly digest and the account features. It does not cover the websites of the sub-processors named below, which have their own policies.

Most of the Service is a public record about software projects and organisations, not about people. Personal data enters only when you create an account, subscribe, use an API key, write to us, or visit the site.

2. What we collect

We do not collect special-category data, do not buy data about you, do not run advertising, and do not sell or "share" (in the California sense) personal data with anyone.

3. Why we use it, and on what legal basis

PurposeDataBasis (GDPR / UK GDPR)
Running your account, watchlist, keys and subscriptionAccount, product use, billing identifiersPerformance of our contract with you
Metering API use and enforcing plan allowancesCall counts per keyContract
Keeping the Service secure; detecting and limiting abuse; diagnosing faultsServer logs, hashed IP in product eventsOur legitimate interest in a secure, working service
Understanding how the product is used and where sign-ups come fromProduct events with UTM attributionOur legitimate interest in improving the product and measuring our own marketing; you may object (section 9)
Sending the digest you asked forNewsletter emailConsent; withdraw by unsubscribing
Service messages about your account (receipts, trial ending, renewal, security notices)Account emailContract, and our legitimate interest in telling you about your account
Tax, accounting and legal record-keepingBilling identifiers and Stripe's recordsLegal obligation
Answering youCorrespondenceLegitimate interest

We do not make decisions about you by automated means that have legal or similarly significant effects. The forecasts the Service publishes are about software projects and organisations, not about you.

4. Product analytics: first-party only

We measure the product ourselves. Product events are recorded by our own servers into our own database; no third-party analytics, advertising or session-replay service is loaded on the site, and no event is sent to one. Concretely:

We honour the Global Privacy Control signal as an objection to the attribution use described here.

5. Cookies and browser storage

Only first-party cookies and storage, set by us or by the identity provider on our domain:

There are no advertising cookies, no third-party analytics cookies, and no cross-site tracking. Fonts are loaded from Google Fonts, which receives the request for the font file (and so your IP address) but sets no cookie; we are considering self-hosting them.

6. Who processes data for us (sub-processors)

ProviderPurposeLocation
Clerk, Inc.Sign-in and account identityUnited States
Stripe, Inc.Checkout, subscriptions, invoices and tax, as merchant of record (Stripe is an independent controller for the payment itself)United States and EU entities
Cloudflare, Inc.Network edge, TLS, DNS, DDoS protection, email routingGlobal edge; United States
Hetzner Online GmbHHosting of the public serving plane, database and product-event storeGermany
Resend, Inc.Transactional email (receipts, account notices)United States
Beehiiv, Inc.The weekly digest newsletterUnited States

Each processes data only for the purpose listed, under a written agreement. We will update this list before adding a sub-processor that handles account data; customers with a data processing addendum are notified as it provides.

7. International transfers

We are in the United States and the database is hosted in Germany. If you are in the EEA, the United Kingdom or Switzerland, your data is transferred to the United States when it reaches us or a US sub-processor. For those transfers we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) with each provider, or on the provider's certification under the EU-US Data Privacy Framework where it holds one. A copy of the clauses we use is available on request.

8. How long we keep it

DataKept
Account, watchlist, keysWhile the account exists; deleted within 30 days of a deletion request or of closing the account
API call counts13 months, for allowance enforcement and usage history
Uploaded lock files or SBOMsProcessed to produce the answer, then deleted within 24 hours; only the derived list of package names is kept with the answer
Billing identifiers and subscription statusAs long as tax and accounting law requires (in the US generally 7 years); Stripe keeps its own records under its policy
Product eventsEvent-level data 13 months, then aggregated; the IP hash key rotates at most every 90 days
Server logsAt most 90 days
NewsletterUntil you unsubscribe; suppression record kept afterwards so we do not re-add you
Correspondence3 years

9. Your rights

Wherever you are, you can ask us to tell you what we hold about you, correct it, delete it, give you a copy in a portable form, restrict how we use it, or stop a particular use. Where we rely on legitimate interest (product analytics, attribution) you may object and we will stop unless we have compelling grounds. Where we rely on consent (the digest) you may withdraw it at any time by unsubscribing. Email [email protected]; we answer within 30 days and may ask you to confirm it is your account. You can remove watchlist entries and revoke API keys yourself on the account page; to close the account, email us.

10. Security

Traffic is encrypted in transit; data is encrypted at rest by our hosting provider. API keys are stored only as SHA-256 hashes. The forecast archive the public reads is served from a read-only copy, and customer account data lives in a separate database. Access to production is limited to the people who operate it, over authenticated private networking. If a breach affects your data we will tell you and the relevant authority as the law requires.

11. Children

The Service is not directed at anyone under 16 and we do not knowingly collect their data. If you believe a child has given us data, contact us and we will delete it.

12. Changes

We will post changes here with a new effective date. Account holders are emailed at least 14 days before a change that reduces their rights or adds a new use of their data takes effect.

13. Contact

Privacy requests and questions: [email protected]. Everything else: [email protected]. Post: Recoilix LLC, 4030 Wake Forest Road STE 349, Raleigh, NC 27609, United States. Related documents: the terms of service, the refund and cancellation policy, the data processing addendum for business customers, and the legal page.