Privacy Policy

Effective: 2026-07-02

1. What We Collect

We collect the minimum data necessary to operate the kariops-pulse Connector. Specifically:

(a) Identity fields via OAuth sign-in. When you sign in via OAuth, we collect your email address and OAuth provider ID (the unique identifier your identity provider assigns to your account) using the Better Auth open-source library running on our own infrastructure. Better Auth is a library, not a separate company. We are the controller of this data. We do not collect your name, phone number, or any OAuth scope beyond what is required for sign-in.

(b) Encrypted engine API keys. When you add an API key for a scan engine (Anthropic, OpenAI, Perplexity, Google, or Serper), we store an encrypted copy of that key in our database. One row per user per engine. See "API Keys and Engine Providers" below for how these are protected.

(c) Brands and competitors you ask us to track. The brand names, domain names, and competitor names you configure in the dashboard are stored so that monthly scans know what to look for.

(d) Scan results we generate using your keys. When a scan runs, we store engine usage metadata returned by each provider, specifically the model identifier, the input token count, and the output token count reported for that call. We also store derived metrics calculated from the engine response: the count of citation mentions identified for your tracked brand or query (an integer) and the citation share percentage for that scan (a decimal). We do not store the body of the engine response, the prompt text we sent on your behalf, or verbatim excerpts of the engine output. Aggregate metrics and the historical trend of those metrics are surfaced in your dashboard.

(e) Audit log entries. We keep a log of every connector tool call with a timestamp, the OAuth scope used, the tool name, and the outcome. This log supports security review and is described further in "Data Retention."

(f) Operator continuity. kariops-pulse is currently operated by a single individual, Kari Doherty. In the event the operator becomes unreachable for an extended period, your stored data (encrypted API keys, scan history, tracked brands, audit log) is preserved per the retention rules in Section 9. If the operator becomes permanently unavailable, an in-app banner and email notice sent to the address on file will identify a successor contact and outline options for data export and deletion. This section commits to the notification mechanism; the specific successor contact is not designated in advance.

We do not collect sensitive personal data as defined under GDPR Article 9. We do not collect billing or payment information for engine usage. You are billed directly by each engine provider against your own account. Our sub-processors Vercel, Sentry, and Better Stack collect IP addresses and user-agent strings as a necessary part of routing requests, tracking errors, and monitoring uptime. We do not store IP addresses or user-agent strings in our own database or use them for analytics or profiling beyond those operational purposes.

Controller identity. The data controller is Kari Doherty, operating kariops-pulse. Privacy contact: kari@kariops.com. No Data Protection Officer is designated. The controller is the privacy contact.

Children. The Connector is not directed to individuals under 16. We do not knowingly collect personal data from individuals under 16.

Lawful basis for processing. Under GDPR Article 6, we rely on the following lawful bases for the processing activities described above. Items (a) through (d) (identity fields, encrypted engine keys, tracked brands, and scan results generated on your behalf) are processed under Article 6(1)(b), performance of the contract you enter with kariops-pulse when you sign in and configure the service. Item (e), the audit log, is processed under Article 6(1)(f), our legitimate interest in security review and incident investigation of a service that handles user credentials. Item (f), operator continuity notification, is processed under Article 6(1)(f), our legitimate interest in maintaining continuity for users of a solo-operator service. Sub-processor collection of IP addresses and user-agent strings for hosting, error tracking, and uptime monitoring is processed under Article 6(1)(f), our legitimate interest in operating the service reliably and securely. Marketing emails, described in Section 5a, are processed under Article 6(1)(a), your consent. You may withdraw consent at any time as described in Section 5a.

2. Sub-processors

kariops-pulse uses the following sub-processors to operate the hosted service:

Hosting and database: Vercel, Inc. (application hosting, edge runtime); Neon, Inc. (managed Postgres).

Authentication: Better Auth (open-source library, self-hosted, data lives in our Neon database).

Operational monitoring: Sentry (error tracking and performance monitoring); Better Stack (uptime and log management).

Transactional email: Resend (notification emails for key changes, scan failures, and security events).

Engine APIs (called using YOUR keys, on YOUR behalf): Anthropic; OpenAI; Perplexity; Google; Serper. See "API Keys and Engine Providers" section for the agency-principal model.

Sub-processor Data Processing Addenda. Each sub-processor listed above operates under a published Data Processing Addendum or equivalent commitment: Vercel (https://vercel.com/legal/dpa), Neon (https://neon.com/platform-terms#3.4), Sentry (https://sentry.io/legal/dpa/), Better Stack (published privacy commitment at https://betterstack.com/privacy; a standalone Data Processing Addendum is available on request and will be executed with Better Stack before any EU or UK personal data is processed via that sub-processor), and Resend (https://resend.com/legal/dpa). Where a sub-processor's DPA incorporates Standard Contractual Clauses for international transfers, those clauses are Module 2 (controller-to-processor) of the EU Commission's 2021 template and are the basis on which the sub-processor may process personal data originating in the European Economic Area or United Kingdom.

We will give you 14 days' written notice before adding or replacing any sub-processor by updating this list and emailing you at the address on file.

Objection to sub-processor changes. You may object in writing to a specific sub-processor change by emailing kari@kariops.com within the 14-day notice window. Vercel, Neon, and the OAuth engine providers listed above are essential to operating the Connector and cannot be substituted on request; objections that would require replacing one of them will be handled by account deletion before the change takes effect. For all other sub-processors (Sentry, Better Stack, Resend, and any future analytics or messaging providers), we will either identify an alternative that resolves your objection or provide account deletion within 30 days of receiving a reasonable written objection. If you take no action within the 14-day notice window, the change proceeds.

International data transfers. kariops-pulse is operated from the United States by a US-based controller. Personal data is processed and stored in the United States. For the current user base, cross-border processing by sub-processors is governed by the Data Processing Addenda referenced above, each of which incorporates Module 2 of the EU Commission's 2021 Standard Contractual Clauses (controller-to-processor) or an equivalent transfer mechanism where the sub-processor routes or stores data across international borders. We do not currently direct the Connector to users resident in the European Union or United Kingdom within the meaning of GDPR Article 3(2)(a) or its UK GDPR equivalent (Recital 23 targeting factors include language directed at the EU or UK, offering payment in EUR or GBP, and marketing or public listings mentioning EU or UK customers). If any of those targeting factors activates in our directory listing, marketing copy, or user-facing interfaces, we will (1) appoint a representative in the European Union under GDPR Article 27 and, if applicable, a representative in the United Kingdom under UK GDPR Article 27, (2) rely on the Article 49(1)(b) derogation (transfer necessary for the performance of a contract between the data subject and the controller) for the direct controller-to-data-subject transfer at account creation, and (3) update this section to reflect the transfer mechanism in use and the identity of each representative. Article 49 derogations are intended for occasional and non-systematic transfers per Article 49(1) second subparagraph; if EU or UK usage becomes systematic, we will re-scope the transfer mechanism (for example to Binding Corporate Rules or Data Privacy Framework registration) before that transition. The associated infrastructure (representative appointment, Data Privacy Framework registration) is not committed in advance of the Article 3(2) trigger.

3. API Keys and Engine Providers

What we collect. Encrypted copies of the per-engine API keys you provide (one row per user per engine), the brands and competitors you ask us to track, scan results we generate using your keys, and an audit log of every connector tool call (timestamp, OAuth scope, tool name, outcome).

What we do not collect. We do not retain engine response content beyond the citation mentions we extract for your dashboard. We do not request or store any personal information beyond the OAuth profile fields (email, provider ID) that Better Auth requires for sign-in. We do not collect billing or payment information for engine usage; you are billed directly by each engine provider.

How your keys are protected. Each stored key is protected by two layers of encryption. First, a fresh 32-byte Data Encryption Key (DEK) is generated for every stored key row. The DEK encrypts your API key using AES-256-GCM with Additional Authenticated Data that binds the ciphertext to your account and engine, so a row copied to a different account or engine fails to decrypt. Second, the DEK itself is encrypted (wrapped) by a root key hosted in Google Cloud Key Management Service (KMS). The root key never leaves KMS. Every wrap and unwrap operation is audit-logged by KMS with the identity that made the call. The plaintext key exists in memory only during the brief window in which a scan calls the engine on your behalf, and is then discarded. Compromising the database alone does not decrypt any keys, because the wrapped DEKs cannot be unwrapped without the KMS root. Compromising the KMS credentials alone does not decrypt any keys either, because the wrapped DEKs and ciphertexts live in the database.

Database access controls. The production Postgres database is hosted on Neon and is accessed by exactly two identities: (1) the production Vercel service, which reads and writes via a scoped connection string provisioned as a Vercel environment variable and (2) the operator (Kari Doherty), who reads directly via the Neon console using multi-factor authentication configured on the operator's Neon account. No shared admin credentials exist. Neon logs every console session and every SQL statement executed against the production database; those logs are retained per Neon's standard policy and available to the operator for security review. The KMS service account used to unwrap DEKs at runtime is scoped to the single production application environment and cannot be assumed by any other identity.

Your rights. You can view, replace, or delete any stored key from the dashboard at any time. Deletion is permanent at the database row level and propagates within minutes. If we rotate the service-wide encryption secret, every stored key becomes unreadable and we will prompt you to re-enter.

4. Cron-Driven Processing

When you schedule a monthly scan, kariops-pulse runs the scan automatically on your behalf at the scheduled time, using the API keys you have authorized. We do this even when you are not actively signed in.

You can pause and resume scheduled scans at any time from the dashboard without deleting your stored keys. When paused, your saved day of month is preserved and no engine calls are made on your behalf until you toggle scans back on. You can also stop scheduled processing entirely by deleting your stored API keys, which cancels any future scheduled runs.

5. Email Notifications

We send transactional emails for security-relevant events: every time you add, replace, or delete an API key, and every time a scheduled scan fails. These emails are not optional in the current version; they are part of how we keep you informed about your own security.

5a. Marketing Emails (Optional)

Separate from the transactional emails described above, we may send occasional marketing emails if you opt in. Marketing emails cover kariops product updates, Field Notes blog announcements, new service offerings, and occasional content Kari thinks will be useful to people running mission-driven small businesses. These emails are also sent through Resend.

Marketing emails are off by default. We will only send them if you check the marketing-email box on the sign-up form, or turn marketing emails on later from your dashboard. You can unsubscribe at any time using the link in every marketing email, or by turning marketing emails off in your dashboard. Unsubscribing from marketing has no effect on the security and account emails described in section 5, which we send regardless.

We do not share your email address with any third party for their own marketing use.

6. Operational Monitoring Data

Operational monitoring data sent to Sentry and Better Stack consists of error stack traces, performance metrics, and uptime probes. It does not include your API keys or the substantive content of your scan results. API keys are filtered before any error is reported to Sentry by a beforeSend scrubber (implemented in lib/observability/sentry-scrubber.ts) that recognizes the five engine key formats we handle (Anthropic, OpenAI, Perplexity, Google, Serper) and replaces any occurrence with [REDACTED_API_KEY] prior to transmission. The scrubber is invoked on every Sentry event and every breadcrumb across the client, server, and edge runtimes. The scrubber's behavior is exercised by an automated test suite (lib/observability/sentry-scrubber.test.ts) that verifies each of the five engine key formats is redacted in both string fields and breadcrumb data, plus a negative case that leaves non-key strings untouched.

6a. Breach Notification

If we become aware of a security incident that has resulted in unauthorized access, loss, alteration, or disclosure of your personal data or your stored API keys, we will notify you without undue delay and no later than 72 hours after we become aware. The notification will describe the nature of the incident, the categories of data affected, the likely consequences, and the steps we have taken or propose to take in response. Notifications are sent to the email address on file for your account.

If a sub-processor listed in section 2 notifies us of a security incident affecting your data, we will forward that notification to you within the same 72-hour window.

Where an incident meets the threshold for notification to a data protection supervisory authority under applicable law, we will notify the relevant authority within the timelines required by that law.

7. Account Recovery

Account access uses OAuth sign-in via Better Auth. We do not store passwords. If you lose access to your OAuth identity provider account (Google, GitHub, or other), recovery is handled by that provider, not kariops. For account issues, contact kari@kariops.com.

8. Your Rights

You have the following rights over your data at any time:

View stored keys. The dashboard shows a fingerprint (a short non-reversible identifier) for each stored key. We never display the full plaintext key.

Replace any stored key. You can overwrite any stored key with a new value from the dashboard. The previous ciphertext is deleted at the database row level.

Delete any stored key. You can delete any individual stored key permanently. Deletion propagates within minutes.

Delete your account. Deleting your account removes all stored keys, scan history, tracked brands, and audit log entries. Deletion cascades to all associated rows. See "Data Retention" for the 30-day processing window after account deletion.

Export your scan history. You can export your full scan history as JSON from the dashboard at any time.

Access and correction. You have the right to request a copy of the personal data we hold about you and to request correction of inaccurate data. Email kari@kariops.com and we will respond within one month, as required by applicable data protection law.

Portability. Your scan history export (JSON) is the portability path. We do not lock your data to a proprietary format.

Objection and withdrawal. You may object to processing based on legitimate interest by contacting kari@kariops.com. Where processing is based on consent, you may withdraw consent at any time.

Supervisory authority. If you are located in the EU or UK, you have the right to lodge a complaint with your local data protection supervisory authority.

Response time. We will respond to any request under this section within one month of receiving it, as required by GDPR Article 12(3). If a request is particularly complex or if we receive a large volume of requests, we may extend that period by up to two further months; if so, we will notify you within one month of receiving the request and explain the reason for the delay.

We do not sell personal data. We do not use personal data for automated decision-making that produces legal or similarly significant effects on you.

9. Data Retention

We retain different categories of data for different periods:

Audit log: 12 months from the date of each entry. After 12 months, entries are deleted automatically.

Scan history: 24 months from the date of each scan. You can delete individual scan records or export and delete all records from the dashboard at any time before the retention window expires.

Encrypted API keys: Retained until you delete them from the dashboard, or until the service-wide encryption secret rotates. If the encryption secret rotates, every stored key becomes unreadable at the database level and you will be prompted to re-enter your keys at the next sign-in.

Operational monitoring data: Retained per provider defaults. Sentry free tier retains error events for 30 days. Better Stack free tier retains log data for 3 days.

Account deletion: When you delete your account, all personal data (keys, scan history, audit log entries, tracked brands) is deleted within 30 days except where a longer retention period is required by applicable law.

10. Changes

We will give you 14 days' notice of changes to this Privacy Policy by email and in-app banner. If you do not agree to the revised policy, you may close your account before the changes take effect.

Contact

kari@kariops.com