Privacy Policy
Effective August 12, 2026
§ 01 What we collect
- Account: your email address, session records (browser user-agent, IP) for sign-in security, and your watchlist configuration.
- Billing: handled by Stripe. We store your Stripe customer id and subscription state; we never see or store card numbers.
- Operations: standard server logs (IP, path, timing) kept for debugging and abuse prevention.
That's the list. No advertising trackers, no fingerprinting, no analytics resale, no selling of personal data — ever.
§ 02 The data we monitor
The regulatory and licensing records the service processes are public records published by government agencies. Where those records contain business contact details (e.g. a contractor's licensed business phone), we surface them as published by the source agency and do not enrich them with private data. Removal requests for personal information within public-record mirrors: privacy@regflow.us — we honor them.
§ 03 Processors
We share data only with the processors that run the service: Stripe (payments), Resend (transactional email), and Fly.io (hosting, US region). Each receives only what its function requires.
§ 04 Cookies & retention
One cookie: your session (30 days, httpOnly). No third-party cookies. Account data is kept while your account exists and deleted within 30 days of account deletion, except invoices, which tax law requires us to retain. Server logs rotate within 90 days.
§ 05 Your rights
Email privacy@regflow.us to access, correct, export, or delete your data — we respond within 30 days regardless of your jurisdiction. Security disclosures: security@regflow.us.
Material changes to this policy are announced by email 14 days in advance.