Privacy Policy

Draft for counsel review. Last updated 2026-09-03.
This policy covers two groups: customers (people who use the dashboard and API) and end users (people who sign up for a customer's service and are scored by OneTrial).

Customers

We collect your name, email address, and password hash (or your Google account identity) to run your account; your workspace settings; and audit logs of actions taken in the dashboard. Billing details are handled by Stripe; we store only Stripe's customer and subscription identifiers. We do not sell this data.

End users

When a customer's application calls our API we receive the signals the customer chose to send: the signup email address, the visitor's IP address, a device hint computed in the browser, passive form behavior (such as time to submit), and, when the customer uses Stripe with OneTrial, a card fingerprint. A card fingerprint is an opaque identifier from Stripe; we never receive card numbers.
Browser storage. Our script stores one value in the browser's local storage on the customer's own website: a random reference we generate, which lets us recognize a returning browser even after an update changes its other characteristics. It is a random number. It is not derived from anything about the person, it carries no personal data on its own, and it is never read across different customers' websites or used for advertising. Clearing site data removes it, and nothing about a visitor is penalized for its absence. We store no cookies of our own on end users.
What we do with it:
  • Email addresses are normalized and stored as a one-way hash for matching. The raw address is encrypted at rest and used only to send a verification link when the customer's flow asks for one.
  • IP addresses are stored with their network prefix for matching and shared-network awareness. We do not build location profiles.
  • Signals, including that browser reference, are linked into an identity graph within the customer's workspace only, to recognize repeat trial attempts on that customer's service.
  • Decisions, scores, and the reasons behind them are shown to the customer, never to the end user. End users see at most which verification options are available.
Retention follows the customer's plan (30 to 365 days), after which raw signals are deleted. Customers can delete an end user's data on request through the API; that erasure clears the browser reference along with the device hint, email, and network data, so an erased person cannot be re-linked.

Sub-processors

Neon (database and authentication), Amazon Web Services (email delivery), Stripe (payments and card verification), Vercel (hosting), Cloudflare (Turnstile verification), NVIDIA (rule-builder language model; receives only the customer's typed rule text, never end-user data).

Your rights

End users: contact the service you signed up for; they can instruct us to delete your data. Customers: email privacy@onetrial.dev to access, correct, or delete your account data.

Contact

privacy@onetrial.dev