Last updated 24 July 2026
This policy describes what Cartographer Intelligence collects when you use Cartographer, why, and who else processes it. It reflects what the service actually does today rather than what it may do later.
Cartographer is operated by [registered entity to be completed], trading as Cartographer Intelligence. For any question about this policy or to exercise a right described below, write to privacy@cartographer.tools.
Account data. Your name, email address, and a password credential managed by our authentication provider. We never see or store your password. Email verification uses a one-time code sent to your address.
Workspace and property data. The domain you add, its verification state, and a hash of the DNS TXT answer that proved your control of it. We do not store the raw DNS answer.
Measurement data. The questions you submit for analysis, and the resulting retained observations: a bounded excerpt of the answer, the public source URLs it cited, the exact measured surface, timestamps, and a hash reference to the provider artifact. We retain the normalized observation and its hash, not the raw provider response.
Billing data.Our payment processor’s customer and subscription identifiers, your subscription status, and billing period dates. Card numbers are entered on the processor’s own hosted checkout and never reach our servers.
Operational data. Audit records of changes you make to your workspace, and server logs containing bounded identifiers and error codes. Our logs are written not to contain message bodies, tokens, query text, or provider output.
To provide the service you asked for: authenticating you, proving your control of a domain before spending on measurement, running the analyses you request, showing you the results, and billing you. We also process it to keep the service secure, to meet accounting obligations, and to diagnose failures.
We do not sell personal data, we do not use it to train models, and we do not run advertising or cross-site tracking.
We use a small number of providers, each for one purpose: hosting and serverless execution; a managed PostgreSQL database and the authentication service attached to it; a payment processor for checkout, subscriptions, and invoices; a transactional email provider for verification and account mail; and an AI gateway that forwards your analysis question to the answer engine being measured.
The question text you submit for analysis is sent to that answer engine in order to measure its response. Do not put confidential information in an analysis question.
These providers operate in the United States and elsewhere, so your data may be transferred outside your country. We rely on the providers’ standard contractual protections for those transfers.
We set a signed, HTTP-only session cookie so you stay signed in. It is required for the authenticated product to function. We also use privacy-preserving page analytics that record which pages are viewed and never receive email addresses, authentication state, query text, or evidence content. There are no advertising cookies.
Account, workspace, property, and measurement data are kept while your account exists, because the product’s value is the ability to compare a measurement against an earlier one. Billing records are kept as long as accounting rules require.
There is currently no self-service account deletion. Email privacy@cartographer.tools from your account address and we will delete your account and its associated workspace, property, and measurement data within 30 days, retaining only what we are legally required to keep.
Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, receive it in a portable format, object to or restrict certain processing, and complain to your data protection authority. Write to the address above and we will respond within the period the applicable law requires.
Customer data is isolated per workspace at the database level, and authorization is derived from your verified session rather than anything your browser sends. Secrets are held in server-side configuration. No system is perfectly secure; if a breach affects your data we will notify you as required by law.
If we change this policy in a way that materially affects you, we will update the date on this page and notify account holders by email before the change takes effect.