DATA PRACTICES

Privacy notice.

Contact

These policies apply to Ephor and its competitive intelligence service. Contact support@ephoranalytics.com.

Information we handle

We store your account email, a password hash, account verification and recovery records, session records, subscription identifiers and workspace settings. Your workspace contains the competitors, source URLs, observations, imported metrics, models and experiment records you add or generate. Support messages contain the information you choose to send.

Service infrastructure processes request information such as IP addresses, paths, timestamps and errors for delivery, security and troubleshooting. Application authentication rate limits use hashed identifiers. We do not receive your full payment card details; Stripe handles payment entry.

How we use it

We use this information to operate and protect the service, authenticate you, collect configured sources, run your workspace analyses, manage subscriptions and respond to requests. Models currently run on data within your own workspace. Customer workspaces are not pooled to train a shared model.

Service providers

The production service is hosted on Akamai Linode. Stripe processes subscriptions and payments. Twilio SendGrid delivers account confirmation and recovery emails. Microsoft 365 provides the support mailbox. These providers receive the information needed for their role and may process it in other countries under their applicable terms and safeguards. Configured public sources receive network requests needed to collect their data.

Cookies and tracking

The public website does not use advertising trackers or analytics cookies. The application uses an essential, host-only session cookie for sign-in. Account email open and click tracking are disabled. Stripe may use cookies and other technology on its hosted payment and account-management pages under its own privacy notice.

Retention

Workspace data is retained to provide the service; some recorded change history is subject to a 180-day window. The latest snapshot and latest model may be retained longer. Imported metrics and account records are not automatically erased when a trial or subscription ends.

Expired sessions and verification or recovery tokens are cleaned up. Accepted email bodies are cleared; sent email records are normally removed after seven days, failed email records after 30 days, and processed webhook records after 90 days. Local database backups are retained for 14 days. Infrastructure logs and providers have separate retention practices.

Your requests

You can export supported workspace data in the app. Email support to request access, correction, account closure or deletion. We verify account ownership and explain any information that must remain for billing, security or legal reasons. Applicable privacy rights depend on your location.

Protection and changes

The service uses HTTPS in production, hashed passwords and session tokens, and separate workspace databases. No system can guarantee absolute security. We may update this notice to reflect changes to the service and will identify material changes when appropriate.