PRIVACY

Privacy policy

This page states exactly what Timory stores, why, how long it is kept and how to have it removed. It describes what the code actually does — if you find a gap between this page and our behaviour, that is a bug and we want to hear about it.

§ 01

What we collect

DataWhenPurposeRetention
Email address (plus the market description you type, for a market watch) Only when you subscribe to a brief, unlock full evidence chains, or create a free market watch Sending the emails you asked for, and nothing else Until you unsubscribe or ask us to delete it
Fit Check fields: work email, company, decision type/date, available source types and authorization/redaction readiness Only when you submit the Fit Check form Deciding whether a first conversation is appropriate and replying to you. The form does not accept customer excerpts or files Not stored in the website database. It is delivered through our email provider and kept in the Timory mailbox only as long as needed to handle the request or a deletion request
Anonymous site event: event name, path, referrer and a daily visitor hash Page views and on-site actions (such as questions, saves and button clicks) Counting page views, daily visitors and channel funnels 90 days
Raw IP address, full user-agent string and IP-derived country, with path and referrer Every page view on this public site Traffic forensics: telling real readers from crawlers and abuse. Readable only by the site owner through an authenticated admin view; never published, never shared, never used for advertising or profiling 30 days, then deleted automatically

The daily visitor hash is sha256(daily rotating salt + IP + user-agent), truncated. The salt changes every day, so the hash cannot be linked across days or reversed. It is a per-day counter, not a persistent identifier.

BEING PRECISE

Because we store the raw IP address alongside that hash, we do not claim this site is anonymous. An IP address is personal data under the GDPR and the PIPL. The list above is complete, and the 30-day limit is enforced by a scheduled job, not by a promise.

§ 02

Cookies

This public site sets exactly one cookie, and only if you unlock full evidence chains with your email: timory_unlock. It stores a signed unlock token — no email address, no identifier we can read back into a person. It lasts 180 days and exists solely so you do not have to re-enter your email on every dossier. There are no advertising, analytics or third-party tracking cookies, so there is nothing to consent to beyond this one functional cookie. Deleting it in your browser simply returns you to the truncated evidence view.

§ 03

Emails we send

You only receive email you asked for: the weekly evidence brief, or the market watch you created. Market watches use double opt-in — the watch stays inactive until you click the confirmation button yourself. Every email carries a one-click unsubscribe link and the standard one-click unsubscribe headers, and unsubscribing takes effect immediately. We do not sell, rent or share your address, and we send no advertising on behalf of anyone else.

PRIVATE ENGAGEMENT

Fit Check and client material are different steps

The public Fit Check collects only the short qualification fields listed above. It does not accept customer material, and its business fields are not written to the Timory website database. They pass through the configured email provider to the Timory contact inbox so we can reply.

If a private engagement proceeds, customer material uses a separately agreed, customer-controlled restricted folder. It does not enter the public evidence corpus, public website or another client project. Do not send files or excerpts until Timory confirms the intake path and retention terms.

§ 04

Unsubscribing and deletion requests

To stop emails, use the unsubscribe link at the bottom of any email — it takes one click and needs no account. To have your stored data deleted, or to ask what we hold about you, email timory2025@gmail.com. We handle these by hand and confirm when it is done. Access logs age out on their own after 30 days, so a request made after that has nothing left to erase.

§ 05

Quotes from public communities

Evidence excerpts on this site come from publicly visible posts and comments in developer and founder communities. Copyright stays with the original authors and platforms; we publish short excerpts with a direct link back to the source, and excerpt limits vary by source. We do not republish private messages, private groups or anything behind a login. If you are the author of a quoted post and want it removed, write to timory2025@gmail.com and we will take it down.

§ 06

Third parties

There is no Google Analytics and no advertising network on this site; visit counting is done on our own server. Outgoing email and Fit Check notifications go through our email provider, which necessarily sees the fields being delivered. Search engines receive publication pings for new public pages only — never anything about you. If you create a market watch, the market description you type is sent to the language-model provider we use (a third party, possibly processing outside your country) so it can be matched against the dossiers we already track. Your email address is not sent to the model.

§ 07

Changes

If we start collecting something new, this page changes in the same release. Retention periods shown above are read from the running configuration, so the numbers on this page are the numbers the system enforces. See also our methodology and terms of use.