Legal · 2026-09-08
Privacy Policy
This policy describes what Baruly collects and why. Counsel has not reviewed this draft.
What we collect
- Account email, and if you use Google sign-in, a Google subject identifier.
- Magic-link delivery through Resend (the email provider).
- Payment identifiers through Stripe (customer and subscription ids, not full card numbers).
- The lists, queries, and runs you submit, including spoken-evidence rows and rights metadata.
- Optional: how you heard of us, marketing-email consent, post-purchase company/role answers, and a cancellation reason if you offer one.
Why
- To run investigations you request and meter credits against your account.
- To sign you in (magic link or Google) and keep a session.
- To take payment and fulfill credit packs or a subscription.
- To send transactional mail, and commercial mail only if you opted in.
- To publish de-identified programmatic SEO pages about public entities from consented free-allotment usage, never your list.
- To show public evidence cards you choose to share.
Processors
Resend sends email. Stripe processes payments. We do not sell personal information. Sharing with these processors is to provide the service, not a sale.
Public pages
Evidence cards at /e/{id} show a single spoken receipt you shared. Rights-restricted cards omit the quote. Entity pages at /said/{slug} use an allowlist of public fields (organization, speaker, rights-gated quote or pointer) and a stamped terms version. They do not include your email, account id, or input list.
Retention and rights
Account rows and billing ledgers persist while the account exists. You may request access, correction, or deletion of account personal data. Published de-identified entity pages may remain with their license stamp after you cancel; that is not a copy of your list.
Contact
Use the email on your account, or the contact path on this site, to exercise a request.