Privacy, in plain English
We read portal data with the read-only scopes you approve; we never write to your portal. Raw API responses are discarded once your audit completes -- we keep only the computed metrics shown in your report. Tokens are encrypted at rest and deleted on request or after 12 months of inactivity. Every email we send includes a working unsubscribe and a "delete my audit and data" link.