Privacy Policy

Last updated: March 24, 2026

SignalBridge ("we," "us," or "our") operates the SignalBridge platform (the "Service"), an AI-powered startup scoring and analysis tool. This Privacy Policy describes how we collect, use, disclose, and protect your information when you use our Service.

Data Controller: SignalBridge is the data controller responsible for your personal data. You can contact us at privacy@signalbridge.app for any data protection matters.

1. Information We Collect

1.1 Account Information

When you sign in via Google or GitHub OAuth, we receive and store your name, email address, and profile picture as provided by the OAuth provider. We do not receive or store your Google or GitHub password.

1.2 Usage Data

We collect information about how you use the Service, including:

  • Companies you search for and scores you generate
  • Scores you save, portfolios you create, and watchlists you maintain
  • Investor theses, reviews, comments, and other content you submit
  • Feature interactions and preferences you configure
  • Referral activity, including your unique referral code and who referred you
  • Webhook URLs you register for programmatic notifications
  • Push notification subscriptions (browser endpoint and encryption keys)

1.3 Technical Data

We automatically collect IP addresses, browser type, device information, and request timestamps for rate limiting, security, and abuse prevention. Server logs are retained for up to 90 days.

1.4 Payment Information

Payment processing is handled entirely by Stripe. We do not receive or store your credit card number, bank account details, or other payment credentials. We store only your Stripe customer ID, subscription ID, tier, and subscription status to manage your account.

1.5 API Key Data

If you create API keys, we store a SHA-256 cryptographic hash of each key. The full key is displayed only once at creation and is not stored or recoverable by us.

1.6 Company Data (Inputs for Scoring)

When you request a score, we collect the company name and any related information you provide. We then gather publicly available data about that company from third-party sources (see Section 3) to generate a score. The company data processed is about organizations, not individuals, though it may incidentally reference publicly available information about founders or executives.

1.7 Enrichment Snapshots

We store historical snapshots of enrichment data gathered from third-party sources for each scored company. These snapshots include the source, data retrieved, fetch timestamp, and confidence metadata. Snapshots are used for trend analysis, score comparison, and benchmarking. They contain company data (not personal user data) and are retained in our database with configurable expiration periods.

1.8 Webhook Configuration

If you register webhooks for programmatic notifications, we store your webhook URL and an HMAC secret used to sign payloads. Webhook URLs may point to your own servers or third-party services. We do not log the content of webhook deliveries.

2. How We Use Your Information

We use your information for the following purposes:

  • Service delivery: To generate scores, maintain your account, and provide platform features
  • Billing: To process subscriptions and manage tier-based usage limits
  • Notifications: To send score change alerts for watched companies and transactional emails (e.g., account changes, digest summaries)
  • Security: To enforce rate limits, detect abuse, prevent fraud, and protect the integrity of the Service
  • Error diagnosis: To identify and resolve bugs, outages, and performance issues
  • Service improvement: To understand usage patterns and improve features (using aggregated, non-identifying data)

We do not use your personal data for advertising, behavioral profiling, or sale to third parties.

3. Third-Party Services and Sub-Processors

We share data with third-party service providers solely as necessary to operate the Service. These providers act as data processors on our behalf:

3.1 Infrastructure and Hosting

  • Vercel — Application hosting and edge functions
  • Neon — PostgreSQL database hosting
  • Upstash — Redis caching (optional; used when configured)

3.2 Authentication

  • Google — OAuth authentication provider
  • GitHub — OAuth authentication provider

3.3 Payments

  • Stripe — Payment processing. Stripe acts as an independent data controller for payment data. See Stripe's Privacy Policy.

3.4 AI Processing

  • Anthropic (Claude API) — AI-powered scoring and analysis. When you request a score, enrichment data about the company (gathered from public sources) is sent to Anthropic's API for analysis. Anthropic does not use API inputs to train its models. See Anthropic's Privacy Policy.

3.5 Data Enrichment Sources

To generate scores, we query publicly available data from the following sources. Company names and identifiers (not your personal data) are sent to these services:

  • NewsAPI — Recent news articles
  • GitHub API — Public repository data
  • Crunchbase API — Company and funding data
  • Proxycurl — LinkedIn company profile data
  • ProductHunt API — Product launch data
  • Twitter/X API — Public social media presence
  • crt.sh — Certificate transparency logs (infrastructure signals)
  • Algolia (Hacker News) — Public discussion mentions
  • npm Registry — Open-source package data
  • Y Combinator Directory — Accelerator participation data

3.6 Communications and Monitoring

  • Resend — Transactional email delivery
  • Sentry — Error monitoring. Sentry may incidentally capture IP addresses or request metadata when logging errors.

We do not sell, rent, or trade your personal information to any third party.

4. AI Processing and Automated Decision-Making

SignalBridge uses Anthropic's Claude API to generate company scores and analysis. When a score is requested:

  • Publicly available company data gathered from enrichment sources is sent to the Claude API
  • The AI generates a score, category ratings, strengths, risks, and insights
  • AI outputs are validated and structured before being stored or displayed

Important: AI-generated scores may contain inaccuracies, reflect outdated information, or omit relevant factors. Scores are not verified by human analysts and do not constitute investment advice, financial guidance, or professional recommendations of any kind. You should not rely solely on AI-generated scores for business, investment, or hiring decisions.

No automated decisions are made about you personally based on AI scoring. Scores evaluate companies, not individuals.

4.2 Anonymized Training Data

We may use anonymized, aggregated scoring data to improve our scoring methodology and generate market insights. When data is used for this purpose, it is stripped of user identifiers and cannot be traced back to individual users. Training examples derived from scoring data are flagged with an anonymization status and quality level.

4.3 Autonomous Analysis Agents

The Service uses internal autonomous agents ("Colony") that analyze aggregate scoring trends and evolve their analytical capabilities over time. These agents operate at the system level and do not access, store, or process individual user data. Agent knowledge is derived from anonymized, aggregate patterns only.

5. Data Retention

We retain different categories of data for different periods:

  • Account data (name, email, profile): Retained for the duration of your account plus 30 days after deletion
  • Score results: Retained for up to 2 years or until account deletion
  • Search history: Retained for up to 1 year; you may delete entries at any time
  • API keys (hashed): Retained until revoked, plus 90 days for audit purposes
  • Payment records: Retained for 7 years as required for tax and legal compliance
  • Server logs: IP addresses, request metadata retained for up to 90 days
  • Enrichment cache: Cached for 24–72 hours for performance; not long-term stored
  • Error monitoring data (Sentry): Retained for up to 90 days
  • Email delivery records (Resend): Retained for up to 30 days
  • Enrichment snapshots: Historical company enrichment data retained with configurable expiration; expired snapshots are periodically purged
  • Referral data: Retained for the duration of both the referrer and referred user accounts
  • Webhook configurations: Retained until you delete them or your account is deleted
  • Push notification subscriptions: Retained until you unsubscribe or your account is deleted

When you delete your account, we purge your personal data within 30 days. Scores you generated may be retained in de-identified form (with your user ID removed) for public leaderboard and aggregate analytics purposes. Because scores contain company names and publicly available business data, this de-identified data is not fully anonymous and is treated with appropriate safeguards.

6. Cookies and Local Storage

We use the following cookies and browser storage:

  • Session cookies: Required for authentication via NextAuth. These are essential cookies necessary for the Service to function.
  • Cookie consent preference: Stored in localStorage to remember your consent choice.

We do not use third-party advertising cookies, tracking pixels, or behavioral analytics cookies. Sentry's error monitoring SDK may set performance-related cookies when configured; these are non-essential cookies and are only set with your consent.

You can manage your cookie preferences at any time by clearing your browser cookies or adjusting your browser settings. You may also opt out of non-essential cookies via the cookie consent banner displayed on your first visit. You can manage email notification preferences (including digest emails) in your account settings, or unsubscribe via the link in any email we send.

7. Security

We implement industry-standard security measures to protect your data, including:

  • HTTPS/TLS encryption for all data in transit
  • SHA-256 hashing for API keys (full keys are never stored)
  • CSRF protection on state-changing requests
  • Rate limiting to prevent abuse
  • Security headers (HSTS, CSP, X-Content-Type-Options, X-Frame-Options)
  • OAuth-based authentication (no passwords stored)

While we take reasonable steps to protect your information, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security.

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

8.1 All Users

  • Access: Export all your data via Settings → Export Data, or through the GET /api/account/export endpoint
  • Deletion: Delete your account and all associated data via Settings → Delete Account, or through the DELETE /api/account endpoint. This action is irreversible.
  • Rectification: Update your profile information through your account settings

8.2 European Economic Area (EEA), UK, and Switzerland Residents (GDPR)

Our legal bases for processing your personal data are: (a) performance of our contract with you (account management, service delivery), (b) legitimate interests (security, abuse prevention, service improvement), and (c) your consent (where applicable, such as cookie consent).

In addition to the rights above, you have the right to:

  • Object to or restrict processing of your personal data
  • Data portability (receive your data in a structured, machine-readable format)
  • Withdraw consent at any time where processing is based on consent
  • Lodge a complaint with your local data protection supervisory authority

Data may be transferred to the United States where our infrastructure providers operate. We rely on Standard Contractual Clauses (SCCs) and the EU-U.S. Data Privacy Framework where applicable to ensure adequate protection for international data transfers.

8.3 California Residents (CCPA/CPRA)

Under the California Consumer Privacy Act and California Privacy Rights Act:

Categories of personal information we collect:

  • Identifiers: Name, email address, IP address, unique account ID
  • Commercial information: Subscription tier, transaction history, API key usage
  • Internet/electronic activity: Search history, scores generated, feature usage, browser type
  • Professional information: Investor type, accreditation status (if provided)

Sources: Directly from you, from OAuth providers (Google, GitHub), and automatically via server logs.
Business purposes: Service delivery, billing, security, service improvement.
Third parties receiving data: Sub-processors listed in Section 3 (infrastructure, payments, AI processing, enrichment, communications).

Sensitive personal information: We may collect account login credentials (via OAuth tokens) and precise geolocation (IP-derived, city-level only for rate limiting). We do not use sensitive personal information for purposes beyond those authorized under CPRA. You have the right to limit our use of sensitive personal information to what is necessary to provide the Service.

Your rights:

  • Right to Know: You may request the categories and specific pieces of personal information we have collected, the sources, the business purposes, and the categories of third parties with whom we share it.
  • Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
  • Right to Correct: You may request correction of inaccurate personal information.
  • Right to Opt-Out of Sale/Sharing: We do not sell or share your personal information for cross-context behavioral advertising. No opt-out is necessary.
  • Right to Limit Use of Sensitive PI: You may request that we limit our use of sensitive personal information to what is necessary for the Service.
  • Non-Discrimination: We will not discriminate against you for exercising any of these rights.

Opt-out preference signals: We honor Global Privacy Control (GPC) and similar browser-based opt-out preference signals as valid opt-out requests under applicable law.

To exercise these rights, contact us at privacy@signalbridge.app or use the self-service tools in your account settings. You may also designate an authorized agent to submit requests on your behalf by providing written authorization to privacy@signalbridge.app. We will verify your identity before processing any request by confirming your email address associated with your account. We will respond to verifiable requests within 45 days.

8.4 Other U.S. State Privacy Laws

If you reside in Colorado, Connecticut, Virginia, Oregon, Texas, Montana, or other states with comprehensive privacy laws, you may have additional rights including:

  • Right to opt out of profiling that produces legal or similarly significant effects
  • Right to opt out of targeted advertising
  • Right to appeal a denied privacy request

We honor universal opt-out preference signals (such as Global Privacy Control) as valid opt-out requests in all applicable jurisdictions. To exercise any rights or appeal a denied request, contact us at privacy@signalbridge.app. We will respond within the timeframe required by your state's law (typically 45 days).

8.5 Other Jurisdictions

If you reside in Canada (PIPEDA), Brazil (LGPD), or another jurisdiction with applicable data protection laws, you may have similar rights. Contact us at privacy@signalbridge.app to exercise them.

9. Children's Privacy

The Service is not directed to individuals under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will take steps to delete it.

10. Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify relevant supervisory authorities as required by applicable law (including within 72 hours under GDPR). Where the breach is likely to result in a high risk to affected individuals, we will also notify those individuals without undue delay via email and/or a prominent notice on the Service.

11. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify registered users via email at least 30 days before the changes take effect, except where changes are required by law, court order, or to address an urgent security concern, in which case changes may take effect immediately. The "Last updated" date at the top of this page indicates when this policy was last revised. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

12. Contact Us

For privacy-related questions, data requests, or concerns, contact us at:

  • Email: privacy@signalbridge.app

We will respond to privacy inquiries within the timeframe required by applicable law (30 days under GDPR, 45 days under CCPA/CPRA, or as otherwise required).