Policy
Privacy Policy
This policy covers the live TitrateLab platform: the research corpus, your account, orders and payments, profiles and reviews, and the on-site assistant. It replaces the earlier pre-launch policy.
Last updated: July 21, 2026. Version 1.0. Operated by TitrateLab, a Delaware LLC.
The short version: we collect what we need to run an account, take a payment, and get an order routed and shipped — plus whatever you choose to add to a public profile or review. We don’t sell your data.
1. What we collect
When you create an account:
- Email address, and — if you use a password — a hashed password (we never store the password itself). If you sign in with Google, we store a Google account identifier instead.
- Whether your email is verified, and account timestamps (created, last login, last seen).
When you set up a profile or place an order:
- Name (display name, and full name for orders), phone number, and a shipping address (street, city, region, postal code, country).
- Public profile fields you choose to add: handle, bio, avatar image, location, website, user title. Anything on a public profile is visible to others.
- Timezone, for scheduling and display.
When you pay:
- Card payments are processed by Stripe. We do not store your full card number; we store a Stripe customer / subscription identifier, the amount charged, and the subscription and billing metadata needed to run memberships and refunds.
- Bitcoin payments involve on-chain transaction data (the addresses and transaction used), which is public by nature.
- Store credit and loyalty / reputation balances tied to your account.
As you use the platform:
- Orders (what, to where, status, history), reviews and COA submissions you post, and moderation flags on them.
- Membership records (plan tier, when Pro was granted or expires, routed-dollar totals used for member perks).
- Assistant and chat queries you send, plus the retrieval context used to answer them (see §3, Anthropic), stored with a session identifier so the assistant can keep context.
- Support-chat messages, if you use the on-site support widget (see §3, Tawk).
Automatically, to run and secure the site:
- IP address, user-agent, requested path, referrer, timestamp on each request — the standard web-server record — plus session cookies needed to log you in, keep your cart, prevent fraud, and rate-limit abuse. We do not load third-party analytics or advertising scripts.
2. What we do not collect
- No raw card numbers — Stripe handles card data; we only see tokens and metadata.
- No third-party advertising or retargeting pixels. Open dev-tools and check.
- No selling, renting, or trading of your personal data, ever.
- No health-history intake. We don’t ask what you’re using or infer it from your chat. The research tools on the site are informational, not a medical intake.
3. Where the data lives (processors)
Our platform and databases run on our own VPS. A small set of service providers each handle only what they need:
- Stripe — card payments and subscriptions. Stripe holds your card data under its own terms; we hold the customer/subscription identifiers and amounts.
- BlockCypher / mempool.space — used to verify Bitcoin payments on-chain. The blockchain itself is public.
- Google — if you choose Google sign-in, Google authenticates you and returns an account identifier; Google’s privacy policy governs that.
- Resend — transactional email (verification, receipts, order and account notices). Resend stores delivery metadata for the addresses it processes.
- Anthropic — the API behind the on-site assistant and chat. Your prompt plus the relevant retrieval context is sent to Anthropic to produce a reply; per Anthropic’s commercial-API terms, that content is not used to train their models.
- Tawk.to — the on-site support-chat widget, if you use it; messages you send through it are processed under Tawk’s terms.
We do not share data with advertisers, data brokers, marketing partners, or the vendors mentioned in our research. We respond to valid legal process when required, push back on anything overbroad, and tell you we received a request unless the order forbids it.
4. Cookies
Default: essentials only — the cookies and local storage needed to log you in,
keep your session and cart, remember your cookie choice (tl_cookie_consent), and
protect the site. We don’t load analytics or advertising scripts today. If we ever
enable optional cookies, the recorded consent value is the gate that decides whether
they fire, and this section changes first.
5. Retention
- Account and order records are kept while your account is open and afterward only as long as needed for legal, tax, accounting, warranty, and fraud-prevention purposes.
- Payment records are retained as required for financial and tax compliance.
- Public content you post (reviews, profile, submissions) remains until you remove it or delete your account, subject to moderation and legal-hold needs.
- Assistant / chat session logs are retained for 90 days, then deleted.
- Server request logs are retained 30 days on a rolling basis (aggregate, IP-free counts may be kept longer). Support correspondence is deleted after 2 years.
- When you delete your account, we delete or de-identify personal data we are not required to keep, promptly.
6. Your rights
Wherever you live (CCPA in California, GDPR in the EU/UK, similar laws elsewhere), you have the rights to know, access, export, correct, and delete the data we hold about you. We honor these regardless of jurisdiction. You can:
- Export your data — a machine-readable copy of what’s tied to your account.
- Correct it — much of it you can edit yourself in account settings.
- Delete your account and associated personal data, subject to records we must legally keep.
- Object to or restrict certain processing, and withdraw consent where processing relies on it.
Email support@titratelab.com to make a request. We may need to verify you control the account before acting.
7. Children
The platform is for adults (see the Terms). We don’t knowingly collect data from anyone under 18, and we delete it if we learn we have.
8. Security
- Passwords are hashed, never stored in the clear.
- Card data is handled by Stripe, not stored on our servers.
- TLS on every connection; no plaintext transport.
- Access to personal data is limited to what’s needed to operate the platform, on a hardened server (firewall, automatic security updates, no unnecessary ports, anomaly monitoring).
- Incident disclosure — if a breach touches your personal data, we email the affected accounts within 72 hours of confirming the incident and post a public note at the top of this page.
9. Changes to this policy
The “last updated” date and version marker advance with every revision. Material changes get a banner at the top of the page for at least 30 days, and if a change materially expands what we collect or how we use it, we email account holders before it takes effect. We don’t quietly revise this policy to permit something we previously said we wouldn’t.
10. Jurisdiction and contact
TitrateLab operates as a Delaware LLC. Disputes touching this policy are governed by Delaware law to the extent not preempted by stronger local data-protection law (CCPA, GDPR, etc.), which we honor regardless of corporate domicile.
- Privacy / data requests: support@titratelab.com
- General: hello@titratelab.com