Legal
Privacy Policy
Effective date: April 1, 2025 · Version 1.0
1. Who We Are
SignalScope is a financial diagnostic platform operated by CEO Sightline LLC ("we," "us," or "our"). This Privacy Policy explains what information we collect, how we use it, and what controls you have over it. If you have questions, contact us at support@ceosightline.com.
2. Information We Collect
We collect the following categories of information when you use the Service:
- Account information. Your name and email address, collected when you register. Your password is stored in hashed form and is never readable by us.
- Financial data. The figures and files you submit when running a diagnostic. This data is used solely to generate your analysis and is not shared or sold.
- Billing information. Payment details are collected and stored by Stripe, our payment processor. We do not store card numbers or full payment credentials on our servers.
- Usage and session data. Standard technical information such as browser type, IP address at time of submission, and interaction logs, used to operate and secure the platform.
- Confirmation records. When you confirm your submitted data before a diagnostic run, we record a cryptographic hash of that data, a timestamp, your IP address, and your browser user-agent. This record contains no financial data — only proof that a confirmation occurred.
3. How We Use Your Information
We use the information we collect to:
- generate your diagnostic analysis and produce your reports;
- operate, maintain, and secure the platform;
- process payments and manage your subscription;
- send service-related communications (account confirmation, receipts, product updates); and
- fulfill legal obligations, including maintaining audit records as permitted by law.
We do not use your data for advertising. We do not sell your personal information to any third party. We do not use your submitted financial data to train AI models.
4. AI Processing
SignalScope uses a rules-based scoring engine to calculate each diagnostic dimension. The written narrative explanations in your reports are generated by an external AI language model (Claude, by Anthropic) using the financial figures you submit.
Your data is transmitted to Anthropic solely to produce your diagnostic narrative. It is processed under Anthropic's data processing terms and is not used to train any AI model. The AI does not make determinations — it explains the output produced by our rules-based engine.
5. Aggregated Benchmarking (Opt-In Only)
You may choose to contribute anonymized data to our industry benchmarking program. This is strictly opt-in — it is disabled by default and has no effect on your use of the Service. You may withdraw consent at any time through your account settings.
When you participate, only derived, anonymized diagnostic signals are included. No raw financial figures, business names, account identifiers, or personally identifiable information are ever shared or published. It is not possible to identify an individual business from any aggregated output. Anonymized data already incorporated into published aggregates cannot be retroactively removed, as it contains no individually identifying information.
6. Data Sharing
We share information only in the following limited circumstances:
- Service providers. We engage Stripe (payments), Anthropic (AI inference), and infrastructure providers to operate the platform. Each is engaged under appropriate data handling agreements and may access only the information necessary to perform their function.
- Legal compliance. We may disclose information if required to do so by law, court order, or governmental authority, or to protect the rights, property, or safety of CEO Sightline LLC, our users, or the public.
- Business transfers. In the event of a merger, acquisition, or sale of assets, user data may transfer as part of that transaction. We will notify affected users prior to any such transfer.
We do not sell, rent, or trade personal information. We do not share financial data with any advertising networks or data brokers.
7. Shared Report Links
You may generate shareable links to your diagnostic reports. These links are token-gated, expire after 90 days, and may be revoked by you at any time. When you share a link, the recipient can view the report but cannot access your account or other data. You are responsible for managing who receives share links.
8. Data Retention
We retain your data for as long as your account is active. When you delete your account:
- Immediate deletion. Your account, diagnostic runs, uploaded data, and active share links are permanently removed upon confirmation.
- Scheduled deletion. Your account is locked immediately and all data is removed following a 45-day recovery window.
Following either deletion path, limited non-financial confirmation records — consisting of timestamps, cryptographic hashes, and session metadata only — are retained for up to three years. These records contain no financial figures and exist solely to establish that a confirmation event occurred, which may be relevant to legal claims. After three years, these records are automatically purged.
Legal acceptance records (evidence of your agreement to these Terms) are retained independently of account deletion, as they may be relevant to the establishment or defence of legal claims.
9. Your Rights
Depending on your location, you may have rights under applicable privacy law (including GDPR and CCPA) to:
- Access. Request a summary of the personal information we hold about you.
- Correction. Request correction of inaccurate information.
- Deletion. Request deletion of your personal data (subject to lawful retention obligations).
- Portability. Request a copy of your data in a machine-readable format.
- Objection. Object to or restrict certain processing activities.
To exercise any of these rights, you may delete your account directly through account settings, or contact us at support@ceosightline.com. We will respond to verifiable requests within the timeframes required by applicable law.
10. Security
We implement reasonable technical and organizational measures to protect your data against unauthorized access, disclosure, or destruction. These include encrypted storage, access controls, and secure transmission protocols. No system is perfectly secure, and we cannot guarantee absolute security. In the event of a data breach that affects your rights, we will notify you as required by applicable law.
11. Cookies and Tracking
We use essential session cookies required to operate the platform (authentication, CSRF protection). We do not use third-party advertising cookies or behavioral tracking. Analytics, if used, are limited to aggregated, non-personally-identifiable usage data to understand how the platform is used.
12. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected information from a minor, we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by updating the effective date above and, where appropriate, by direct notice to your registered email address. Continued use of the Service following notice of a material change constitutes acceptance of the revised Policy.
14. Contact
Privacy questions and data rights requests may be directed to:
CEO Sightline LLC
support@ceosightline.com