Privacy Policy
Effective date: June 24, 2026 · Last updated: August 19, 2026
Plain English summary: Your case history, vendor memory, and investigation data never leave your device — they're stored in your browser only. When you run an analysis, the details you submit are sent to our secure analysis engine and are not intentionally retained after the analysis completes. We don't sell your data. We do not require user accounts. We process the information you choose to submit for analysis, along with limited technical and usage information needed to operate and protect the Service.
1. Who We Are
PaySentinel ("we," "us," or "our") is operated as an unregistered sole proprietorship doing business under the name PaySentinel, based in Ohio, United States. Contact us at hello@paysentinelhq.com with any privacy-related questions.
2. Information We Collect
We collect two categories of information:
| Data type | What it includes | Where it's stored |
|---|---|---|
| Analysis submissions | Vendor names, routing numbers, invoice details, email addresses, transaction amounts, and any other details you enter into the analysis forms | Sent to Anthropic for processing. Per Anthropic's standard commercial API policy, this data is not used to train their models, and is automatically deleted from their systems within 30 days. Routing numbers are also checked against a third-party bank routing registry |
| Local app data | Analysis history, vendor memory, investigation queue, usage count, business type preference | Your browser's localStorage only — never transmitted to us |
| Usage analytics | Page views, feature interactions, and general usage patterns via PostHog. We configure analytics not to collect the contents of analysis submissions | PostHog (third-party analytics provider) |
| Server logs | IP address, browser type, request timestamps — standard web server logs | Cloudflare infrastructure, retained per Cloudflare's standard policy |
3. How We Use Your Information
Information you submit for analysis is used solely to generate a fraud risk assessment for that specific submission. PaySentinel does not intentionally store analysis submission contents after processing is complete. We configure our systems to avoid retaining submitted content, subject to limited transient processing and infrastructure logs necessary to operate and secure the Service.
We do not use your submission data to:
- Build profiles about you or your business
- Train machine learning models
- Share with third parties for marketing purposes
- Cross-reference against other users' submissions
4. Local Storage
PaySentinel uses your browser's localStorage to store your analysis history, vendor memory, investigation queue, and preferences. This data exists only on your device. We cannot access it, and it is not backed up to any server. Clearing your browser's site data will permanently delete this information.
If you use PaySentinel on multiple devices or browsers, your local data will not sync between them.
5. Third-Party Services
PaySentinel relies on the following third-party services to operate:
- Cloudflare — our infrastructure provider. Handles DNS, CDN, DDoS protection, and our API worker. Cloudflare may process your IP address and request metadata. See Cloudflare's Privacy Policy.
- Cloudflare Turnstile — bot protection on analysis requests. Processes basic browser signals to verify you're human. No personal data is stored.
- Anthropic — provides the AI technology used to generate analysis results. Analysis submissions are sent to Anthropic for processing under our applicable service agreement. Under Anthropic's standard commercial API policy, data sent to their API is not used to train their models by default, and inputs and outputs are automatically deleted from their backend systems within 30 days of receipt (except where retention is required to enforce their Usage Policy or comply with law). See Anthropic's API and data retention policy for full details.
- Bank routing registry — when you submit a routing number, it's checked against a third-party bank routing registry to confirm the associated financial institution, in addition to standard ABA checksum validation. Only the routing number itself is sent for this lookup.
We do not use advertising networks, social media trackers, or data brokers.
5a. Newsletter and Waitlist Emails
If you voluntarily provide your email address — to join our newsletter, or to join the waitlist for a paid plan — we use it to send you PaySentinel news, product announcements, plan-availability updates, and educational content. Email signups are managed through Buttondown, our email service provider. You may unsubscribe at any time using the link in any email we send, or by contacting us directly. We retain your email address until you unsubscribe or request deletion, subject to applicable legal requirements.
6. Cookies
PaySentinel does not use tracking cookies. We use localStorage (not cookies) for app functionality. Cloudflare may set a technical cookie (`__cf_bm`) as part of its bot-management and security processes. Cloudflare processes information associated with this cookie as described in its own Privacy Policy.
7. Data Retention
- Analysis submissions — not intentionally retained by PaySentinel after the analysis response is returned. Anthropic, which processes the submission to generate the analysis, automatically deletes it from their systems within 30 days by default and does not use it to train their models; see Section 5 for details
- Local app data — retained in your browser until you clear it or use the "Clear all" function within the app
- Server and infrastructure logs — retained for the period provided by our infrastructure providers and applicable service configuration
- Analytics data — retained in aggregated, anonymized form
8. Data Security
All analysis submissions are transmitted over HTTPS. Our API worker runs on Cloudflare's infrastructure with TLS encryption in transit. We are not designed to store submission data long-term, which limits the risk of a data breach exposing your payment details.
Your local app data is only as secure as your device and browser. We recommend clearing your PaySentinel data if you use a shared computer.
9. Children's Privacy
PaySentinel is not directed at children under 13 and we do not knowingly collect personal information from children. If you believe a child has submitted information through our Service, please contact us and we will take appropriate steps.
10. Your Rights
Since we do not maintain user accounts or store personal data on our servers, most data subject requests do not apply in the traditional sense. However:
- Access and deletion of local data — you can view and delete all locally stored data directly within the app at any time
- Submission data — not retained, so there is nothing to access or delete after the analysis completes
- Analytics opt-out — if you have Do Not Track enabled in your browser, we honor it
If you are a resident of California, the EEA, or another jurisdiction with specific privacy rights and have questions about how those rights apply to your use of PaySentinel, please contact us at hello@paysentinelhq.com.
11. Changes to This Policy
We may update this Privacy Policy as the Service evolves. When we do, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically. If a change materially affects how we handle personal information, we will provide additional notice where required by applicable law.
12. Contact
Questions, concerns, or requests related to this Privacy Policy can be directed to:
hello@paysentinelhq.com