The rules, written down.
Five documents, one page each, all public. We keep this index short on purpose — the privacy policy, the terms of service, the cookie policy, the sub-processor disclosure, and the publisher agreement.
Privacy Policy
What we collect, why we collect it, who processes it for us, and how rights requests are handled. Written to be read, not skimmed.
Terms of Service
The service we provide, what's yours vs. ours, how payments, refunds, and notifications work today — written to the product as it ships, not as it's planned.
Cookie Policy
The real storage inventory — what's strictly necessary, what's consent-gated analytics, and the reserved classes nothing runs under. How to manage what's set, and by whom.
Publisher Agreement
For catalogue publishers: the application fee, content licence, publication and versioning, revenue share, payouts, and termination. Accepted at application.
Sub-processor List
Vendor disclosure for procurement review: hosting, auth, payments, email, AI model providers, maps and travel data, consent-gated analytics, and observability — including integrations disclosed ahead of launch.
Prior versions
Every policy states its effective date and version. Need an earlier effective version for a procurement review? Request it and we will send a copy.
Request a version →Data processing terms
Processing, transfer, and redline terms are contract-specific until a maintained legal source publishes broader terms. Procurement confirms scope.
Request terms →Data subject requests
Export, delete, amend, or object to processing through the privacy request flow. Response timing is governed by applicable law and maintained legal terms.
Open a request →Something here unclear, or something you'd like changed? Email legal — we read everything.