Legal

Privacy.

Data-minimization is architecture here, not policy. This page describes what we process, what we keep, and what we never do.

Last updated 2026-07-25

What we process

To run a prediction cycle we read the table you supply or the objects your connector returns. That data is processed for the run and then discarded.

What we retain

Engine-derived facts (scores, factors, lift, calibration, gate verdicts), the column metadata from the run manifest, and entity IDs. Entity IDs are retained deliberately — an action cannot target an account without one.

What we never do

  • We do not train models on your data.
  • We do not persist raw input rows after a run completes.
  • We do not permit bulk export beyond your own entities.

Isolation

Every tenant-scoped table carries a tenant identifier and a row-level security policy, set per transaction. Counterfactual access is per-tenant scoped and rate-capped.

Sub-processors

We use infrastructure providers for hosting, database, background execution, authentication, and connector credential storage. Connector tokens are held by the credential provider, never in our database.

Contact

Questions about this policy: sales@hunter-seeker.net

Privacy · Hunter-Seeker