Privacy notice · Updated September 3, 2026

Privacy at Pastlight.

This notice explains the information processed in the Pastlight private pilot, why it is used, and the controls available to participating analysts and organizations.

Information

What Pastlight processes.

Account and organization information

Pastlight processes the email address used for authentication, the organization and role associated with the account, and application access records needed to operate an invite-only workspace.

Review material

When an authorized user starts a review, Pastlight processes the organization name, target domains, review dates, research instructions, uploaded or pasted company-provided material, extracted claims, analyst decisions and notes, public evidence, generated findings, and exports.

Operational and demand-validation data

Pastlight processes content-free operational fields such as identifiers, hashes, counts, duration, status classes, token usage, and cost estimates. Public acquisition measurement uses a first-party, pseudonymous visitor identifier plus fixed fields such as entry page, campaign token, CTA, material type, and funnel step. The analytics event schema does not accept document text, claims, filenames, target domains, email addresses, or management notes.

Purpose

Why the information is used.

  • Authenticate invited users and enforce organization access
  • Extract claims, conduct bounded historical research, and produce analyst-reviewable findings
  • Store and deliver authorized evidence and report exports
  • Operate, secure, debug, and measure the reliability and cost of the pilot
  • Understand whether material type and acquisition source relate to review completion and value
  • Respond to support, privacy, deletion, and security requests

Pastlight does not operate an advertising data-sale program. Pilot analytics are used to improve and evaluate Pastlight’s own service.

Service providers

Where processing may occur.

Pastlight uses service providers to deliver the application: Vercel for web hosting and workflows; Supabase for authentication, database, and private storage; Resend for configured email delivery; the Internet Archive for historical web discovery and replay; and OpenAI when optional model-assisted extraction or language review is enabled.

These providers process information needed for their function under their own applicable terms and agreements. Public web sources may also record ordinary network requests. Contact Pastlight before uploading if your organization requires specific provider terms, a data-processing agreement, geographic restrictions, or model-processing controls.

Retention

How long review data remains.

The current private-pilot policy sets a 30-day retention deadline after terminal completion or the last recorded activity for a nonterminal review. A scheduled process deletes eligible review content after safely reconciling workflow state. Authorized users can also request review or organization deletion.

Content-free hashed deletion and lease-reconciliation records may remain for up to 90 days to prove and operate safe deletion. Service providers may retain limited information under their own security, legal, backup, and contractual schedules.

Choices

Access, correction, and deletion.

Workspace controls allow authorized deletion of individual reviews and organizations. To request access, correction, deletion help, or information about Pastlight’s processing, email jbench1234@gmail.com. We may need to verify the requestor’s identity and organization authority.

Browser settings can remove the first-party pilot-measurement cookie. Removing it causes a later visit to receive a new pseudonymous identifier; it does not retroactively identify or erase already aggregated events. Contact us for assistance with a privacy request.

Boundaries

Use only appropriate deal material.

Participants must have authority to submit the material they provide. Do not upload highly sensitive personal information that is not necessary for the historical review. This pilot notice is a plain-language operational summary and may be supplemented by a written agreement with a participating organization.

See security and data handling for implementation controls and pilot terms for conditions of use.