Privacy Policy
Last updated July 22, 2026 — restructured by data class.
The short version: we sort everything we hold into three classes and treat each differently. Class A — public information and anonymous usage — is the business: we analyze, aggregate, and license what we gather and what anonymous public usage generates. Class B — your account data — is used to run your account and is never sold. Class C — intelligence content customers submit under contract — is never used to train AI models, never sold or licensed, and held in confidence. The details of each class are below, and the enterprise view lives at /trust/.
How we sort data: three classes
Every piece of data we touch falls into exactly one of the classes below. When a rule in this policy applies to one class, it does not quietly leak into another: the broad rights we keep over Class A never extend to Class B or Class C.
Class A — public information and anonymous usage
What it is: the public corpus we gather (news, public data, prediction-market prices), the signals and analysis we derive from it, and anonymous, aggregate usage of the service — counts and patterns. Class A is defined by what it excludes: if a record would identify you, it is not Class A. (Abuse-protection counters are keyed to a truncated hash of your IP address; the raw address is never stored, and those pseudonymous counters are used only to protect the service — they are never licensed or sold.)
What we do with it: this is the business. We analyze, combine, aggregate, license, and sell what we gather and what anonymous public usage generates, and we build products on it. Any sharing happens under contract and a lawful basis. Usage data that would identify you belongs to Class B and carries Class B’s protections, not Class A’s rights.
Class B — your account data
What it is: your email (only if you give it), the topics you track, your plan and billing state, and usage records tied to your account. Card data never touches our systems — checkout runs entirely on Stripe-hosted pages, and we hold only the resulting subscription state.
What we do with it: run your account, send what you asked for, and keep the service secure. Class B is never sold. It is shared only with the service providers who operate the service for us (named below), who may not use it for their own purposes. If Signal Bureau is ever part of a financing, merger, or acquisition, account data may transfer with the business, carrying these same protections with it.
Class C — intelligence content you submit
What it is: the substantive material customers give us so we can work for them — private-desk concerns and watch lists, the context behind a coverage or quote request, and, when a private question mode ships, questions asked in private mode. This is the class an enterprise buyer cares about, so the commitments are hard ones:
- Never used to train AI models. We train no models on Class C content — no such pipeline exists — and we do not permit our subprocessors to use it for model training.
- Never sold, never licensed. Class C content is not part of the Class A data business and never becomes part of it.
- Contracted confidentiality. Private-desk material is held under the confidentiality and data-use terms of the customer’s contract, and those contracted terms supersede our public terms wherever the two differ.
- Deletion on request. Tell us to delete Class C content and we delete it. Retention beyond that is whatever the contract states — we do not keep it longer on our own initiative.
- Excluded from the public quality corpus. Our answer-quality measurement runs internally; anything published is an aggregate with a minimum group size per topic, and private questions are excluded from it entirely.
One honest boundary: the public Answer Engine has no private mode today. Questions asked there are public-mode (see the next section) and are not Class C. Until a private question mode ships, do not put confidential material in a public question.
Questions you ask on the public engine
The text of your public questions is collected so we can answer them and improve answer quality. Each answer is published at an unlisted public link (a random address, shareable by anyone who has it); recent answers may appear on the Ask page. Stale links stop serving the stored answer after roughly 36 hours and redirect to a fresh re-ask. Don’t include personal or confidential information in a public question — and if you need a stored question removed, email lead@evfm.co with the answer link and we’ll delete it from our store, normally within 7 days.
Cookies and analytics
We set no advertising or tracking cookies. Signing in keeps a session in your browser’s local storage, under your control. Aggregate usage measurement comes from our own counters (keyed to truncated IP hashes, never raw addresses) and from our host’s cookieless, aggregate analytics. Stripe’s checkout pages and other providers’ own surfaces operate under their own policies.
Service providers we rely on
To run Signal Bureau we use a small number of infrastructure providers: Cloudflare (hosting and edge delivery), Supabase (application database and sign-in), Anthropic (the Claude models that generate and check answers), Stripe (payments — card data never touches our systems), and Mailgun (transactional email). During answering, question-derived search terms are also sent to Polymarket’s public market-search API to find matching markets. Providers process data only to provide their service to us and may not sell it. The full roster, with roles, lives at /trust/.
Your choices
- Manage your topics any time at /account — a one-tap emailed sign-in link proves the address is yours, then pause, resume, or stop anything.
- Delete your data yourself. On /account, “Delete all my data” removes your email, tracked topics, and coverage requests — instantly, no email to us required.
- Do Not Sell or Share My Personal Information. We do not sell Class B or Class C data. To the extent any disclosure could be considered a “sale” or “share” under applicable law, you can opt out by deleting your data at /account or by emailing lead@evfm.co.
- You can use the Answer Engine without giving us an email at all.
Children
Signal Bureau is intended for adults and is not directed to children under 13.
Changes & contact
We’ll reflect material changes by updating the date above. Questions about privacy? Email lead@evfm.co.
See also our Terms of Use and the enterprise trust posture at /trust/. Informational only — not advice.