Skip to content

Privacy

Last updated 4 October 2026

This notice covers the public site, the signed-in app at app.canitrustthat.com, and the email subscription to new teardowns and blog posts. Questions and requests go to [email protected].

The public site

Public pages set one cookie, theme, and only when you use the theme toggle: its value is light or dark (the chosen colour theme), and it expires after one year. The web server records each request (address, time, page, browser identification) in its logs to operate and protect the service.

Analytics and session recording

The public site and the app send pseudonymous page views to PostHog, Inc., an analytics service in the United States. A page view records the page address and the referring page without the part after "?", the browser, the operating system, the screen size and when you leave the page. Nothing is stored in your browser for page views: each page load gets a new random id, kept in memory until the page closes. In some regions session recording starts by default and the banner lets you stop it: the US states of Alabama, Alaska, Arizona, Arkansas, Colorado, Georgia, Hawaii, Idaho, Indiana, Iowa, Kansas, Kentucky, Louisiana, Maine, Minnesota, Mississippi, Missouri, Nebraska, New Jersey, New Mexico, New York, North Carolina, North Dakota, Ohio, Oklahoma, Rhode Island, South Carolina, South Dakota, Tennessee, Texas, Utah, Vermont, Virginia, West Virginia, Wisconsin and Wyoming, the District of Columbia, Australia, New Zealand, Japan and Singapore. Everywhere else session recording starts after you choose Yes in the banner. In the European Economic Area, in the United Kingdom and wherever your region cannot be determined, page views also start only after you choose Yes; everywhere else page views are on by default. Our own web server chooses these defaults from the country and state codes that Cloudflare, the network in front of our site, adds to each request; the codes are neither stored nor sent to PostHog. A recording records the page layout, clicks, scrolling and mouse movement; all text on the page, the text of element attributes such as titles, labels, image descriptions and placeholders, and everything typed into a field are replaced by asterisks before they are sent; link and image addresses are recorded without the part after "?"; request and response contents and headers are excluded. While recording is on, a random id for the tab is kept in sessionStorage so one recording covers the pages opened in that tab; the browser deletes it when the tab closes. Your browser sends page views and recordings to our own web server, which forwards them to PostHog's US servers without your IP address; they contain no email address or account id, and PostHog's location lookup is turned off. PostHog deletes page views and recordings after 90 days. Your choice in the banner is stored in this browser's localStorage under citt-analytics-consent and applies to later visits. To change it, open Analytics choices at the bottom of any page, set the switches for page views and session recording, and choose Save. With Global Privacy Control or Do Not Track turned on in your browser, nothing is sent to PostHog and the banner asks nothing.

Rate limits by IP address

Your IP address is used to limit how many requests are accepted from it. The web server counts page and API requests per address each second. The app counts the subscription emails it sends per IPv4 address or IPv6 /64 network, and the store searches made without signing in per network each hour. These counts are kept in memory and are lost when the server or the app restarts.

The address is also passed to the subscription service (Ghost, hosted on our own server), which applies its own limit to subscription emails. The plugin's sign-in requests are counted per address in the account database, which records the address and the time of each request.

Accounts in the app

Signing in uses your email address and a code sent to it. The account keeps:

  • your email address, when the account was created and when you last signed in;
  • your sign-in sessions (start, last activity and expiry) and the current sign-in code until it expires, with the number of attempts;
  • the scans you submit, free scans saved to start later, and the address to notify when a scan finishes;
  • the builds you upload, with the file name, size, SHA-256, package id and version;
  • your projects, your questions and their answers, your scrutiny requests and your chats about a scan's findings;
  • the exports you create and each download of them;
  • a usage record of each counted action, with its units and its model cost;
  • a log of account events: uploads, submissions and publications;
  • your plan, its status and renewal date, your Stripe customer and subscription ids and Stripe's events about your subscription;
  • your team and your role in it;
  • your API and plugin tokens (a hash of each secret, the client name, and when each was created and last used), and the plugin's sign-in requests;
  • plan changes made by our staff, with who made each one and why.

Payments for plans are processed by Stripe; CanITrustThat receives the plan, its status and the billing email, never the card number.

Questions and model answers

Answers to questions and scrutiny requests, and the findings of Deep scans, are produced by Anthropic's Claude models. The text of your question and the files of the app's decompiled code that the model reads are sent to Anthropic to produce the answer, including the code of a build you uploaded when you ask about it.

Subscribers

Subscribing to new teardowns and blog posts stores your email address and your newsletter choice. Every email contains an unsubscribe link, and unsubscribing stops the emails.

Work with us form

The form at /work-with-us collects the type of request, the message, the organization if one is given, and the email address entered. The web server sends them, with the page address and the time, in one email to the [email protected] mailbox, with the email address set as the reply-to. That email is the only record of the brief. Your IP address is counted in memory to limit how many briefs are accepted from it. The email is kept in the mailbox for as long as the correspondence it starts.

Your requests

You can ask for a copy of the data held about you, its correction or its deletion by writing to [email protected] from the address concerned.