Privacy Policy

Last updated: 2026-07-10

EvalRank has no public account or authentication flow. This policy describes anonymous website and API requests plus the explicit retention choice for decision receipts.

1. Anonymous requests

Public pages and API routes do not require a profile or credential. Delivery, rate limiting, abuse prevention, and operational logging may process request metadata such as IP address, user agent, path, timing, and error details. The EvalRank web application does not set tracking or authentication cookies.

2. Decision queries

A share=false decision returns a receipt to the requesting page without retaining it under a replayable receipt URL. A share=true decision repeats the identical query and retains the public-safe receipt under a content-addressed ID.

Anyone with a shared receipt URL can retrieve its query, result, evidence, freshness, snapshot, and methodology. Do not submit personal, confidential, regulated, or secret information.

3. Retention

Shared receipts are retained so their URLs can replay the same immutable document. EvalRank does not currently publish a self-service deletion guarantee or a fixed deletion period for shared receipts. Private share=false decision receipts are not retained by the public decision route.

4. Service providers

Hosting, network, storage, and observability providers process data needed to deliver and protect the service. Their own terms and lawful retention obligations apply to data they process.

5. Your choices

Use share=false when you do not need a replayable public URL. Do not share a retained receipt URL beyond its intended audience.

Privacy rights and lawful retention exceptions apply as required by applicable law. Public decision fields are not a privacy-request channel.

6. Changes

Changes to processing or retention will be reflected here with a new update date. A product plan or schema alone does not change this policy; running behavior must change first.