Privacy
Public-source audit data
The public audit surfaces use publicly accessible source material. They do not require account credentials and do not intentionally collect private customer documents.
The SaaS exit scanner stores public-source URLs, short evidence snippets, fetch metadata and conservative classifications needed to reproduce its report. Raw fetched page bodies are not persisted by the scanner.
Private pilot inquiry forms (#004 and #005)
If you choose to submit a paid-pilot inquiry, the form sends the work email address you enter, the hostname from the public company/service URL you enter, the selected inquiry type, a fixed form variant and the receipt time to the Factory's Vercel-hosted lead endpoint. The full company URL is reduced to its hostname before the lead record is written. The form requires explicit consent and includes a bot-trap field.
These fields are used only to receive and respond to the inquiry, confirm scope and pricing, and distinguish the requested pilot. Do not submit credentials, private documents, personal notes or sensitive information.
The current Stage A endpoint does not write inquiries to an application database; it writes the minimized lead record to the hosting function's operational logs. Those logs are processed and retained by the hosting provider according to the provider/account configuration. Because this pilot does not yet expose a self-service account or record store, there is no self-service access or deletion control. Do not submit the form unless this limited Stage A handling is acceptable.
Product measurement
Minimum application-level KPI events use fixed event names and do not intentionally include page content, email addresses, cookie values, localStorage values, advertising identifiers or user-created identifiers. Synthetic QA traffic is marked separately and must not be counted as genuine demand.
No cookies, localStorage or advertising identifiers are used by this public MVP for its application-level KPI events. Hosting and analytics providers may process ordinary network metadata under their own infrastructure policies.