Legal

Privacy Policy

Analisa US is built to need as little about you as possible. Most of the site works without an account, the analytics use no cookies and store no IP addresses, and there are no ads or third-party trackers. This page lists everything we do keep.

Last updated

Who we are

The controller of your personal data is Tiago Reis Antunes Unipessoal Lda (NIPC 514657138), Odivelas, Lisbon, Portugal (“we”, “us”). For any question or request about your data, write to [email protected].

This policy covers the hosted service on this website, its public API and its MCP server. If you run the open-source software yourself, you are the controller of the data on your server.

Visitors without an account

To count visits we record, for each visit, the pages viewed, the referring site, campaign tags (utm_*), the browser, operating system and device type, the language, and a country inferred from the browser's time zone. A visitor is identified only by a hash of the request under a random salt that changes every UTC day; the salt is deleted the next day, so visits cannot be linked across days or back to you. We never store your IP address.

Daily AI and API limits are counted against a salted hash of your IP address (a whole /64 block for IPv6), never the address itself.

Legal basis: our legitimate interest in running, securing and improving the site (GDPR art. 6(1)(f)).

If you create an account

We keep what the account needs (legal basis: the contract with you, art. 6(1)(b)):

  • your email address and, if you add one, your name;
  • a password hash (never the password), or the link to your Google account if you sign in with Google — we do not keep Google's tokens or your profile picture;
  • your sessions, each with a short device summary such as “Firefox on macOS” and no IP address;
  • what you save and set up: watchlists, alerts, saved searches, opportunity-fit profiles, reports, API keys (stored only as a hash), team memberships and invitations;
  • supplier screening lists: from an uploaded file we keep only the UEI, CAGE code, name and state columns; the file itself is never stored.

While you are signed in we also record the pages you view and the features you use, linked to your account, to understand what is useful (legitimate interest). If your browser sends Global Privacy Control or Do Not Track, we count those visits and features without your account.

Payments

Paid plans are sold and billed by Stripe. Your card details go directly to Stripe and never reach our servers. We keep your Stripe customer id, the plan, its status, seats and billing period. Stripe keeps the invoices and the payment data as an independent controller under its own privacy policy, and we keep billing records for as long as tax law requires.

If you join a plan's waitlist, we keep the email, the plan and the description you chose, only to write to you when it opens. Ask us and we delete it.

AI features

When you use an AI feature (Ask Analisa, claim checks, search interpretation, where-to-live suggestions, opportunity fit), the text you type and the public data it needs are sent to our AI providers to produce the answer. Do not type personal or confidential information into them.

Ask Analisa conversations are not stored on our servers: your browser keeps them and sends them back with each turn. To avoid paying twice for the same answer we cache some answers under the normalized question (claim checks, where-to-live prompts, short concept phrases), without any link to you.

If you rate an answer, we keep the rating, the reason and an optional comment of up to 280 characters, with email addresses and phone numbers removed.

Emails

We send the emails the service needs (address verification, password reset, a notice if someone tries to sign up with your address, team invitations) and the alerts and digests you turn on. Every alert email has a one-click unsubscribe link. We send no newsletters or marketing.

Cookies and local storage

We use only strictly necessary cookies, so there is no cookie banner:

  • analisa.session_token and analisa.session_data — keep you signed in (up to 30 days);
  • analisa.dont_remember — ends the session when the browser closes, if you chose so;
  • analisa.oauth_state — protects a Google sign-in while it happens.

Your browser's local storage keeps your own preferences (theme, map and compare settings, which digest you have seen). They never leave your device.

Who processes data for us

We do not sell or share personal information, and we do not use it for advertising. These providers process it on our behalf, only to run the service:

  • Contabo GmbH (Germany) — the servers that host the site and its database;
  • a storage provider that keeps the database backups off the server;
  • Stripe — payments, invoices and the billing portal;
  • an email delivery service — sending the emails above;
  • Google — only if you choose to sign in with Google;
  • OpenRouter and the model providers it routes to, and TypeSafe — the AI features above.

Maps load their background tiles from CARTO or Esri directly in your browser, which sees your IP address as any website you load does; we send them nothing about you.

Some of these providers are in the United States. Transfers rely on the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses.

How long we keep it

  • Account data and what you saved: until you delete your account; deletion removes it at once.
  • Visit and feature-use records: 400 days, then only daily totals remain.
  • Sent-email records and finished background jobs: 90 days. Alert matches: 180 days. Read notifications: 90 days.
  • Report PDF files: 30 days.
  • API usage counts: 400 days.
  • Billing records: as long as tax and accounting law requires (up to 10 years in Portugal).
  • Backups: they roll over within weeks, so deleted data leaves them on that schedule.

Your rights

You may access, correct, delete or export your data, restrict or object to how we use it, and withdraw a consent at any time. You can edit your account and delete it yourself from the account page (an active paid plan must be cancelled first). For anything else, write to [email protected]; we answer within one month.

You also have the right to complain to a data protection authority; in Portugal it is the Comissão Nacional de Proteção de Dados (cnpd.pt).

US residents: we do not sell or share personal information as defined by California and other state privacy laws, and we honor Global Privacy Control. The rights above apply to you too.

People in the public data

The site publishes official public records about places and organizations. People appear only where they hold or seek federal office (members of Congress and federal candidates), with information from official sources. Contact names and details in contract notices are removed before loading. If you find information about you that you believe should not be here, write to [email protected].

Security and children

Connections use HTTPS, passwords are hashed with scrypt, API keys and verification tokens are stored only as hashes, and each service reaches the database with the least privilege it needs.

The service is not directed to children under 16 and we do not knowingly collect their data.

Changes

If we change this policy, the date below changes, and we email account holders about material changes before they take effect.

Contact

Tiago Reis Antunes Unipessoal Lda · NIPC/VAT PT514657138 · Odivelas, Lisbon, Portugal

[email protected]