Trust & Data Posture
Last updated July 22, 2026 · verified against the running system on that date.
This page states how Signal Bureau treats data — in plain English, one claim per sentence, each one true of the system as it runs today. Where the honest answer is “we don’t do that yet,” this page says so instead of implying otherwise. The same commitments are mirrored in a machine-readable JSON block at the bottom of this page, so your agents can read them too.
The three data classes at a glance
- Class A — public information and anonymous usage. The public corpus we gather, the signals we derive from it, and anonymous aggregate usage. Nothing in it identifies you. We analyze, aggregate, license, and sell Class A and build products on it — that is the business, stated plainly.
- Class B — identified account data. Email, tracked topics, plan and billing state, account-tied usage records. Used to run your account. Never sold. Shared only with the subprocessors named below.
- Class C — customer-submitted intelligence content. Private-desk concerns and watch lists, coverage and quote-request context, and private-mode questions when a private question mode ships. The hard commitments below apply to Class C.
The full policy treatment of each class is in the Privacy Policy.
Model training: the Class C prohibition
Class C content is never used to train AI models. We train no models on it — no training pipeline of any kind exists in our system — and we do not permit our subprocessors to use it for model training. Answers are generated by calling a commercial model API; your content is processed to produce your answer, not to teach anyone’s model.
Retention and deletion
- Data lives in our application database (Supabase) until deleted.
- Public answers stop being served at their links after roughly 36 hours; the stored rows remain until deleted.
- Self-serve deletion: on /account, “Delete all my data” removes your email, tracked topics, and coverage requests instantly.
- Stored questions are deleted on request by email to [email protected], normally within 7 days.
- The honest gap: we do not yet publish a fixed calendar retention schedule for stored rows. Until we do, deletion on request is the governing rule, and contracted desks set retention in the contract.
Subprocessors, named
Every third party that touches customer data in operating Signal Bureau, with its role. This list is verified against the code, not against intentions.
- Cloudflare — hosting and edge delivery.
- Supabase — application database and sign-in.
- Anthropic — model inference: answer generation and verification.
- Stripe — payments; checkout runs on Stripe-hosted pages and card data never touches our systems.
- Mailgun — transactional email: confirmations and notifications.
- Polymarket (Gamma API) — public market data source. During answering, question-derived search terms are sent to its public market-search endpoint to find matching markets. We disclose this because most services in our position would not think to.
Incident notification
If we learn of a security breach affecting your data, we tell affected customers promptly — plainly, with what we know, what we don’t yet know, and what we’re doing about it. We do not sit on bad news.
Isolation, stated honestly
Signal Bureau runs on shared infrastructure: one application database serves all customers, with row-level security enabled and every write passing through server-side functions — public keys can neither read nor write the tables. There is no per-tenant physical isolation today. Private-desk isolation is contractual — confidentiality and data-use commitments in the contract — not a separate database. We state this plainly rather than imply an architecture we don’t run.
Availability, stated honestly
The service is continuously operated and monitored by automated patrols; the current patrol verdict is public at /patrol/latest.json. There is no contractual SLA on the public service today, and we will not publish an uptime number we have not measured and committed to. We expect formal service commitments to arrive when metered accounts reach general availability; until then, service commitments for contracted private desks are set in the contract.
How we measure quality without exposing askers
- Answer-quality analysis runs internally.
- Anything published is an aggregate with a minimum group size of three per topic, so no published number can be traced to a single asker.
- Published aggregates carry no question text and no user identifiers.
- Private questions are excluded from the public quality corpus entirely.
Public service and contracted desks: two tiers
The public service — this site, the public Answer Engine, the open API and MCP tools — runs under our standard Terms of Use. Contracted private desks run under negotiated terms: confidentiality, data use, retention, deletion, incident handling, and a data-processing agreement are part of what the contract covers. For Class C content, the contracted terms supersede the public terms wherever the two differ. Public reading surfaces stay free for anyone; charges meter work done on a customer’s behalf.
For your agents: the machine-readable posture
Every commitment on this page is mirrored in the JSON block embedded below (element id trust-posture, schema sb.trust.v1). Fetch this page and parse it — the block and the prose are maintained together, and if they ever disagree, tell us at [email protected] and we’ll fix it and say so.
See also our Privacy Policy and Terms of Use. Questions about this posture: [email protected].