NakedSignal

Privacy.

What nakedsignal.com collects when you read it, when you use the change check, and when you write to us.

Effective and last updated

Who is responsible

CareerLoop Inc. (NakedSignal), a Delaware corporation and the company behind NakedSignal (“we”), is responsible for the personal information described here. You can reach us through the contact form; every request about your information goes there too.

Reading the site

The site is a set of static pages. It has no user accounts and no log-in.

  • Request data at our host. Vercel serves the site. Like any web server it receives what every browser sends with a request (IP address, browser and operating system, page requested, time) and uses it to deliver the page and protect the service against abuse.
  • Page counts. We count page views with Vercel Web Analytics, which sets no cookies. For each page view it records the page, the referring page, the country and region, browser, operating system and device type. Visitors are told apart by a hash of the incoming request that is discarded within one day, so we see totals and trends, not individuals.
  • Action counts on the change check and the free calculators. On the check and the calculators we also count a few actions, each recorded the same cookieless way as a page view of an address starting /_event/: trying the public example, opening a file, pressing the payment or invoice link, using a calculator, and following a calculator's link to the check or its file template. Each is counted at most once per page visit. A count carries the name of the action only: never your file, its name, anything you type or any result.
  • Your theme choice is kept in your own browser and never sent to us.

No cookies of any kind; no advertising, tracking pixels, tag managers or social widgets; no fonts, scripts or embeds from other companies' servers. We do not sell or rent personal information.

The change check

  • Your file stays on your computer. The check reads your file and does every calculation inside your browser. The file, the pair IDs and the results in it are never uploaded to us or anyone else. The page's security settings stop it from connecting to any server but ours, and about your check it sends ours only the two things below (besides the page and action counts described above, which hold nothing from your file).
  • Use your own pair IDs. Never put a patient name, record number or other patient identifier in the file. The check does not need one.
  • Payment. If you buy a full report you pay on a page run by Stripe. Stripe collects your payment details and the email and billing details its form asks for, and processes them under its own privacy policy. We receive from Stripe a record of the payment (amount, date, the email and billing details you gave, and the last four digits and brand of the card); we never see your full card number. After payment your browser sends us the payment reference Stripe gave it, we ask Stripe whether that payment completed, and we tell your browser yes or no and when the report stops being unlocked (30 days after payment). We keep no copy of that exchange beyond Vercel's ordinary request logs. Your browser keeps the payment reference in its local storage so you can come back within the 30 days; clearing your browser data removes it.
  • The Registry (optional, off unless you choose it). After a check you may contribute a summary of your change to the Analyser-Change Registry. Nothing is sent unless you mark the consent box and press the button, and you see the exact summary first. It holds, for each test: the test name and unit, the old and new system names as written in your file, the number of pairs used, the comparison line, the average difference and the difference at each decision line, and how many results crossed each line; any count from 1 to 4 (or below the minimum you set) is withheld. It holds no pair IDs and no individual results. The summary reaches us by email. If your system names name your laboratory or a person, edit them in your file before sending. Contributing is never a condition of buying.

Writing to us

When you send the contact form we receive what you entered: your name, work email, organisation, and optionally your role, sector, topic and message. It reaches us by email. We use it to reply and to carry on the conversation you started.

Why we may use it

  • Delivering and protecting the site, and counting page views: our legitimate interest in running a secure site and knowing which pages are read.
  • Contact form and the emails that follow: our legitimate interest in replying to a message you chose to send.
  • Payment and unlocking the report: performing the contract you entered when you bought it, and keeping the records the law requires.
  • Registry contribution: your laboratory's choice to contribute under the Registry terms. A summary with counts below 5 withheld is designed not to identify anyone; where it still holds personal information (for example a person's name typed as a system name), we delete that part on request.

Who processes it for us

Vercel (hosting, the two check functions, page and action counts), Resend (delivering form messages and Registry summaries), Google (our mailbox) and Stripe (payments). They may process information in the United States. We are a United States company, so what you send us is processed in the United States. Where the law requires a transfer safeguard for a provider, we rely on that provider's data processing terms and the safeguards they contain.

If our company is bought by or merged with another company, or sells its business, what we hold passes to the new owner as part of that business. The new owner must keep the promises in this notice, including your rights below. Passing it on in this way is not a sale of personal information.

How long we keep it

The site has no database. Its functions store nothing they receive. What is kept, where, and for how long:

  • Contact messages and our replies are emails in our mailbox at Google. We keep them as correspondence and do not delete them on a schedule; we delete them when you ask. Resend, which delivers the form to us, keeps a log of each email it sent for 30 days (Resend pricing, “Data retention”).
  • Payment records stay in our Stripe account. We keep them for as long as the account exists, because tax and accounting rules require a record of every sale; we do not delete them on request for that reason. Stripe keeps its own records under its privacy policy.
  • The payment check stores nothing on our side. The payment reference sits in your browser's local storage until you clear it, and the page removes it itself on your first visit after the 30 days have passed.
  • Registry summaries are emails in our mailbox, kept for the life of the Registry under its terms (with the same 30-day Resend log); personal information found in one is deleted on request.
  • Request logs at Vercel. On our current Vercel plan the logs of the site's functions are kept for one hour (Vercel runtime logs, “Limits”). To limit abuse, each function keeps a short one-way hash of the caller's address in its working memory, which is cleared whenever Vercel restarts the function; the hash is never written to disk or to a log.
  • Page and action counts are kept by Vercel; on our plan the guaranteed reporting window is one month, and Vercel may keep the data longer (Vercel Web Analytics limits).

Your rights

You can ask what personal information we hold about you, ask us to correct or delete it, or object to how we use it, through the contact form. We answer within one month. Depending on where you live, you may also complain to your data protection authority. The site is for professionals and is not directed at children.

Changes

If what the site collects changes, we update this page before the change takes effect and change the date at the top. See also security and data handling, the terms of use and the change check's terms.