TrueSignal, Inc. d/b/a SolidChecked · Effective August 17, 2026
What this covers
This policy describes how TrueSignal, Inc. (“we,” “SolidChecked”) collects, uses, and protects information when you use solidchecked.com and related services.
What we collect
From builders (product owners)
- Account information: name, email address
- Identity verification data: processed by Stripe Identity (government ID, selfie). We receive a verification result; we do not store your ID documents.
- Product information: URL, domain, product name
- Payment information: processed by Stripe. We do not store card numbers.
- Customer verification evidence: screen recordings or screenshare sessions you provide to verify active customers
From scans (automated)
- Publicly accessible information from your product’s website: TLS configuration, HTTP headers, privacy policy and terms text, third-party network requests, page content for liveness classification
- DNS records (SPF, DKIM, DMARC)
- Scan results, timestamps, and method metadata
From visitors
- Standard server logs: IP address, browser type, pages visited
- We do not use tracking cookies or third-party analytics
How we use it
- To run checks and generate your product’s record
- To verify your identity as a builder
- To publish your record (only with your explicit consent)
- To re-scan your product on the applicable schedule (every 30 days for free, every 14 days for paid)
- To process payments and manage your account
- To send transactional emails: scan results, re-check notifications, account updates
- To enforce record integrity (revocation on failing re-scans)
We do not sell your data. We do not use your data for advertising. We do not share individual data with third parties except as described below.
What becomes public
When you claim and publish your record, the following becomes publicly accessible: your product name, domain, certification ID, check results (status, method, date), scoreboard, complaint count, and builder name. This is the core function of the service — your record is the product.
Draft records (pre-publication) are private and accessible only via a unique token. Scan results for unclaimed products are never made public.
Third-party processors
- Supabase — database hosting and authentication (US)
- Vercel — application hosting and edge delivery (US)
- Stripe — payment processing and identity verification (US)
- Anthropic — AI-powered document analysis for policy and disclosure checks. Product text is sent for analysis; no personal data is sent.
- Resend — transactional email delivery (US)
Data retention
Check results are retained indefinitely. History is append-only — this is a core design principle. Consecutive passing checks over time are what make a record meaningful.
Account data is retained while your account is active. If you close your account, we delete your personal information within 30 days. Published records remain accessible (they are public documents) but are marked as inactive.
Your rights
You may:
- Request a copy of the personal data we hold about you
- Request correction of inaccurate personal data
- Request deletion of your account and personal data
- Withdraw consent to publish your record at any time (the record will be marked inactive)
To exercise any of these rights, email privacy@solidchecked.com.
Security
We use TLS encryption for all data in transit, encrypted storage at rest via our infrastructure providers, and role-based access controls. We do not store government ID documents, payment card numbers, or passwords in plaintext.
Children
SolidChecked is a business service. We do not knowingly collect information from anyone under 18.
Changes
We may update this policy. Material changes will be posted here with an updated effective date. Continued use of the service after changes constitutes acceptance.
Contact
TrueSignal, Inc.
privacy@solidchecked.com