Privacy Policy

Version 2026-08-03 · Effective 3 August 2026

How we collect, use, share, and protect your personal data when you use Shingou.

1. Data controller

The controller of your personal data is Adolfo Gastalver Rubio, Sole trader (autónomo), NIF 05294386Q, Carrer de la Igualtat 67, 6-2, 08902 Barcelona, Spain. For any privacy matter, contact contact@shingou.io. This policy is provided under the EU General Data Protection Regulation (GDPR) and Spain’s Organic Law 3/2018 (LOPDGDD).

2. What we collect

  • Account data: your email address (used for passwordless sign-in) and your plan.
  • API-key metadata: a key name, prefix, creation and last-used timestamps, and a hash of the key (never the key itself).
  • Usage data: API request counts and technical logs, including IP address and request metadata, kept for security, abuse prevention, and quota metering.
  • Billing data: if you subscribe to a paid plan, a customer identifier and invoice records. Card details are collected and processed directly by Stripe; we do not store your full card number.
  • Signup attribution: if you arrive through a link we published, the standard campaign tags in that link (utm_source, utm_medium, utm_campaign) and the referring site's domain name are recorded once, when your account is created, so we can tell which channels bring people here. Domain only, never the page you came from. Nothing is transmitted unless you actually sign up.
  • Site analytics: aggregate page views and referring domains via Cloudflare Web Analytics, which sets no cookie and assigns no identifier to you. It cannot follow you across sites and cannot be tied back to your account.
  • Documentation readership: for a short list of public pages (our API docs, research page, integrations page, llms.txt and the MCP endpoint) we keep a daily counter of how many times each was fetched, grouped by a coarse label for the software that fetched it, such as "browser" or the name of a published AI crawler. We keep the counter and the label only. No IP address, no account, no session, no identifier, and never the full browser string. The purpose is narrow: to find out whether AI crawlers and agents actually read the files we publish for them.
  • Communications: messages you send us (e.g. support email).

3. Why we use it, and our lawful bases

  • To provide the Service (accounts, authentication, API access, billing): performance of a contract.
  • Security, abuse prevention, rate limiting, and service improvement: our legitimate interests in running a safe, reliable service.
  • Accounting and tax records: compliance with a legal obligation.
  • Any non-essential cookies or optional communications: your consent, which you may withdraw at any time.

4. Who we share it with (processors)

We do not sell your personal data. We share it with service providers who process it on our behalf under data-processing agreements. The ones that handle personal data are:

  • Supabase: Authentication and database hosting.
  • Resend: Delivery of the sign-in link emails we send you.
  • Google Workspace: The mailbox that receives email you send us, including data-protection requests.
  • Stripe: Payment processing and invoicing.
  • Vercel: Web application and API hosting and delivery.
  • Cloudflare: DNS, network security, and content delivery.

The full sub-processor register lists these alongside the vendors that process the signal pipeline’s public news text and receive no personal data at all. Our Data Processing Agreement covers the contractual terms.

We may also disclose data where required by law or to protect our rights.

5. International transfers

Some processors are located outside the European Economic Area (for example, in the United States). Where personal data is transferred outside the EEA, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an adequacy decision.

6. How long we keep it

We keep account and usage data for as long as your account is active and for a reasonable period afterwards. We retain billing and invoicing records for the period required by Spanish tax and commercial law. Usage records that include an IP address are deleted after 90 days. Aggregate counters that identify nobody, such as daily request totals, are kept indefinitely. When data is no longer needed, we delete or anonymise it.

7. Your rights

You have the right to access, rectify, erase, restrict, or object to the processing of your personal data, and the right to data portability, as provided by the GDPR. Where processing is based on consent, you may withdraw it at any time without affecting prior processing. To exercise any right, email contact@shingou.io. You also have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es) or your local supervisory authority.

8. Cookies

We use only cookies that are strictly necessary for the Service to work, chiefly a session cookie to keep you signed in, and functional cookies set by Stripe and Cloudflare for payment security and network protection. Because these are essential, they do not require consent. One further short-lived cookie is set only when you ask for a sign-in link: it carries the campaign tag described in section 2 across the magic-link round trip and expires after 30 minutes. Our site analytics are cookieless and set no identifier. We do not use advertising cookies. If we introduce tracking or other non-essential cookies in future, we will ask for your consent first and update this policy.

9. Security

We apply reasonable technical and organisational measures to protect your data, including encryption in transit, hashing of API keys, and access controls. No system is perfectly secure, so we cannot guarantee absolute security.

10. Changes

We may update this policy; the version and effective date appear at the top of this page. For material changes we will provide reasonable notice.

11. Contact

Privacy questions or requests: contact@shingou.io.

Change history

Every entry below is checkable against this project’s public commit history. A change history nobody can verify is a claim rather than a record.

  • 2026-08-31 — Data Processing Agreement and the sub-processor register published. Anthropic and Voyage AI added to the register, having previously been absent from the processor list on the Privacy Policy. GitHub moved from that list into the register's no-personal-data section, where it belongs: the Privacy Policy's list is who we share personal data with, and the hash-commitment log contains none. Nothing was removed from disclosure; the register lists every vendor and the Privacy Policy links to it.
  • 2026-08-14 — Terms §5 backed by the billing code: listed prices are VAT-exclusive, the rate is shown before payment, and EU businesses supplying a VAT number are billed under the reverse charge.
  • 2026-08-03 — Current version. Security and data-retention statements aligned with what the system actually enforces.
  • 2026-08-02 — Controller contact address moved from a personal mailbox to contact@shingou.io, so data-subject rights survive any one mailbox.
  • 2026-07-04 — Terms of Service, Privacy Policy and Legal Notice first published.