Cyber Insurance Subjectivity Tracker
Privacy

Privacy

Cyber Insurance Subjectivity Tracker reads the control list you tick or paste in your browser. Nothing you tick, paste or type leaves your browser until you choose to save a clock. It asks for no passwords and no access to anyone's systems, runs no scan, and reads no document.

What a save stores

A saved clock holds the label you give the applicant, the jurisdiction, the target level and add-ons, the start date, the list text (any cell over 300 characters and any email address are removed first, in the browser and again on the server), the gap lines with their checkpoints, and the counts. The notes typed into the control list form stay on the page and are never sent.

The applicant link

A saved clock can have one private applicant link. Only a hash of the link's token is stored. The applicant opens it with no account and reports a line closed with a date, an optional note and an optional name or role. Each report is stored with the time it was made and a salted hash of the network address (never the address itself), to limit abuse. Reports are never changed or removed through the link; the owner of the clock can revoke the link, and the reports already made stay with the clock.

Where it is kept and who can see it

Saved clocks, reports and account details are kept in Supabase in Sydney, Australia (AWS ap-southeast-2), encrypted at rest and in transit. The processors are Cloudflare (hosting), Supabase (the database), Stripe (payment) and SendGrid (sign-in links and the email you ask for). Saved clocks are kept until you delete them or close your account; support opens a saved clock only when you ask it to. The people on your account see your clocks according to their role; the applicant sees only its own schedule, through its link.

Emailing a result to yourself. Where a result offers to be emailed to you, your browser sends only the summary shown on the page: the counts, the titles of the findings raised with their counts, and any coverage notice. The list you pasted, and any name or value in it, is never sent. We store your email address, that summary, when you asked, and whether you ticked the box for a note when the tool adds something new (no more than once a month), with the words of that box. Without the tick you get the one email and nothing else, and your address goes on no mailing list. Every email carries a link that stops them at once; an address that uses it is kept on a do-not-send list so we never write to it again. A request without the tick is deleted after 30 days; with it, it is kept until you unsubscribe and deleted 30 days after that. The email is sent through SendGrid from support@theartofservice.com.

Your rights

Delete a clock, or your whole account, yourself from the account page, or write to support@theartofservice.com.

Counting visits

An anonymous cookie (va) joins page visits to a later sign-up; no third-party analytics run on the site.