Trust Center
Privacy, security, compliance — in one page
Every legal, security, and operational disclosure is published on this site as both a human page and a machine-readable mirror at a stable /.well-known/ path. Procurement teams, AI agents, and security researchers can all start here.
Legal
What we collect, how long we keep it, who processes it on our behalf.
Use rules for the website, dashboard, MCP server, and Agent Credits.
GDPR Art. 28 DPA template; counter-signed copy on request.
Security
How we protect subscriber email, Stripe customer IDs, and share-token endpoints.
How to report, what's in scope, response SLA, safe harbor.
Canonical disclosure contact + JSON mirror.
Compliance
Stripe, Vercel, Resend, PocketBase/Hetzner, PostHog (EU), GitHub, Cloudflare, Anthropic, Coinbase. Roles + DPAs + regions.
GDPR, CCPA, HIPAA, PCI, SOC2 status; data-residency; retention.
Per-bot rules; training-data posture; CC BY 4.0 license terms.
Transparency
Government data requests, takedown demands, breaches — published yearly with explicit zeros.
Live uptime + freshness signals + last-modified watermarks.
Public log of every signal correction we've issued and the rationale.
Email & Tracking
RFC 8461. Mail to @gitdealflow.com must be delivered over TLS or rejected.
We honor the EFF DNT Policy v1.0 for any browser/agent that sends DNT: 1.