Privacy
What we hold, and what we don't.
Your email address, your settings, and dated copies of public pages you asked us to watch. That is close to the whole list.
- Last updated
- 26 August 2026
- Data controller
- Prav Durgani, United Kingdom
- Contact
- prav@deltachime.io
- Regulator
- Information Commissioner's Office (UK)
The short version
- We hold your email address, your workspace settings, and dated copies of the public pages you asked us to watch.
- We do not sell personal data, and there are no advertising trackers on this site.
- Payment happens at Stripe. We never see or store your card details.
- Ask for deletion and it is real: one command removes your account and every row attached to it. That behaviour is covered by an automated test, not a promise.
Who is responsible
DeltaChime is run by Prav Durgani in the United Kingdom. For UK and EU data protection law he is the data controller for everything described here.
Every privacy request goes to prav@deltachime.io. There is nobody else to route it to, which is the one advantage of a one-person company.
What we hold
- Your email address
- Used to sign you in, send your briefs, and answer you when you write. It comes from you at sign-up.
- Workspace settings
- The competitors you named, the pages in each Source Pack, and your delivery preferences.
- Captured pages and evidence
- Dated copies of the public pricing and plan pages you asked us to watch, the SHA-256 hash of each copy, and the differences between them. This is what every claim in your brief points to.
- Briefs and delivery records
- The briefs we produced for you, and a log of what was sent where and when, so we can show a brief went out and never send the same one twice.
- Subscription status
- Your plan, whether it is active, and Stripe's identifiers for the subscription. Not your card.
- Sample-brief requests
- If you ask for a free sample brief: the email address and competitor domains you gave, any note you wrote, and a one-way hash of your IP address used to rate-limit the form.
- Server logs
- Cloudflare records requests to the site so faults and abuse can be investigated. Short-lived, and not used to build a profile of you.
The pages we capture are company commercial pages. Now and then one carries a person's name — a quote, a contact line. We do not go looking for it, do not index it, and do not build a profile of anyone from it.
What we do not hold
- Card numbers. Stripe handles payment from end to end and we never receive them.
- Anything behind a login on a competitor's site. We only read pages anyone can open.
- Advertising or cross-site tracking data. Nothing here is shared with data brokers or ad networks, and personal data is never sold.
- Special category data. DeltaChime watches company pricing pages; it has no reason to hold anything about anyone's health, beliefs or politics, and it does not.
Why we are allowed to hold it
- Running your account
- Contract. Without your email address and your competitor list there is no brief to send.
- Keeping it working and safe
- Legitimate interests: debugging, preventing abuse of the forms, and making sure the same brief is not delivered twice.
- Sample-brief requests
- Legitimate interests, and you asked for it. Tell us to delete it and we do, straight away.
- Billing and tax records
- Legal obligation. Financial records have to be kept for a period set by UK tax law, whatever else is deleted.
Who else touches your data
Six suppliers, named honestly: five the product cannot run without, and one that sits on the operator's side and receives nothing about you. It is listed anyway, because a supplier you cannot see is a supplier you cannot check.
- Cloudflare
- Hosts and serves the site, keeps the short-lived server logs, and provides the cookieless analytics.
- Neon
- Runs the Postgres database where your account, settings, captures, evidence and briefs live.
- Clerk
- Handles sign-in. Holds your email address and your session.
- Stripe
- Takes payment and holds your card details. We see the subscription, never the card.
- Resend
- Delivers the email. Sees your address and the contents of your brief.
- Slack
- The operator's own alert channel: scheduler health, and chimes from the operator's own workspace. There is no customer Slack connection in DeltaChime, so nothing of yours — no brief, no chime, no address — ever reaches it.
Several of these are US companies, so some processing happens outside the UK. Each publishes a data processing agreement with the standard contractual clauses and the UK addendum, and that is the basis those transfers rely on. If this list changes, it changes here.
How long we keep it
While your account is active we keep your captures and change history, because that continuous record is the product. How much of it you can browse depends on your plan: 90 days on Solo, 365 days on Pro.
Delete your account and everything attached to it goes within 30 days: competitors, Source Packs, captures, evidence, Chimes, briefs, delivery records and feedback.
Billing records stay longer where tax law requires it. Sample-brief requests are deleted whenever you ask.
Your rights
UK and EU data protection law gives you the right to get a copy of what we hold, correct it, delete it, take it elsewhere in a portable format, and object to how it is being used.
One email covers all of them: prav@deltachime.io. You get an answer within 30 days and usually a great deal sooner. There is no charge and you do not have to justify the request.
Deletion is not a soft flag here. A single command removes a user and every row belonging to them in one transaction — competitors, Source Packs, captures, Chimes, briefs, delivery logs, feedback — and it either completes or rolls back entirely. An automated test proves one customer's data disappears while another customer's is left untouched.
If something goes wrong
If a breach puts your data at risk you get an email: what happened, what was affected, and what has been done about it. Where the law requires it, the Information Commissioner's Office is told within 72 hours.
The security boundary we work insideComplaints
Write to prav@deltachime.io first — it is the fastest route to a fix, and it reaches the person who can make it.
If that does not satisfy you, you can complain to the Information Commissioner's Office in the UK, or to your national data protection authority if you are in the EU.
ico.org.ukChanges to this notice
A material change gets an email at least 14 days before it takes effect. A small correction just changes the date at the top.
The rest of the agreement