Assertion Labs / Privacy

Privacy, with clear boundaries.

Notice version: 2026-10-03. This local implementation is under review; external sending is disabled.

Contact inquiries

We request your name, email, optional organization, purpose and message to respond to an inquiry. If you request a specific service, its name is included with the message. Named campaign links may attach a public campaign label; arbitrary query values are discarded. The intake stores encrypted request data in PostgreSQL before acknowledging receipt. It retains that payload for at most seven days, deleting it after confirmed handoff. Minimal identifiers and fingerprints support replay protection for 90 days. Local testing uses a Trace stub; live Trace processing is not verified.

Newsletter

Contacting Assertion Labs does not subscribe you. Signup and confirmation mail are currently disabled. Any future subscription requires a separate request and confirmation.

Analytics

The existing website uses host-scoped Google Analytics 4. Local preview disables analytics. Form contents, email addresses, tokens and private identifiers must never be sent to analytics. No session replay is used.

Hosting and requests

The existing host is Fly.io. Existing contact and product services use PostgreSQL and Resend; the new local intake does not send mail. IP-derived counters expire after 15 minutes and are used to limit abuse.

Access, correction or deletion

Use hello@assertionlabs.com for a privacy request. Please do not send sensitive records through the initial contact form.