Privacy policy
Draft — not yet reviewed by counsel
This is a beta draft, written to be complete enough for legal review, not yet reviewed by counsel. Do not treat it as final or binding until that review is complete and this frontmatter's status changes.
What we collect
Account information
Your account email, used for sign-in (an emailed one-time code — suo does not use passwords) and for service notices.
Signing in sets a strictly necessary session cookie on the dashboard, good for up to 30 days, so you stay signed in between visits; it is not used for advertising or cross-site tracking, and it goes away if you sign out or let it expire. It also sets a second cookie across usesuo.com that says only that you are signed in, so usesuo.com can take you straight to your dashboard; it holds no account or session data, lasts as long as the session, and is removed when you sign out.
The content you give us
Records you push through the API, and pages our crawler reads from domains you have verified. This is your content, indexed so it can be searched; see Indexes, records and objectIDs.
Crawl snapshots
When our crawler reads a page from a domain you have verified, it stores the raw HTML it fetched alongside the extracted, searchable records, so a crawl run can be inspected or diagnosed after the fact. A snapshot is kept for 90 days after its crawl run, then deleted automatically, and every snapshot from an index is deleted immediately, along with that index's crawl history, when the index itself is deleted.
Query logs
What visitors to your site or app search for, so you can read it back in Reading analytics:
- The query text itself, and which result (if any) was clicked.
- The caller is not identified: never stored as a raw IP address, and never as an identifiable user ID. To count distinct searchers, suo runs the visitor's IP address through a one-way hash salted with a value that rotates every day; only that daily hash is stored, the IP address itself is never written to disk, and because the salt changes each day, the same visitor's hash on one day cannot be linked to their hash on another.
- Retention is 90 days, after which query logs and distinct-searcher hashes are dropped and cannot be recovered by anyone, including suo.
- Per-index logging switch: query logging, including the distinct-searcher hash, can be turned off entirely for a specific index, from that index's settings, if you would rather not have query text recorded for it at all.
What we do not collect
We do not store IP addresses — including when you sign in to the dashboard yourself. To slow down repeated sign-in attempts, the dashboard counts requests to its sign-in endpoints per network address over a one-minute window; it keeps only a keyed hash of the address and the endpoint, never the address itself, and deletes each counter within 15 minutes. The same applies to API calls — search, writes, crawls and key management: the connecting IP is used transiently, inside Cloudflare's own Rate Limiting binding, to throttle abusive request rates, is never persisted in any store suo controls, and is never linked to query content or account data. We do not build a cross-site profile of an individual visitor. We do not use query content for anything beyond serving the search and the analytics described above.
How data is used
- To answer search queries and serve the widget.
- To show you analytics about your own indexes' query traffic.
- To operate, secure and improve the service — for example, the accuracy program described in the platform plan, which never uses your specific query logs, only the golden sets we maintain ourselves.
Sub-processors
suo runs on Cloudflare's edge network and Cloudflare's Durable Objects, D1, Workers, Analytics Engine and R2 products for storage, compute and analytics. See the Sub-processors list for the current, complete list.
Data location and isolation
Content you push into a partitioned index is isolated per partition — see Partitions. Deleting a partition (for example, on account deletion) removes its records and tombstones immediately, with no 30-day grace period, unlike an ordinary record delete.
Your choices
- Turn off query logging per index, at any time, from that index's settings.
- Request deletion of your account and its data by contacting us at the address in the Crawler policy.
- Clear a partition yourself at any time via the API or dashboard — see Clear a partition.
Changes to this policy
Material changes will be announced, not applied silently, while this page carries status: draft and afterward.
Placeholders for legal review: a lawful-basis statement for each processing purpose, international transfer mechanism, data subject rights process and response timeline, retention schedule for account records (as opposed to query logs, which are already fixed at 90 days), and a DPA are intentionally not drafted above — plans/001-suo-platform.md notes a DPA template is out of scope for v1 and should be revisited before general availability.