Last updated: May 15, 2026 · Effective: May 15, 2026
Privacy Policy
This Privacy Policy explains how RL Roberts Consulting, LLC ("SentryDate," "we," "us") collects, uses, discloses, and safeguards personal information when you use our website and AI-powered scam-pattern detection tools (the "Service"). We are the data controller of the personal information described below. By using the Service you confirm you are at least 18 years old and that you have read and understood this Policy.
1. Personal information we collect
Categories of personal information we collect, as classified under the California Consumer Privacy Act (CCPA/CPRA, Cal. Civ. Code §1798.140):
- Identifiers: email address, account display name, IP address, authentication identifier from Google sign-in (if used).
- Customer records: billing email, purchase history, credit balance.
- Commercial information: products purchased, subscription status. Card numbers are processed and stored by Stripe; we do not see or store them.
- Internet activity: pages visited, scan submissions, browser/device metadata, error logs.
- Inferences and AI-generated output: risk scores, signal lists, and analyses generated by the Service from content you submit.
- User-submitted content: images and message text you choose to upload to be analyzed. This may incidentally include personal information about third parties (e.g. a profile photo of someone you matched with online). You are responsible for ensuring you have a lawful basis to upload such content — see Section 7.
2. How we use your information & legal basis (GDPR Art. 6)
- To provide the Service (running scans, returning results, retaining your scan history) — performance of contract.
- To process payments and prevent fraud — performance of contract and legitimate interest.
- To secure the Service and prevent abuse (rate limiting, log retention, abuse detection) — legitimate interest and legal obligation.
- To send transactional emails (receipts, password reset, account notifications) — performance of contract.
- To comply with legal obligations (tax records, lawful requests, NCMEC reporting if required) — legal obligation.
We do not use your scan content to train AI models. We do not sell or "share" personal information for cross-context behavioral advertising as those terms are defined under the CPRA. We do not engage in automated decision-making that produces legal effects concerning you.
3. Service providers (subprocessors)
We share personal information only with vendors that process it on our behalf under written data-processing agreements:
- Lovable Cloud (database, authentication, hosting) — United States.
- Stripe, Inc. (payment processing) — United States.
- Google LLC (Gemini AI models, Google sign-in) — United States.
We may also disclose information if required to do so by law, valid legal process, or to protect the rights, property, or safety of SentryDate, our users, or the public.
4. International data transfers
Personal information is processed in the United States. If you access the Service from the European Economic Area, the United Kingdom, or Switzerland, your information will be transferred internationally. We rely on Standard Contractual Clauses approved by the European Commission, and equivalent UK and Swiss safeguards, as the lawful transfer mechanism.
5. Retention
- Account data: retained until you delete your account.
- Scan content & results: retained for the lifetime of your account so you can revisit them. You may delete an individual scan from your dashboard at any time.
- Payment & transaction records: retained for at least seven (7) years to comply with US tax and accounting requirements.
- Server and security logs: retained for up to 90 days.
- After account deletion, residual personal information may persist in encrypted backups for up to 30 days before being overwritten.
6. Security
We employ administrative, technical, and physical safeguards designed to protect personal information, including TLS in transit, encryption at rest, row-level access controls, principle-of-least-privilege access, and audit logging. No system is perfectly secure. In the event of a personal-data breach affecting you, we will notify you and applicable regulators in accordance with applicable law (including GDPR Art. 33–34 and US state breach-notification statutes).
7. Content about third parties
If you upload content (a photo, screenshot, or message thread) that contains personal information about another person, you represent that you have a lawful basis to do so under applicable law (for example, that the content was sent to you, that you obtained it from a publicly available source, or that the third party consented). If you are a third party who believes content about you has been uploaded without a lawful basis, contact us at privacy@sentrydate.app and we will delete the relevant scan record within 30 days of verifying the request.
8. Children
The Service is not directed to and not intended for children. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from a person under 18, we will delete it. Parents or guardians who believe their child has provided personal information to us should contact privacy@sentrydate.app.
9. Cookies and similar technologies
We use strictly necessary cookies and local storage to keep you signed in, remember your session, and operate the Service. We do not use advertising or third-party tracking cookies. You can clear cookies in your browser settings, though this may sign you out.
10. Your privacy rights
Depending on where you live, you may have the right to:
- access the personal information we hold about you;
- correct inaccurate personal information;
- delete your personal information ("right to erasure" / "right to delete");
- obtain a portable copy of your personal information;
- opt out of any "sale" or "sharing" (we do not sell or share, but the opt-out is honored);
- limit use of sensitive personal information (we do not use sensitive personal information for purposes beyond providing the Service);
- withdraw consent where processing is based on consent (GDPR);
- lodge a complaint with your local data-protection authority (GDPR), or the California Privacy Protection Agency.
To exercise any of these rights, visit our Data Removal page. Authenticated users can permanently delete their account and all associated data with a single click. Authorized agents may submit requests on behalf of a consumer; we will require written authorization and reasonable verification of identity before acting. We will respond within 45 days (CCPA/CPRA) or one month (GDPR), with a possible 45-day extension for complex requests. We will not discriminate against you for exercising any privacy right.
Appeals: If we deny your request, residents of Colorado, Virginia, Connecticut, and other states with appeal rights may appeal that decision by replying to our denial email within 60 days. We will respond to appeals within 60 days.
11. "Do Not Sell or Share My Personal Information"
SentryDate does not sell personal information for monetary value and does not share personal information for cross-context behavioral advertising. There is therefore no "Do Not Sell or Share" mechanism to enable. We honor Global Privacy Control (GPC) signals where applicable.
12. Changes to this Policy
We may update this Policy from time to time. Material changes will be communicated by email to registered users and posted at the top of this page with a new "Last updated" date at least 30 days before they take effect.
13. Contact
RL Roberts Consulting, LLC
Attn: Privacy
[Street Address]
[City, State, ZIP]
Email: privacy@sentrydate.app
EU/UK residents may also contact our representative at the address above. To exercise privacy rights directly, please use our Data Removal page.