Legal

Privacy Policy

Effective 19 July 2026 · Last updated 19 July 2026

This policy explains what IDØ (“we”, “us”) collects when you use the IDØ website and service at www.id-null.com, why we collect it, who else processes it, and what you can ask us to do with it. It applies to visitors to the site and to account holders.

1. The short version

  • We collect the minimum needed to run an account and send you your brief.
  • We run no advertising trackers and no third-party analytics on this site.
  • We do not sell, rent or share your data for marketing.
  • The companies you track are never told that you track them.
  • You can ask us to export or delete your data, and we will.

2. Information we collect

Information you give us

  • Account details — your email address, and a name if you provide one. Used to authenticate you and to send your brief.
  • Workspace content — the competitors you choose to track and any settings you configure.
  • Billing details — if you subscribe to a paid plan. Card details are entered directly with our payment processor and are never received or stored by us.
  • Correspondence — if you email us, we keep the message so we can answer it.

Information collected automatically

  • Essential cookies and session data — used to keep you signed in. We do not use advertising or cross-site tracking cookies.
  • Server logs — standard technical records (IP address, request time, user agent, error traces) generated by our hosting provider, used for security and debugging.

What the engine collects about tracked companies

This is the part most privacy policies do not cover, so we will be specific. To measure whether a company's move landed, our engine reads publicly accessible surfaces only: changelogs, blog and news pages, careers and pricing pages, public code repositories, public applicant-tracking boards, and public posts on platforms such as Hacker News and Bluesky.

  • We hold no credentials for anyone else's systems and read nothing from behind a login or paywall.
  • We store the public artifact and a timestamp so any figure we publish can be verified.
  • Where a public post carries an author's handle, that handle may be stored as part of the evidence for a reaction. We do not build profiles of individuals, and we do not enrich, sell or market to them.
  • Tracking is one-directional. A company you watch receives no notification, no request identifying you, and no signal that you exist.

3. Why we use it, and on what basis

  • To provide the service — running your account and producing your brief. Basis: performance of our contract with you.
  • To take payment — for paid plans. Basis: performance of our contract.
  • To keep the service secure and working — logging, abuse prevention, debugging. Basis: our legitimate interest in a functioning, secure product.
  • To answer you — when you contact us. Basis: legitimate interest.
  • To meet legal obligations — such as keeping tax records. Basis: legal obligation.

We do not use your data to train machine-learning models, and we do not use an LLM anywhere in the scoring path.

4. Who else processes your data

We keep this list short on purpose. Our processors are:

  • Neon — managed PostgreSQL hosting; stores account and workspace data.
  • Vercel — website and application hosting; generates server logs.
  • Clerk — authentication and session management for the product application.
  • Stripe — payment processing for paid plans. Stripe receives your card details directly; we receive only a subscription status and the last four digits.

Each processes data on our instructions in order to deliver the service. We do not sell or rent personal data, and we do not share it with advertisers or data brokers. We may disclose data if legally required to, or to protect our rights or the safety of others.

5. International transfers

Our processors operate infrastructure in multiple countries, so your data may be processed outside the country you live in. Where that happens, we rely on the transfer safeguards those processors put in place, such as standard contractual clauses.

6. How long we keep it

  • Account and workspace data — for as long as your account is open, and for up to 30 days after you close it, after which it is deleted.
  • Billing records — retained as long as tax and accounting law requires.
  • Server logs — short-lived, retained by our hosting provider on their standard schedule.
  • Public artifacts collected by the engine — kept while a company is tracked so published figures remain verifiable.

7. Your rights

Whatever jurisdiction you are in, you can ask us to:

  • tell you what we hold about you;
  • give you a copy in a portable format;
  • correct anything inaccurate;
  • delete your data and close your account;
  • stop processing for a particular purpose, or object to it;
  • withdraw consent, where we relied on it.

Email privacy@id-null.com and we will action it. We aim to respond within 30 days. Depending on where you live, you may also have the right to complain to your local data-protection authority.

8. Security

Data is encrypted in transit. Access to production systems is limited to those who need it. Our architecture deliberately reduces the amount of sensitive data in play: we hold no third-party credentials, ingest nothing from behind an authentication wall, and never receive your card details. No system can be guaranteed secure, but there is little to expose because little is collected. Details of how any particular source is fetched or stored are available on request — see Security.

9. Children

IDØ is a business product and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, contact us and we will delete it.

10. Changes

If we change this policy we will update the date above, and for material changes we will notify account holders by email before the change takes effect.

11. Contact

Privacy questions and data requests: privacy@id-null.com. Anything else: hello@id-null.com.

Also

Read the Terms.