Privacy Policy
Effective date: 2026-05-14 · Last updated: 2026-08-02
Real Product Origin ("we", "us") operates the Product Origin Checker browser extension, mobile app, and supporting backend services (collectively, the "Service"). This Privacy Policy explains what data we collect, how we use it, and your rights.
1. What we collect
1.1 Information you provide
- Complaint submissions: When you use "Contest this finding", we collect the information you fill into the form — your name, email address, optional phone number, your stated affiliation or credentials, the indicators you're contesting, any proposed corrections, and your free-text reasoning.
- Email-verification interactions: Whether and when you clicked the verification link we sent. We use this to confirm you own the email address you provided.
- Sign-in and account: When you sign in to use the browser extension, mobile app, or to subscribe, we collect your email address. We do NOT collect a password — sign-in uses a one-time link sent to your email (magic link). We store the email, the timestamp you first verified it, and the timestamp of your most recent sign-in. We also store how many product scores and how many brand checks you have run, as daily totals — two separate counts, because they are two separate allowances. That is the whole of it: not which products, not which brands, and not which shops. The table holding these counts has no product, no brand and no retailer on it at all, and the separate table that records which products get scored has nothing about who scored them — so neither can be joined to reconstruct what you looked at. We also store the language to write to you in — taken from the page you signed up on, or from your browser's language setting when you sign in if we have none. It decides which translation of a receipt or a sign-in email you get, and nothing else. If you choose to tell us what to call you, we store that too and use it for one thing: the greeting on those emails. It is optional, you can change or clear it in your account settings at any time, and leaving it blank costs you nothing. We do not ask for a surname or a postal address, because we have no use for either. We also record the country your sign-in came from, as a two-letter code and nothing finer — it tells us which countries to add retailers for. It is derived from the same connection information every website sees; we do not ask you to type it, and we do not track where you are afterwards. We do not keep a list of the browsers or devices you have signed in from — that record used to exist and was deleted, because it was the one thing that could have connected an anonymous browser to your name.
- Subscription details: If you subscribe, Stripe collects your billing information directly (see section 3). We receive back and store: your Stripe customer identifier, your subscription plan (Basic, Pro, or Premium — monthly or yearly), your current billing-period start and end dates, whether you have set your subscription to cancel at period end, and — if you cancel and choose a reason from the Stripe survey — that cancellation-reason category and any free-text comment you provided.
- Access-code redemptions: If we've given you an access code (a private promo, gift, or partnership code of the form
RPO-XXXX-XXXX) and you redeem it in the extension, we store the code you redeemed, the time you redeemed it, and the plan tier it granted, so we can honor your access until the code's expiration date. Codes are not linked to any identity beyond the account that redeems them.
1.2 Information collected automatically
- Product identifiers: The retailer's own product identifier for the item you ask us to score — for example an Amazon ASIN, a Target TCIN, a Walmart item ID, or the equivalent SKU or catalogue number used by each of the retailers we support (the current list is on our products page). We cache scores by that identifier.
- Product-page content (transient): The extension activates only on product-detail pages of the retailers we support. When it is active on such a page — either automatically or when you ask it to score — it reads the page's public product information and sends it to our backend to compute an origin score. Specifically: the product title, brand, seller name, price, "Sold by" and "Ships from" fields, product description, A+ content text, up to 15 questions-and-answers, a short excerpt of top reviews, up to 10 product gallery image URLs, and up to 8 customer-review image URLs.
We keep our conclusions, not the retailer's content. That page content is used to compute the score and is then discarded. What we retain is the product identifier, the four scores with their confidence levels, and the citation URLs supporting them — plus a few short factual fields (title, brand, seller, price, the URL of the product's main image, and the address of the product page itself) so we can show you which product a cached score belongs to and link you back to it.
That page address is stored against the product, not against you. It is the link our browse page uses to send you to the retailer, so it is the same single row every visitor to that product shares — one address per product, not a list of the pages any person visited. Nothing records which addresses you requested.
When a retailer's page publishes no brand at all, we also store the brand we inferred from the product's title or web address, kept separate from a brand the page actually stated so the two are never confused. It is our guess about the item, not something read from you.
We also store our own classification of the product — its category and product type, plus a note of how we worked that out and how confident we are. That is our judgement about the item, not anything read from you, and it is what lets the browse page group products sensibly. Product descriptions, A+ content, questions-and-answers, review excerpts, and the gallery and review image URLs are not stored — we keep only the single main-image URL noted above. We do not keep copies of retailer page text, and we never copy or host the images themselves — only that one link. The single exception is a diagnostic session you switch on yourself (section 1.2a), where that text is kept for 30 days so we can see the evidence a score was based on.
We do not read your retailer account, cart, purchase history, or any other page on the retailer's site besides the product-detail page you are actively viewing. The extension has no permission for sites we do not support. - Anonymous install identifier: When you install the browser extension or mobile app, we generate a random UUID and store it in your browser's local extension storage (or the app's local sandbox on mobile). This UUID is sent as an HTTP header (
X-Install-Id) with every request to our backend so we can measure usage: how many distinct installs are active, how often each one requests a score, and cache-hit patterns. We keep that as a daily count — how many scores, per install or, if you are signed in, per account. Not which products, and not which shops. It is also not stored next to the products you scored. Which products get scored is counted separately, as a daily total per product with nothing on it to say who scored them — so “what has this browser looked at” has no answer in our database, rather than merely going unasked. It is not linked to your name, email address, retailer account, IP address in our aggregates, or any other identifier. Uninstalling the extension or app permanently erases it, and reinstalling generates a new one.
There is no table in our database that maps this identifier to a person. We used to keep a list, against each account, of the browsers that had signed into it — which meant that in principle the two could be joined. We removed that list. Signing in still carries your free-check count across, but the browser identifier is used during sign-in and then discarded rather than recorded against your account. This is enforced by automated tests that fail the build if the link is ever re-introduced. - Coarse country from browser timezone: We derive a two-letter country code (e.g.
US,DE,JP) from your browser's IANA timezone (e.g.America/New_York) and send it as an HTTP header (X-Client-Country). This is not GPS-precise location: it never reveals a city, street, or coordinates, and we never ask your browser for its geolocation. The country is used only to plot aggregate usage on a world map so we can see roughly where our users are. - Submission metadata: For each complaint, we record the IP address it was submitted from and the User-Agent of the browser/device. This helps us detect abuse and is retained only for audit purposes.
- Server logs: Standard request logs from our hosting provider (Render) recording request paths, timestamps, response codes. These do not include personal data beyond IP addresses and are retained for 7–30 days for operational monitoring.
- Error tracking (if enabled): If we have Sentry enabled, application errors are sent to Sentry for diagnosis. Sentry data is automatically scrubbed of personal data we control.
- Session token: When you sign in, we create a session token — a random string with no personal information in it — and store it in your browser's local extension storage (or the app's local sandbox on mobile). The token is sent as an
Authorization: Bearerheader on subsequent requests so we know it's still you. Sessions last 30 days from your most recent activity; signing out or 30 days of inactivity invalidates the token. - Free-tier usage counter: If you have not subscribed, we count how many product checks you have used against your one-time free allowance, keyed on your account (if signed in) or the anonymous install identifier (if not signed in). This counter does not reset — the free allowance is a trial, not a recurring monthly quota.
The counter records that a product was counted, not which product it was. Each entry stores a one-way cryptographic hash of the product identifier rather than the identifier itself. That is all the counter needs — it only has to recognise a product it has already counted, so you are never charged twice for re-viewing the same item — and it means the table cannot be read back into a list of what you looked at. Not by us, and not by anyone who obtained a copy of it.
1.2a Diagnostics — off unless you switch them on
If you are working with our support team on a problem, you can switch on a diagnostic session from the extension's Settings pane. While it is on, we record the product pages you score — the product, the answer we gave, and the internal steps we took to reach it — so we can see what went wrong without asking you to open a developer console.
That record includes the product information the extension read from the page, including the retailer's own product description and the customer review excerpts it used. We would otherwise be looking at a scoring decision with its evidence removed, which is not a diagnosis. Outside a diagnostic session we do not keep any of that text.
- It is off by default and only you can turn it on. We have no way to start one. There is no screen in our admin tools that accepts an email address or a browser identifier and begins recording; the capability does not exist in the software.
- It is identified by a code, not by you. Turning it on generates a short code that you read out to support. That code is the only handle we get. The record carries no email address, no account, and no browser identifier — so even we cannot work out whose session it was, or connect two sessions to the same person.
- It stops on its own. Sessions expire after 24 hours. You can switch it off at any moment, and so can we once the problem is solved.
- The records are deleted after 30 days. A diagnostic is worth keeping while we are fixing something and not worth keeping afterwards, so the records delete themselves on a schedule rather than waiting for anyone to remember.
- It still only covers supported product pages. A diagnostic session does not widen what the extension can see. Your other tabs and your browsing history remain outside its reach, exactly as before.
1.2b Email we send you
Two different things, governed differently.
- Email your account needs. Sign-in links, receipts, renewal reminders, and notices if a payment fails. These are sent because you have an account with us, not because you agreed to marketing, and they cannot be switched off while the account is open — a failed payment you were never told about is worse than an email you did not want.
- Product news. Offered as a box when you sign up or
subscribe, and never sent until you have confirmed your address — an
unconfirmed address is a typo or somebody else's inbox, not a person
who agreed. We record the date, the page, and whether the box was
already ticked when you saw it.
Whether it starts ticked depends on where you are, because the law does. In the United States it may arrive already ticked; federal law (CAN-SPAM) permits that, and requires instead that every message be honestly labelled and carry an unsubscribe we honour. In the European Economic Area, the United Kingdom, Switzerland, Canada, Japan, China and everywhere else we serve, it arrives unticked and stays that way until you tick it — a pre-ticked box is not consent under the ePrivacy Directive and the GDPR, and we would rather have a shorter list than an indefensible one. Anywhere we cannot tell where you are, we treat it as the stricter case.
Two things follow from that, and we hold to both: a box we ticked for you will never put you back on the list after you have left it, and signing in again does not re-subscribe you.
Every message carries a one-click unsubscribe that works without signing in, and it takes effect on the next send — not "within 10 business days". You can also turn it off at any time in your account settings.
We do not sell, rent, share or trade your email address, and we do not send anyone else's marketing to you.
1.3 What we DO NOT collect
- We do not collect your account information, login, or order history on any supported retailer (the current list is on our products page).
- We do not collect your browsing history outside of product pages on the retailers we support (the current list is on our products page).
- We do not build a record of the products you look at. Scores are cached against the product, not against you — the same cached answer serves everybody who views that item. Our usage counter stores one-way hashes rather than product identifiers, and nothing in our database maps a browser identifier to a person. There are exactly two exceptions, and you have to switch each one on yourself: a diagnostic session, described in section 1.2a, which expires within 24 hours and is identified by a code rather than by you; and the scan history described below.
- Your scan history is off unless you turn it on. When you do, we keep a plaintext list on your account of the products and brands you checked: the title, the brand, the retailer, the product link, and the answer we gave you at the time — where it was made, where it shipped from, who the retailer was and where the money went, or for a brand, who we concluded ultimately owns it. Only you can switch it on and only you can read it. Turning it off stops new entries; what is already saved stays until you delete it, which you can do a row at a time or all at once. It is capped at 500 entries. Nothing is written to it while it is off, and it is never used for anything except showing you your own list. Manage or delete it at your history.
- We do not collect or store your full payment-card number, CVC, or expiry date. If you subscribe, Stripe collects those directly through their hosted checkout — see section 3. We only receive back a Stripe customer identifier and subscription metadata (plan, dates, status), as described in section 1.1.
- We do not collect precise location: no GPS coordinates, no city, no street. The only geographic signal we collect is the coarse country code described in section 1.2, which is derived from your browser's timezone and never reveals more than a country.
- We do not collect advertising IDs, contacts, or microphone/camera data. The anonymous install UUID described in section 1.2 is not an advertising identifier — it is never shared with third parties for advertising and it does not survive an uninstall.
- The browser extension does not have permission to read or write pages on any site other than the retailers it currently supports (the current list is on our products page).
- The mobile app does not request permission to read your contacts, photos, location, or clipboard contents outside of the explicit "Check the link you copied?" prompt.
2. How we use what we collect
- Scoring products: The retailer's product identifier and the page content described in section 1.2 are sent to our backend, which queries the Anthropic Claude API to compute the four transparency indicators (Made in, Ships from, Retailer, Money goes to). The page content is used for that computation and then discarded. What we cache is the identifier, the four scores, their citation URLs, and short factual fields (title, brand, seller, price) — for up to 30 days. (Made in and Money goes to carry a longer nominal setting, but a score is only usable while every indicator is fresh and a re-score rewrites all four together — so 30 days is the figure that actually applies.) A cached score is invalidated immediately if we detect that the product's brand or seller has changed since we last scored it.
- Reviewing complaints: Your complaint submissions are reviewed by our team. We may contact you at the email or phone number you provided to follow up.
- Service improvement: We use aggregate patterns from cached scores and complaint outcomes to refine our scoring engine.
- Aggregate usage measurement: The anonymous install UUID and coarse country code described in section 1.2 are used only to power an internal usage dashboard — totals such as "how many installs are active this week," "how often each install scores a product," "which countries our users are in." We do not sell, share, or otherwise disclose this data to third parties.
- Abuse prevention: IP addresses and User-Agents from complaint submissions are used to detect spam, bots, and coordinated abuse.
3. Third parties we share data with
| Recipient | What they receive | Why |
|---|---|---|
| Anthropic, PBC | Scraped product metadata (title, brand, seller, reviews snippets) to score. Per Anthropic's policy, this is processed for inference and is not used to train their models without explicit opt-in. | Country-of-origin scoring requires AI inference. |
| Stripe, Inc. | If you subscribe: your email address, billing address, and payment-card information — collected directly by Stripe in their hosted checkout and customer-portal pages. We do NOT receive or store your full card number, CVC, or expiry date. We only receive back a Stripe customer identifier (cus_…), a subscription identifier, plan tier, current-period timestamps, subscription status, and (if you cancel) the cancellation-reason category you selected. |
Subscription billing, recurring charges, hosted customer portal for cancel / update card / switch plans. |
| Render, Inc. | Hosting our backend service and managed PostgreSQL database. All data we collect is stored here. | Hosting provider. |
| Resend, Inc. | Recipient email address and verification-email contents. | To deliver complaint-verification and admin-notification emails. |
| Cloudflare, Inc. | Standard web-server logs: request URL, response code, timestamp, IP address, and User-Agent. This covers our marketing site (realproductorigin.com), which is hosted on Cloudflare Pages, and also our API (api.realproductorigin.com), which our hosting provider serves through Cloudflare's network. Requests from the extension and the mobile app therefore pass through Cloudflare as well. Cloudflare tells our API which country a request came from; we use that to decide which country's email rules apply to the newsletter box, and we store it only as the country on your account. | CDN, DNS resolution, DDoS protection for both the marketing site and the API. |
| Sentry, Inc. (if enabled) | Application error data, scrubbed of personal data. | Error monitoring. |
| Law enforcement | Only as required by valid legal process. | Legal compliance. |
We do not sell your personal data. We do not share your personal data with advertisers.
4. Data retention
- Cached product scores: retained while the product remains in our catalogue. A cached entry holds the product identifier, the address of its page at the retailer, the four scores with confidence levels, the citation URLs, and short factual fields (title, brand, seller, price) — not the retailer's product description, A+ content, questions-and-answers, review text, or images, none of which are stored at all outside a diagnostic session you have switched on (section 1.2a, kept 30 days). A cached score is treated as stale after 30 days and re-computed on the next request. Superseded scores are kept for audit and quality control so that a correction can be traced to the evidence behind it.
- Complaint submissions and personal data therein: retained until the complaint is resolved + 24 months for audit, or until you request deletion (whichever is later).
- Account records (email, sign-in metadata): retained for the life of the account plus 24 months after account deletion (for accounting and abuse-history purposes). Deleting your account via privacy@realproductorigin.com clears your email and links the account to an anonymous placeholder within 30 days.
- Subscription records: retained for the life of the subscription plus 7 years after final cancellation, to satisfy tax and accounting record-keeping requirements. Payment-card information is never stored by us — only by Stripe.
- Session tokens: automatically deleted 30 days after their last use, or immediately when you sign out.
- Server logs: 7–30 days.
- Manually-verified score overrides: retained indefinitely. Even when "retired", the record persists for audit. The data does not contain personal information.
5. Your rights
Depending on where you live, you may have rights under applicable law (including GDPR for EU/UK residents and CCPA/CPRA for California residents):
- The right to access the personal data we hold about you.
- The right to have inaccurate data corrected.
- The right to have your data deleted ("right to be forgotten" under GDPR).
- The right to restrict or object to certain processing.
- The right to data portability.
- The right to lodge a complaint with a supervisory authority.
To exercise any of these rights, email us at privacy@realproductorigin.com from the email address associated with your complaint(s). We will respond within the timeframes required by applicable law.
6. Children's privacy
The Service is not directed at children under 13 (or 16 in the EU). We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us and we will delete it.
7. Security
We use industry-standard practices to protect the data we hold:
- All connections to our backend are encrypted via TLS.
- Our database is hosted on private networking within Render and is not directly accessible from the internet.
- Administrative access to our admin module is gated by strong authentication and operated over TLS only.
- Secrets (API keys, passwords) are stored as encrypted environment variables; never committed to source control.
No system is perfectly secure. If we discover a breach affecting your personal data, we will notify affected users within the timeframes required by applicable law.
8. International transfers
Our backend is operated in the United States. By using the Service, you understand that your data may be processed in the United States, which may have data-protection laws different from the laws of your country.
9. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected in the "Last updated" date at the top of this page. We encourage you to review the policy periodically.
10. Contact us
Questions, requests, or complaints: privacy@realproductorigin.com.
Real Product Origin LLC30 N Gould St, Ste R
Sheridan, WY 82801
United States