Legal
Privacy Policy
Last updated: 4 September 2026
1. Overview
This Privacy Policy explains how StatGazer LLC ("StatGazer", "we", "us") handles information in connection with the StatGazer website at statgazer.com (the "Site") and our communications with you. We collect as little as we need and do not sell personal information.
Advertising data transparency. Google explains how it processes personal information received from sites and apps in its Business Data Responsibility resource. You can accept, refuse, or later change StatGazer's optional advertising measurement and personalization settings.
2. Information we collect
- Information you give us. When you email us, request a consultation or program access, or start a payment, we receive your name, email address, organization/context if provided, and whatever you include in your message.
- AI assistant messages. If you use the optional website AI assistant, each question you type is sent to our AI service provider to generate a reply. To understand a follow-up, the assistant may send the immediately preceding question and answer again with your next message. After a successful reply, the current browser tab temporarily keeps a limited transcript and signed context token so the conversation can continue through a same-tab page refresh or navigation. The chat is intended only for general service and site information. Do not include confidential data, source code, credentials, portfolio holdings, client names, or non-public information.
- AI assistant usage events. To understand whether the assistant works well, we record timestamped technical events about its use: an event type (for example, chat opened, reply produced, or an error class), a coarse page group, and a service, interaction-stage, or error category. The Analytics Engine records do not include message text, full URLs, IP addresses, or visitor or conversation identifiers, and we analyze them only in aggregate. Our hosting and security layer may separately process standard technical data as described below.
- Website funnel events. To understand whether service pages lead to enquiries, we record timestamped aggregate events such as a service-page view, consultation-link click, form start, form submit attempt, delivered request, or a closed error class. Each record contains only an allowlisted event name, coarse page and landing categories, and booleans indicating server-verified advertising-measurement consent and whether an advertising click identifier was present. The funnel dataset does not contain names, email addresses, organizations, form contents, IP addresses, browser user agents, cookies, raw URLs, query strings, referrers, advertising click-identifier values, or user, device, or session identifiers. Our hosting and security layer may separately process standard technical data as described below.
- Technical data. Like most websites, our hosting provider may process standard server and security logs (for example, IP address, browser type, and timestamps) to operate and protect the Site.
- Advertising measurement data. With your consent, we use the Google tag and Meta Pixel and Conversions API to understand whether advertising visits lead to a delivered consultation request. For Google Ads, this may also measure whether a request later becomes a human-reviewed qualified lead or client engagement. Advertising services and ordinary network requests may receive advertising click or browser identifiers, page URL, browser or device information, IP address, consent state, and a limited conversion event. Our site code does not send consultation form fields to Google or Meta.
- Consent records. When you save advertising choices, or when notice-based measurement is recorded on a first visit from outside the EEA, the UK and Switzerland (see below), we create random consent subject and event identifiers and retain an append-only server record of the notice version shown, the choices made or applied, the server date and time, and later updates or revocation. The consent record does not contain your name, email address, form contents, IP address, browser user agent, or advertising click identifiers.
Google Consent Mode defaults optional advertising storage, advertising-user-data processing, personalization, and analytics storage to denied. If you visit from the EEA, the UK or Switzerland, Google and Meta advertising tags remain off until you allow advertising measurement. If you visit from anywhere else, advertising measurement (not personalization) is on by default under this notice from your first visit: we record a notice-based consent event, Google and Meta advertising tags may then run, and you can switch measurement off at any time from Privacy choices, after which the tags stop and their cookies are cleared. The region is derived from our hosting layer's coarse country signal and is never stored with the consent record. If you allow it, Google and Meta may set first-party advertising cookies such as _gcl_*, _fbp, and _fbc. Google states that, beginning in August 2026, its advertising services may use IP addresses received through customer tags, SDKs, HTTP calls, uploads, or similar means for advertising measurement and personalization in the EEA, the UK, and Switzerland. We send Google consent signals that reflect your choices. Learn more in Google's Business Data Responsibility resource.
For a successfully delivered consultation request, Meta may receive a deduplicated browser and server conversion event containing an event identifier, timestamp, source URL, IP address, browser user agent, and available Meta browser or click identifiers. The event does not contain your name, email, organization, role, engagement details, or problem summary.
If you allow advertising measurement and a delivered request later becomes a human-reviewed Qualified Lead or Won Client, we may send Google a limited offline conversion record containing the Google click identifier, conversion name and time, an opaque order identifier, and the applicable advertising-user-data and personalization consent statuses. We do not include form fields, name, email address, organization, problem summary, or IP address in that offline record. A denied, missing, invalid, expired, or subsequently revoked advertising-user-data consent record is not eligible for upload.
We use an HTTP-only, cryptographically signed first-party cookie named sg_consent_v3 to associate the current choice with its server record. A separate denial-only first-party cookie mechanism ensures that a withdrawal takes effect even if the consent service is temporarily unavailable or another browser tab still holds older state. These cookies expire after up to 400 days. We do not use browser local or session storage for advertising consent.
3. How we use information
- To respond to your enquiries and arrange consultations.
- To answer general questions about StatGazer services and route you to the appropriate next step through the optional AI assistant.
- To provide, scope, and deliver our services and programs.
- To operate, secure, and improve the Site.
- With your consent where required, to attribute advertising visits and successful consultation requests, measure campaign performance, and personalize advertising if you separately enable that option.
- To comply with legal obligations.
4. Service providers
We rely on a small number of providers who process data on our behalf or as needed to deliver the Site: Cloudflare hosting, D1, Turnstile, and Workers Analytics Engine (for serving and protecting the Site, the consent ledger described in Section 2, bot and abuse prevention, security logs, aggregate traffic and performance measurement, and the AI assistant usage and website funnel events described in Section 2), OpenAI (for generating replies and moderating content in the optional AI assistant), Google Ads and the Google tag (for consent-based advertising attribution, online and offline conversion measurement, and optional personalization according to your choice), Meta Platforms and its Pixel and Conversions API (for consent-based advertising attribution and delivered-request measurement), email (for correspondence), web fonts served by Google Fonts (which receives a request, including your IP address, when fonts load), and, for paid consultations or programs, a payment processor such as Stripe (which handles payment details directly under its own terms). We do not control, and are not responsible for, third parties' independent practices.
5. Client and engagement data
Confidential information shared during an engagement is handled under a non-disclosure agreement. We use it only for that engagement, do not use it for third-party AI training, and return or delete it on request at the end of the engagement, subject to legal retention requirements. Where possible, we work inside the client's environment or on the smallest useful extract. Access to client engagement data is limited to the founder unless otherwise agreed in writing. Data handled by our hosting, email, and storage providers is protected by their security controls, including encryption in transit and provider-managed encryption at rest where available.
6. Data retention
The Site does not save AI assistant conversation history in cookies, localStorage, or a server-side chat database. It stores at most six completed exchanges and a signed context token in the current tab's session storage. The chat can be restored for 30 minutes after the latest successful reply; expired data is ignored and removed when the chat next loads or checks the session. Starting a new chat clears it, and the browser normally clears it when the tab session ends. The transcript shown in the browser is not trusted by the server; only the verified signed token can provide the immediately preceding exchange to a follow-up request. We send Responses API requests with store: false, so response objects are not retained as application state for later retrieval through our account. Under OpenAI's default data controls, separate abuse-monitoring logs may contain prompts, responses, and related metadata for up to 30 days, unless longer retention is required by law or reasonably necessary to prevent harm. The AI assistant usage and website funnel events described in Section 2 are stored by Cloudflare Workers Analytics Engine as individual timestamped records and are retained for about three months before automatic deletion.
We keep enquiry correspondence for as long as needed to respond and maintain our business records, and engagement data for the duration of the engagement and a reasonable period afterward unless you ask us to delete it sooner. Consent cookies expire after up to 400 days. We retain consent-event records only as long as reasonably necessary to demonstrate and honor the current choice and later updates or revocation, and periodically delete records that have passed the operational retention window. Google, Meta, and our other providers retain data according to their own applicable settings and policies.
7. Your rights
You may ask us to access, correct, or delete the personal information we hold about you, or to stop contacting you. You can reopen at any time to change optional Google Ads and Meta settings. Email hello@statgazer.com and we will respond within a reasonable time. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA.
8. International operation
StatGazer is based in the United States and operates globally. If you contact us from outside the United States, your information may be processed in the United States and other countries where we or our providers operate.
9. Children
The Site is intended for businesses and professionals and is not directed to children, and we do not knowingly collect personal information from children.
10. Changes
We may update this Policy from time to time. Material changes will be reflected by updating the date above.
11. Contact
Questions or requests: hello@statgazer.com.