Privacy Policy
This Privacy Policy explains how Spike-Buster Media LLC, a California limited liability company that operates the Enginerds website and the Enginerds Compass product (the "Service"), collects, uses, discloses, and protects personal information, and the rights you have over your information. Spike-Buster Media LLC is the controller of the personal data described here.
This is a notice of our practices. Where the law requires your consent for a specific use — for example, non-essential cookies or optional marketing email — we ask for that consent separately, at the point of collection, and you can withdraw it at any time. Using the Service does not by itself constitute consent to those uses.
Who We Are & How to Reach Us
- Controller: Spike-Buster Media LLC, 13157 Mindanao Way #188, Marina del Rey, CA 90292, United States.
- Websites: https://enginerds.com and the Compass product.
- Privacy contact: support@enginerds.com.
- People in restricted regions: Enginerds is operated from the United States by Spike-Buster Media LLC. We do not offer account creation or account-based Compass services — the free tier, Ask, generated or saved reports, watches, alerts, notes, exports, API access, subscriptions, or one-off report purchases — to people located in the European Union or European Economic Area, the United Kingdom, Türkiye, or mainland China (see Where the Services Are Offered in our Terms of Service). Public Enginerds articles, the published Insights reports, and the non-personalized samples remain viewable from those locations, but that public accessibility is not an offer of account-based services. We do not direct or market the account-based Service to those regions, and we do not carry out behavioural advertising or build profiles of visitors there. On that basis we have not designated a representative under Article 27 of the GDPR or of the UK GDPR. If we open account access in any of those regions, we will designate a representative where required and name them on this page before we do so. Whether or not those laws apply to us in your case, you can always contact us about your personal data at support@enginerds.com, and we will handle your request as described in Your Rights below.
- If you try to register from a restricted region: we use the limited sign-in and coarse location information involved to decline account provisioning, keep the Service secure, explain the restriction, and keep an appropriate audit record. We do not use that information to market Compass to you. You may ask us to delete it, subject to the security and legal-record exceptions described in Retention below.
- Complaints: tell us first at support@enginerds.com so we can try to put it right — but you do not have to. Depending on where you live, you may also be able to complain to your national data-protection authority; in the UK that is the Information Commissioner's Office (ico.org.uk), and in the EU/EEA it is the supervisory authority in the country where you live or work, or where you believe the issue arose.
Personal Data We Collect
We collect only what we need to run the Service. Depending on how you use it, that includes:
- Account & authentication data — your email address, any name you provide, and the sign-in identifiers issued by our identity provider, used to create and secure your account and workspace.
- Subscription & payment data — your plan, billing status, and transaction records. Card payments are processed by our third-party payment processor; we receive limited billing metadata (such as plan, status, and card brand / last four digits) and a customer/subscription identifier. We do not receive or store full card numbers. When you buy, we also keep a purchase-consent record as legal evidence of what you were shown and agreed to: the exact terms text, the date, the order reference, a truncated browser user-agent, and a coarse country hint — never an IP address (see Retention).
- Searches & prompts — the topics you look up and the questions you ask (for example, in Ask Compass), used to return results and operate features. See AI Processing of Your Prompts below.
- Watchlists, alerts & notes — the topics you choose to monitor, your alert/digest email and preferences, and private notes you save, used to deliver those features and notifications. A new watchlist includes a weekly email digest of what it measured; you can switch it off with one click in the watchlist or from any digest email.
- Integrations you configure — if you set up an outbound webhook (for example, to Slack, Zapier, or your own endpoint), we store the destination URL, a label, your event selection, an optional signing secret, and delivery status, and we send your alert/digest content to that endpoint at your direction. Choose destination endpoints you trust — what arrives there is governed by that service, not by this policy.
- Generated reports, briefs & saved content — content you generate or save, retained so you can re-open it.
- API usage data — for Signal API users, your API key identifier (we store only a hashed form of the key) and request metadata (endpoints called, timestamps, volume), used for authentication, rate limiting, quota enforcement, security, and abuse prevention.
- Waitlist data — if you join a pre-launch waitlist, or ask us to tell you when paid plans open in your region, your email and any name, plan interest, and free-text note you provide, together with a coarse country hint from our hosting platform (never an IP address) so we know which region you are asking about. We use the address to send you the one announcement you asked for.
- Report email subscriptions — if you ask us to email you a report on a schedule, we store your email address, which topic set you chose, the level of detail, and how often you want it, until you turn it off. Watchlist digests are part of the watchlist feature itself, as described above, and switch off with one click. We do not publish a newsletter.
- Usage & device data — standard information your browser and our servers generate when you visit: pages viewed, timestamps, referrer, browser and device type, and language. Your IP address is processed transiently by our hosting and security layer to deliver and protect the Service; we do not store IP addresses in our application database. For signed-in accounts we also keep per-account records of which product features you used and when (for example, that you opened a lens, ran an export, or reached a plan limit), used to operate quotas and allowances and to understand how the product is used. With your consent, analytics tools also collect aggregate usage data (see Cookies & Analytics).
We do not intentionally collect special-category / sensitive data, and we ask that you not submit it in prompts, notes, or reports.
Where this data comes from
California law asks us to name the categories of sources we collect personal data from. There are three, and only three:
- Directly from you — what you type or submit: your account details, prompts and searches, watchlists, saved reports, waitlist entry, and anything you send us by email.
- Automatically from your device — as you use the Service: request and security logs, your cookie choice, and (only with your consent) aggregate analytics.
- From the providers who operate the Service for us — our identity, payment, and email providers return the limited information we need to sign you in, take payment, and deliver email.
We do not buy personal data, and we do not obtain it from data brokers, advertising networks, or social platforms.
Why We Use Your Data — Purposes & Lawful Bases
We hold a specific reason for every use of your data, and we do not repurpose data for something you were not told about. The vocabulary below is the GDPR's, because it is the clearest available shorthand for these ideas:
| Purpose | Basis (GDPR terminology) |
|---|---|
| Create and secure your account; provide the workspace, reports, watchlists, and API you request; process your subscription | Performance of a contract (Art. 6(1)(b)) |
| Operate, maintain, secure, debug, and prevent abuse of the Service; enforce plan limits; keep aggregate, product-improvement measurements | Legitimate interests (Art. 6(1)(f)) — running a secure, reliable product |
| Non-essential analytics cookies/tags; optional marketing email and any announcement you ask us to send you | Consent (Art. 6(1)(a)) — withdrawable at any time |
| Meet tax, accounting, and other legal obligations; respond to lawful requests | Legal obligation (Art. 6(1)(c)) |
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not use your account data, prompts, watchlists, or reports for third-party advertising.
AI Processing of Your Prompts
Compass features such as Ask and generated reports send the text you enter — your question and the measured data we assemble to answer it — to a third-party AI (large-language-model) provider, which returns the drafted wording. Site and video search also send your search text to a third-party AI provider to convert it into a numeric representation for matching. We use this only to operate those features.
- We do not use your prompts, searches, or generated content to train our own models, and we do not sell them.
- The provider processes this text under its API terms as our service provider. We use providers whose API terms state that data submitted through the API is not used to train the provider's models and is retained only for a limited period (typically no more than 30 days for abuse monitoring) before deletion, unless a longer period is legally required.
- On our side, we retain your Ask questions and their answers for 60 days and then delete them automatically (see Retention).
- AI-drafted wording can be wrong or incomplete; it is provided as a measurement summary, not advice. You are responsible for reviewing the cited sources.
Cookies & Analytics
We use two kinds of cookies and similar technologies:
- Strictly necessary — sign-in/session, security (anti-forgery, login-flow integrity), and remembering your cookie choice. These are required for the Service to work and are set without consent.
- Analytics — Google Analytics and Ahrefs, used to understand aggregate usage. These load only if you consent — no analytics or tracking runs before you choose. (Some resources needed to display the site, such as web fonts, stylesheets, and scripts for interactive charts and exports, may load from a content-delivery network as the page renders; these set no cookies and are used only to present the page.)
You choose your cookie preferences in the banner shown on your first visit, and you can change or withdraw them at any time via in the site footer. Rejecting analytics is as easy as accepting it, and we keep a record of your choice (its date, the policy version, whether a privacy signal was present, a truncated browser user-agent, and a coarse country hint — linked to your account email if you are signed in, so we can include it in a data-subject-access export) as proof of consent. We honor a Global Privacy Control (GPC) or Do-Not-Track browser signal as an opt-out: when we detect one, analytics stays off.
| Cookie / tag | Provider | Purpose | Category | Duration |
|---|---|---|---|---|
| Session / auth cookie | Us (via our identity provider) | Keep you signed in | Necessary | Session / up to 7 days |
| Anti-forgery & login-flow cookies | Us | Security / CSRF protection | Necessary | Session |
| Consent record (local storage) | Us | Remember your cookie choice | Necessary | Up to 180 days |
| Consent reference ID (local storage) | Us | Ties your choice to our consent record so we can evidence it. A random value, not used to track you or profile you, and created whether you accept or decline. | Necessary | Until you clear site data |
| Theme preference (local storage) | Us | Remember light/dark mode | Necessary | Until you clear site data |
| Interface preferences (local & session storage) | Us | Remember small display choices — for example, a collapsed panel or a dismissed banner | Necessary | Until you clear site data / end of session |
_ga, _ga_* | Google Analytics | Aggregate usage measurement | Analytics (consent) | Up to 2 years |
| Ahrefs analytics tag (sets no cookie) | Ahrefs | Aggregate usage measurement — cookieless; no identifier is stored on your device and you are not tracked across sites | Analytics (consent) | No storage on your device |
Service Providers
We use vetted service providers to operate the Service. Each processes personal data only on our documented instructions, under a data-processing agreement, and only as needed to provide its service to us. We disclose personal data to the following categories of recipient:
| Category of recipient | What they do for us | Data involved | Location / transfer |
|---|---|---|---|
| Cloud hosting & infrastructure | Application hosting, database, file storage, compute, and secret management | Account, subscription, prompts, watchlists, notes, and reports | United States / global (SCCs) |
| Identity & authentication | Sign-in and account security | Email, name, authentication identifiers | United States / EU (SCCs) |
| Payment processing | Subscription billing | Email, billing metadata, a customer/subscription identifier | United States (SCCs) |
| Email delivery | Transactional and opt-in email, notifications, and digests | Recipient email + name, message content | European Union |
| AI / large-language-model processing | Drafting the wording of Ask answers and reports from your prompt | Your prompt/question text and the measurements we assemble | United States (SCCs / DPA) |
| Analytics (with your consent) | Aggregate usage measurement | Aggregate usage data; IP processed transiently | United States / other (consent-based) |
We keep a current internal record of the specific providers in each category and update it as our providers change. Where the law gives you the right to the identity of the specific recipients of your personal data (for example, in response to a data-subject access request), you may request it at support@enginerds.com and we will provide it unless the law permits us to decline.
International Data Transfers
We are based in the United States, and some of our providers are located in or transfer data to the United States and other countries. Wherever your data crosses a border, we require appropriate contractual safeguards from the provider — in practice Standard Contractual Clauses (and the UK Addendum where relevant), supported by a transfer assessment. Where a provider is certified under the EU-US Data Privacy Framework, we may also rely on that certification.
Retention
We keep personal data only as long as needed for the purpose it was collected, then delete or anonymize it. Our schedule:
| Data | Retention |
|---|---|
| Ask questions & answers | Automatically deleted after 60 days |
| Account, watchlists, notes, saved reports, custom lenses, preferences | For the life of your account; deleted or anonymized on account closure or a verified erasure request |
| Subscription & billing records | Kept as needed to provide the subscription and to meet tax/accounting obligations, then deleted |
| Purchase-consent & cancellation records | Kept for at least three years, and at least one year after the agreement ends, whichever is longer — automatic-renewal law requires us to retain proof of what you agreed to. Kept longer only where necessary for tax, accounting, fraud-prevention or legal claims. Then deleted automatically |
| Feature-usage records (per-account) | Kept while your account is active to operate quotas and allowances; deleted or anonymized on account closure or a verified erasure request |
| API keys & usage metadata | While the key is active plus a short security window; keys are stored only as a hash |
| Waitlist & report email subscriptions | Until you unsubscribe/withdraw or ask us to delete it; removed on request |
| Security & abuse logs | A short period as needed for security, then deleted |
| Consent records (proof of your cookie choices) | Kept as evidence of consent for as long as needed to demonstrate compliance, and then deleted |
| Backups | Held on a rolling basis and overwritten in the ordinary course |
Your Rights
Everyone. You can ask us to access, correct, or delete your personal data, and to stop optional email, by emailing support@enginerds.com. You can also delete much of your own content (notes, watchlists, custom lenses, saved maps) directly in your account. We verify requests against your account and respond within the timeframe the applicable law requires. We will not discriminate against you for exercising your rights.
California residents (CCPA/CPRA). To the extent the CCPA and CPRA apply to us, California residents have the rights those laws provide — to know the categories and specific pieces of personal information we collect (set out above), the sources, purposes, and the categories of recipients (our subprocessors); to request access, deletion, and correction; and to opt out of the "sale" or "sharing" of personal information. Regardless of whether we currently meet every statutory applicability threshold, we honour verified requests of those kinds, as described below. We do not sell or share your personal information for cross-context behavioral advertising, and we treat a Global Privacy Control signal as a valid opt-out. You may use an authorized agent, and you will not be discriminated against for exercising these rights.
Everyone, wherever you live. Whether or not a particular privacy law applies to us in your case, we honour verified requests to access your personal data, get a copy of it in a portable form, have it corrected or deleted, have its use restricted, and object to a use based on our legitimate interests. Where we rely on your consent, you can withdraw it at any time without affecting processing already carried out. We do not charge for this and we do not treat you differently for asking. Some records — billing and purchase-consent evidence — we are required to keep, and we will tell you when that applies to part of a request.
Do Not Track / Global Privacy Control. Because there is no consistent industry standard for Do Not Track, we respond to browser privacy signals as follows: a GPC or DNT signal turns off non-essential analytics and is recorded as an opt-out of any "sale"/"sharing" (of which we do none).
How We Secure Your Data
We use commercially reasonable technical and organizational measures — encrypted transport (HTTPS/TLS), access controls, hashed API keys and credentials handled by our identity provider, and managed secret storage — to protect personal data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach affecting your personal data occurs, we will notify affected users and regulators as required by law.
Children's Privacy
The Service is not directed to children under 13, and account, subscription, and API features are intended for adults (18+) or those with the legal capacity to contract. We do not knowingly collect personal data from children under 13. If you believe a child has provided us personal data, contact us and we will delete it. Where your country requires parental consent for older minors, we will require it before collecting their data.
Links to Other Websites
The Service may link to sites we do not operate, including the news outlets we cite. We are not responsible for the privacy practices of those sites; review their policies before providing personal data.
Business Transfers
If we are involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction. We will provide notice before your personal data becomes subject to a different privacy policy.
Changes to This Policy
We may update this Privacy Policy. For material changes we will post the updated policy here, revise the "Updated" date above, and — where appropriate or legally required — notify you by email or a prominent notice. Your continued use after an update reflects the current policy, except where a change requires your consent, which we will request separately.
Contact Us
- By email: support@enginerds.com
- By mail: Spike-Buster Media LLC, 13157 Mindanao Way #188, Marina del Rey, CA 90292, United States