1.Definitions
- Service.
- the StationScope website, applications, and recommendation tools (Tandem mode and Solo mode).
- Personal Information.
- information that identifies, relates to, or could reasonably be linked with you, including email address, the first name you may supply in Tandem mode, the address you type into the address box, and chat content you submit.
- Tandem Group.
- a set of two to five users using Tandem mode jointly to produce a shared neighborhood recommendation.
2.Information StationScope Collects
StationScope has no user accounts and no passwords. Everything below is collected because you typed it, because you paid for something, or because your browser sent it with the request.
- Tandem Mode. StationScope collects your email address, the first name you enter when you join a group (used only as a display label next to your contributions), chat responses (housing preferences, location constraints, lifestyle factors), the address you enter and the map coordinates it resolves to, city and neighborhood preferences, and group composition (number of members, relationship type, bedroom count, whether children are part of the household and their ages if you say so, and optionally MBTI personality types). Your email address is the join key for the group; the name is a label only.
- Solo Mode. StationScope collects the address you enter for station search, the map coordinates and nearest station it resolves to, any preferences you submit during the session, and the resulting chat transcript. Solo mode has no sign-in: a session identifier generated in your browser tab is the only link between your turns. If you buy Refine Further, the email address you give Stripe at checkout is also stored so the report can be sent to you.
- Payment Information. Card data is entered on a checkout page hosted by Stripe and is handled entirely by Stripe. StationScope never sees, receives, or stores full card numbers, security codes, or expiry dates. What StationScope stores is the Stripe checkout session identifier, whether the payment succeeded, the email address you gave Stripe, and the access code minted for that purchase.
- Technical and Usage Information. When you send a chat message, StationScope records your IP address, browser user agent, and language preference alongside the saved transcript. It also records the page that referred you, any campaign parameters in the link you arrived through, and the browser and platform hints your browser volunteers, unless your browser sends a Do Not Track or Global Privacy Control signal. When that signal is present, none of those attribution fields are captured at all, and the signal itself is recorded so the session can be left out of later analysis. StationScope also records the number of tokens each recommendation consumed, with no user identity attached, so it can track its own running costs.
3.Information StationScope Does Not Collect
Some categories are deliberately out of scope. StationScope does not ask for the following, and its chat is instructed not to probe for them.
- Income, salary, employment status, or credit history. The chat asks what you are willing to spend on rent, which is a budget figure you choose. It does not ask what you earn, who in your household earns more, or whether anyone is employed. If you volunteer that kind of detail, the chat is instructed to accept it and move on rather than follow up on it.
- Social Security numbers, government identification numbers, driver's license numbers, or financial account numbers.
- Protected-class characteristics as selection criteria. StationScope does not ask your race, color, religion, national origin, sex, familial status, or disability, and does not use any such characteristic to include or exclude a neighborhood. If you raise one of these topics in chat, the chat is instructed to decline the demographic question and redirect to the concrete feature you are likely asking about.
- Full payment card numbers, security codes, or expiry dates. These go to Stripe and never reach StationScope.
- Device GPS location. StationScope works from the address you type, not from your device's location sensor, and does not request location permission from your browser.
4.How StationScope Uses Information
- To generate neighborhood recommendations through large language models (currently the Anthropic Claude API).
- To deliver recommendation reports by email (through Resend).
- To store group data and chat transcripts on Supabase, so that multi-member Tandem flows can associate members with the same group and so that Solo and Tandem chats can be resumed.
- To take payment, confirm it succeeded, issue the access code or unlock that the payment bought, and answer billing questions later.
- To answer support messages you send, and to investigate a problem you report.
- To measure aggregate website usage through Google Analytics, which you can turn off, and to monitor the Service's own running costs and error rates.
- To review how the recommendation pipeline is performing and improve its quality, including reading stored transcripts when diagnosing a defect.
- To protect the Service against abuse, fraud, and chargeback disputes, and to comply with legal obligations or lawful requests.
StationScope does not sell your Personal Information, does not rent or trade it, and does not share it for cross-context behavioral advertising.
5.Scope and Legal Bases
The Service covers seven United States metropolitan areas, is offered to users in the United States, and is not directed at or marketed to residents of the European Economic Area, the United Kingdom, or Switzerland. StationScope does not claim to operate a full European data protection compliance program.
Where a data protection law that requires a legal basis does apply to you, StationScope relies on the following: performance of a contract, for the processing needed to produce and deliver the recommendation you asked for and to take payment; legitimate interests, for security, fraud prevention, cost monitoring, quality review, and aggregate usage analytics, which you can switch off at any time and which stops for any browser sending a privacy signal; consent, where you volunteer information the Service did not ask for; and legal obligation, where StationScope must retain or disclose records.
6.Third-Party Processors
StationScope engages the following third-party processors. Each receives only what its function requires, and each is governed by its own terms and privacy policy. StationScope does not control how these companies operate their own systems.
- Anthropic.
- AI processing of chat content; receives your chat messages and the group or session context needed to produce a recommendation.
- Resend.
- transactional email delivery; receives your email address and the rendered report or notification.
- Stripe.
- payment processing; hosts the checkout page and handles all card data. StationScope receives back only a session identifier, the payment status, and the email address you entered at checkout.
- Supabase.
- database; stores StationScope's group, member, recommendation, payment-unlock, and chat transcript records.
- Railway.
- hosting; runs the StationScope website and its backend, and therefore processes every request you make to the Service, including your IP address.
- LocationIQ.
- geocoding and address autocomplete; when you type an address, StationScope's server sends that text to return matching suggestions. Receives the partial address query and the map region of the city you selected. Map data © OpenStreetMap contributors.
- OpenFreeMap.
- interactive map tiles; the map in your browser loads base map tiles directly from OpenFreeMap, which therefore receives your IP address and the map areas you view (standard for any web map). No account, key, or cookie is involved. Map data © OpenStreetMap contributors.
- Geoapify.
- map images in emailed reports; StationScope's servers load base map tiles from Geoapify when composing the static map image in your report email. No data about you is sent; the request comes from StationScope's servers. Map data © OpenStreetMap contributors.
- Google Analytics.
- website usage analytics. It does not load, and receives nothing at all, if you have turned analytics off or your browser sends a privacy signal. Otherwise it receives your IP address, the pages you visit, and standard browser and device information, and sets its own cookies. StationScope uses this only to understand aggregate site usage.
StationScope may also disclose information to its professional advisers, to a successor in the event the Service is sold or transferred, or where required by law, subpoena, or a good-faith belief that disclosure is necessary to protect rights or safety.
7.Public Data Sources
The following are sources StationScope reads from, not processors it sends your information to. No user data is transmitted to any of them.
- United States Census Bureau (ACS 5-year estimates).
- public demographic and rent data by census tract, queried through the Bureau's public API. This product uses the Census Bureau Data API but is not endorsed or certified by the Census Bureau.
- Transit agencies.
- station names, routes, and coordinates derived from schedule data (GTFS feeds) published by the transit agencies serving each metropolitan area. StationScope is not affiliated with, endorsed by, or sponsored by any of them.
8.Cookies, Browser Storage, and Analytics
StationScope uses Google Analytics 4 to see aggregate traffic patterns, never for advertising. It runs by default, and the notice at the bottom of the screen tells you so. You can turn it off at any time, either from that notice or from the Cookie preferences link in the footer of the home page, and your choice is remembered in your browser. When analytics runs, it sets its own cookies and reports your IP address, the pages you view, and standard browser and device information to Google. Analytics is tied to a measurement identifier supplied by each deployment's configuration, so a deployment that has none collects nothing.
Your choice is stored in your browser under the key ss-analytics-consent-v1. If you turn analytics off, StationScope sets Google's own opt-out flag for that measurement identifier, expires the _ga and _gid cookies it can reach, and stops sending events. One limit is worth stating plainly: a script already loaded into the page you are looking at cannot be unloaded from it, so measurement stops right away but the script itself is gone only on your next page load. You can turn analytics back on from the same places.
The Service also uses your browser's own session and local storage to remember things like your current chat session identifier, your language choice, and your analytics choice. That data stays in your browser and is not itself sent to StationScope, though the session identifier accompanies your chat requests so the conversation can continue.
If your browser sends a Do Not Track or Global Privacy Control signal, StationScope treats it as an answer rather than a hint. Google Analytics never loads for that visit, the cookie notice does not appear, and the signal overrides analytics being on by default as well as any earlier choice to leave it on.
The same signal changes what the server keeps. A request carrying it is not recorded with a referring page, campaign parameters, or browser and platform hints, because those fields exist to work out where a visit came from and on what device. Your IP address, user agent, and language header are still recorded, since they serve abuse handling, support, and language selection rather than analytics. The signal is stored with the session so it can be left out of any later analysis, and two things about that are worth saying plainly: the Service runs no server-side analytics system for it to feed, and leaving flagged sessions out of internal analysis is an operating practice on StationScope's side rather than something the database refuses to do.
9.What StationScope Does Not Do
- StationScope does not operate advertising trackers and does not use your information for advertising or ad targeting. The only third-party measurement it uses is Google Analytics, solely to measure aggregate website usage, and only after you have allowed it (see Cookies, Browser Storage, and Analytics).
- StationScope does not share your individual chat content with other members of your Tandem Group beyond what the final recommendation report presents. The report aggregates each member's preferences into compromise findings rather than republishing them verbatim, and anonymizes content where reasonably practicable. Because the report is written for the whole group, do not enter anything in a Tandem chat that you would not want summarized to the people you plan to live with.
- StationScope does not sell your Personal Information and has never sold it.
10.Data Retention
StationScope keeps a written retention schedule, and the periods below are the ones it applies. Two rules shape all of them. A record of a payment is not deleted, because it is the only proof that money changed hands and it may be needed for refunds, disputes, and tax; what is removed from such a record is the personal detail hanging off it, and only long after the last window in which anyone would need to be contacted about the purchase. And nothing deletes a report a paying customer can still open, or a transcript a report still owed to a buyer would have to be rebuilt from.
- Solo chat transcripts: 90 days from your last activity in the session. If the session is behind a paid Refine Further unlock, 365 days instead, and never while a report you paid for has not been sent yet.
- Solo Refine Further records: an abandoned checkout that was never paid is deleted 90 days after it was started. A paid row is a financial record and the row itself is kept, with the buyer email address cleared 730 days after the purchase.
- Tandem groups: a group that was cancelled or expired without ever delivering anything is deleted 90 days after it was created. Any other group is deleted 365 days after it was created, together with its members, transcripts, and recommendation.
- A Tandem group unlocked by a payment is not deleted on any schedule, so the buyer keeps the report they paid for. Its chat transcripts are still deleted after 365 days, because the conversation is an input to the report rather than the report itself.
- Access codes: on a code that came from a purchase, the buyer email address stored in the code's notes is redacted 730 days after the code was issued, and the code record is kept as a payment record. A code that carries no payment, such as a comp or test code, is deleted 365 days after it was issued, once it has been used up or has expired and no surviving group still resumes from it.
- Broker workspace data: a client's response and the chat behind it are deleted after 365 days, and an expired broker sign-in session is deleted 30 days past its expiry.
- Broker account records, including the broker's own contact email address, have no retention period and are kept until the account is closed on request. Not everything here ages out, and this is the part that does not.
- Deletion request records are deleted 30 days after the request, and the token and cost log, which carries no identifier of any kind, is deleted after 730 days.
One thing about this schedule should be stated rather than glossed over. The periods above are defined and implemented, and the job that carries them out is written and scheduled, but it currently runs in a reporting mode that counts what is due without removing it. Switching it to actually delete takes a deliberate configuration change that has not been made yet, and it will be made after the first reports have been reviewed. Until then, treat the periods above as the retention StationScope applies to your data going forward, and the deletion route described below as the way to have your own data removed today, which works now and does not wait for that switch.
Copies held by the processors listed above, such as email delivery logs at Resend or payment records at Stripe, are kept under those companies' own retention schedules, which StationScope does not control.
11.Your Rights
Subject to applicable law, you have the right of access, meaning you may request a copy of the Personal Information StationScope holds about you; the right of correction, meaning you may ask StationScope to fix information that is inaccurate; and the right of deletion, meaning you may have the Personal Information it holds about you removed, subject to legitimate retention obligations. Deletion is self-service and does not require anyone's permission, and the two paths below are the ones to use. Access and correction go through the contact address, because they need a person to answer.
Solo mode has no account, so the credential is the session identifier your browser holds, which your tab stores under solo.session_id and sends with every turn of the chat. A request to /api/data/delete carrying that identifier returns a preview of exactly what would go and removes nothing; the same request with the confirmation flag set carries it out immediately. The transcript is deleted, any unpaid checkout rows are deleted, and a paid purchase record is kept with your email address cleared from it.
Tandem mode is shared, so a typed address on its own proves nothing. A request to /api/data/delete with your email address sends a confirmation link to that address; the link works once and expires after 24 hours. Opening it shows what is about to happen and removes nothing until you submit the form on that page, so a mail scanner or a link previewer cannot delete your data by fetching the link. The response is the same whether or not the address is known to StationScope, so the route cannot be used to find out whether a particular person used the Service.
Some things survive a deletion request, and it is better to say so than to let you find out later. A Tandem group is never destroyed to satisfy one member, so the other members' answers and any report someone paid for stay intact; what goes is you, with your name, address, coordinates, station, and chat cleared and your email address replaced by an unusable placeholder, including inside the group's stored report. A purchase record is kept as a financial and tax record with your address stripped out of it. A paid Solo report that has not been sent yet keeps the address it is going to until it is delivered. Closing a broker account is a separate request and is not covered by a renter's deletion request. And deletion reaches StationScope's own database only: it cannot pull back an email already delivered to someone's inbox, and it does not reach Stripe's payment records or Resend's delivery logs, which follow those companies' own retention schedules.
If you would rather a person handled it, or you want a copy of what StationScope holds about you, or you want something corrected, write to stationscope@gmail.com. Say which mode you used, the email address involved, and roughly when, so the right records can be found. StationScope may ask a follow-up question to confirm the request comes from you, and may decline a request it cannot verify.
Residents of California and of other states with comprehensive privacy statutes may have additional rights, including the right to know the categories of information collected and disclosed, the right to delete, the right to correct, and the right not to be discriminated against for exercising those rights. StationScope does not sell Personal Information or share it for cross-context behavioral advertising, so there is nothing to opt out of on that front. A Global Privacy Control signal from your browser is treated as a binding opt-out of analytics, as described above. Use the deletion routes above, or the contact address, to exercise any of these rights.
12.Data Security
StationScope takes reasonable measures to protect the information it holds. Traffic to the Service travels over encrypted connections, the database sits behind row-level access rules, payment card data never touches StationScope's own systems, and access to production data is limited to the operator. No system is perfectly secure, and StationScope cannot guarantee that its safeguards or those of its processors will never fail. You use the Service with that understanding. If StationScope becomes aware of a breach affecting your Personal Information, it will notify affected users as required by applicable law.
13.International Users and Data Transfers
StationScope is operated from the United States and its processors store and process data in the United States and, in some cases, in other countries where those companies operate. If you access the Service from outside the United States, you are sending your information to the United States, where privacy laws may differ from those of your own country, and you consent to that transfer by using the Service. The Service itself only covers United States metropolitan areas, so it is unlikely to be useful outside them.
14.Children's Privacy
The Service is intended for adults aged 18 or older who are searching for a rental, and it is not directed to children. StationScope does not knowingly collect Personal Information from anyone under 13, and does not knowingly collect it from anyone under 18. If you are a parent or guardian and believe a child has provided StationScope with Personal Information, contact StationScope and it will be deleted. Note that a parent describing their household in Tandem mode may mention the number and ages of their children; that is information the parent supplies about the household, and the children themselves are not users of the Service.
15.Changes to This Policy
StationScope may update this policy as the Service changes. When it does, the date at the top of this page will be updated, and the current version will always be posted here. If a change materially reduces the protection given to information already collected, StationScope will make a reasonable effort to give notice on the site before it takes effect. Continued use of the Service after an update means you accept the updated policy.
16.Contact
Questions regarding this Privacy Policy, and requests to access, correct, or delete your information, may be directed to stationscope@gmail.com. This is the only contact channel StationScope monitors.