Who this notice covers
This notice explains how Rightmark ("we") handles personal information on rightmark.ai, on bscout.ai short links, in the owner, Scout and buyer portals, and in the staff console.
Rightmark helps companies license their private data to AI developers. We estimate what the data is worth, check who owns it, and route it to licensees the owner approves. Rightmark Scouts introduce owners to us and are paid from our own income.
The short version
- The appraisal asks for nothing personal. Your answers stay in your browser until you ask for a reviewed estimate or choose to save your result.
- We ask for contact details only when you want a reviewed estimate, want to save your progress, or join a program.
- We never hold your passwords. Sign-in uses a 6-digit code or a link sent by email.
- Rightmark never keeps a copy of licensed data. Verification documents are stored privately and deleted 12 months after a deal closes, or sooner if you ask.
- We do not sell personal information, and we do not use it for advertising.
- Our analytics set no cookies and carry no personal data.
- You can see, export, correct and delete your personal data. Owners can do most of this in the portal.
Notice at collection for California residents
This section is our notice at collection under California law. It applies when we collect personal information from California residents, and it lists what we collect, why, and how long we keep it.
What we collect, by category:
- Identifiers: name, email address, phone number if you choose to give it, company name and website, referral code, and account and session ids. Network addresses are stored only as a hash with a daily salt and cleared after 30 days.
- Professional information: your role (for example owner, Scout or adviser), your job title where you give it, whether you can sign for the company, and for Scouts, a profile link and the kind of network you work in.
- Commercial information: submissions about your company’s data, appraisal results, offers and deals, and for Scouts, the earnings ledger.
- Internet activity: sign-in times, Scout link clicks (the link used, the landing page, a device class and a coarse referrer class), and records of actions taken in the portals and the console.
- Documents you upload: ownership and verification documents, stored privately.
- Sensitive personal information: we do not ask for it.
Why we collect it: to give you an estimate and a reviewed estimate, to run your submission, to verify ownership, to route your data to licensees you approve, to run the Scout program and pay Scouts, to keep accounts secure, and to meet legal duties. The section on how we use information has the full list.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
How long we keep it: the section on retention below has every period. In short, submissions are kept for the life of the relationship plus 24 months, drafts you never submit lose their personal fields after 30 days, logs are kept 30 days, and verification documents are deleted 12 months after a deal closes or when you ask.
Your California rights are described in the California rights section below.
The appraisal asks about your data, not about you
The appraisal estimator runs in your browser. It asks about your company’s data: the data family, headcount, years of records, region, tools, regulated data and similar facts.
Nothing you type is sent to us until you ask for a reviewed estimate or choose to save your result. At that point the intake rules below apply.
Our analytics record that an appraisal started or finished, with the data family, a range bucket and the confidence level. These events carry no personal data.
If you upload a Repo Check report, we receive the report file, not your code. Repo Check runs on your own computer and uploads nothing on its own. Before you upload, the site shows exactly what will be sent, and we reject a report that contains email addresses, web addresses or file paths.
Our public quote service computes an estimate from what you send and stores nothing.
Asking for a reviewed estimate
When you ask for a reviewed estimate, we collect:
- Contact details: your name, your role, your email address, and your phone number if you choose to give it.
- Company details: the company name and website, and the answers that shape an offer for your data family, such as company status, prior licenses and their exclusivity, software vendors’ claims to training rights, your appetite for exclusivity, authority to sign, and whether staff have been told.
- A Scout or partner code, if you type one or arrived through a Scout link.
- Your consent to be contacted, and the version of this notice you saw.
Your form saves as you go, so a reload does not lose your answers. If you ask, we email you a link to resume, which works for 7 days. A draft you never submit loses its personal fields after 30 days; we keep only the data family, a range bucket and how far you got.
When you submit, our server recomputes the estimate from your answers and stores its own result.
To keep the forms free of spam, we run a bot check and apply rate limits. Rate limits use hashed keys that are cleared within a day.
If a Scout or adviser fills in the form for an owner, we record the contact details they give us.
The owner portal
When you sign in to the owner portal, we collect and keep:
- Your email address, for sign-in. Sign-in sends a 6-digit code and a link. The code works for 10 minutes; the link works for 15 minutes and only in the browser that asked for it.
- A session record: when it started, when it was last used, and a hashed network address that is cleared after 30 days.
- Documents you upload for verification, with the file name, size and a fingerprint (SHA-256) of the file. Accepted types are PDF, PNG, JPG, WebP, CSV, TXT, JSON and DOCX, up to 25 MB per file.
- Messages between you and our staff.
- A log of the consents you gave or withdrew.
- Your requests to withdraw a submission, and the reason if you give one.
- Your requests to export or delete personal data.
You see only your own records. Downloads of your documents use links that expire after 5 minutes.
Rightmark Scouts and Scout links
When you apply to be a Scout, we collect your name, email address, an optional profile link, the kind of network you work in, and how you found us. We record that you accepted the Scout terms. Once approved, you get a referral code and links on rightmark.ai and bscout.ai.
When someone clicks a Scout link, we record the click: which link was used, the landing page, a device class (desktop, mobile, tablet or bot), browser signals that tell a real click from a forced redirect, a coarse referrer class (never the full address), and a network address hash with a daily salt that is cleared after 30 days. We then set a first-party attribution cookie, described in the cookie notice.
We keep an earnings ledger for each Scout, with the rule that produced each amount and its state. If you join the leaderboard, we show the display name you choose and counts only, never money.
Scouts see the owners they referred as a company name and a stage only. Scouts never see owners’ contact details, appraisal amounts or other Scouts’ data.
We will update this notice before we collect payout or tax details from Scouts.
The buyer portal
Buyer accounts are created only by staff invitation. For each buyer contact we collect name, email address, and phone number and job title where given, and notes our staff keep about the relationship.
We record acceptance of the nondisclosure agreement and the buyer terms, sample requests, standing orders and messages. Catalog use is logged and rate limited.
Buyers see data cards that describe a collection: type, size, dates, languages, formats, known gaps and rights status. A data card carries no owner identity before an agreement.
The staff console
For Rightmark staff we collect name, email address, role assignments and second-factor credentials. A passkey stores a public key, never a private one. An authenticator app secret is stored encrypted. Recovery codes are stored hashed and shown once.
Staff sessions last 8 hours at most and end after 30 minutes without use. Every staff change, export, download and failed authorization is written to an append-only audit log.
Other places we collect information
- Partner program: the contact person for a partner firm, and the sites where the partner may embed our appraisal widget. The widget itself collects no personal data and reads no session.
- Bounty alerts: if you subscribe, we keep your email address once you confirm it by email. A subscription you never confirm is deleted after 7 days.
- Messages you send us: your contact details and your message.
- Every visit: our hosting provider processes your network address and browser details to deliver the page and protect the service.
What we do not collect
- Passwords. Sign-in is passwordless. Transfers use scoped, revocable connections your admins approve, or exports.
- A copy of licensed data. It goes from your systems to the licensee you sign with.
- Your code. Repo Check runs on your own computer, and you send us its report, not the code.
- Personal data in analytics, logs or error reports. Logs are scrubbed of names, emails, phone numbers, free text, tokens and cookie values before they are written.
How we use information
We use personal information to:
- Give you a reviewed estimate and explain it.
- Run your submission: review it, ask follow-up questions, and send receipts and status emails.
- Verify ownership, consents and the rights you can license.
- Route your data to licensees, only on terms you approve.
- Run the Scout program: approve Scouts, attribute referrals, compute and record earnings, and resolve disputes.
- Run the buyer portal and the partner program.
- Keep accounts and the service secure: sign-in, sessions, second factors for staff, rate limits, bot checks and the audit log.
- Measure how the site is used, with cookieless analytics that carry no personal data.
- Meet legal duties, enforce our terms, and respond to lawful requests.
We email you about your submission or your account.
Service providers and what each one receives
We use these services to run Rightmark. Each receives only what it needs for its job. The list on this page matches the integrations in our code, and a test keeps the two the same.
Hosting and server code
In use- Provider
- Our hosting provider
- What it receives
- Your network address and browser details on each request, to deliver pages and protect the service.
Database
In use- Provider
- Our managed Postgres provider
- What it receives
- Our system of record: submissions, accounts, consents and the Scout ledger.
Private file storage
In use- Provider
- Our hosting provider
- What it receives
- Verification documents, Repo Check reports and personal data exports, stored privately.
Transactional email
In use- Provider
- Our email delivery provider
- What it receives
- Your email address and the message: sign-in codes, receipts and status updates.
Bot protection on forms
In use- Provider
- Our hosting provider
- What it receives
- Request headers when you use a protected form. Never what you type.
Cookieless analytics
In use- Provider
- Our hosting provider
- What it receives
- Page views and events with no personal data, such as the data family of an appraisal.
Staff notifications
In use- Provider
- Our staff chat workspace
- What it receives
- A reference number, a data family, a range bucket or stage, and a console link. No names, emails or text you typed.
Error reports
Our own logs only- Provider
- Our own scrubbed logs
- What it receives
- Error details scrubbed of names, emails, phone numbers, tokens and free text. We will name any outside error reporting provider here before we add one.
Customer relationship management
Switched off- Provider
- None today
- What it receives
- Nothing. The sync is built but switched off, and we will name the provider here before it is turned on.
Antivirus scanning of uploads
Not in use- Provider
- None at launch
- What it receives
- Nothing. Uploads are not sent to a scanning service at launch, and we will name the provider here before we add one.
How long we keep it
Submissions and the personal data in them
- How long
- For the life of the relationship plus 24 months.
- Then
- We remove the personal fields and keep the financial and audit records our ledger needs.
Appraisal and intake drafts you never submit
- How long
- 30 days after your last change.
- Then
- We remove the personal fields and keep only the data family, a range bucket and how far you got.
Verification documents you upload
- How long
- 12 months after the deal closes, or sooner when you ask.
- Then
- We delete the file and its record.
Logs, and the hashed network addresses on sessions and Scout link clicks
- How long
- 30 days.
- Then
- We delete the log entries and clear the hashes.
Files we build when you ask for an export of your personal data
- How long
- Until the export request expires. Each download link works for 5 minutes.
- Then
- We delete the file a day after the request expires.
Bounty alert subscriptions
- How long
- Until you unsubscribe. A subscription you never confirm lasts 7 days.
- Then
- We delete the subscription 30 days after you unsubscribe.
The Scout earnings ledger, consent records and the audit log
- How long
- As long as the law requires us to keep financial records and evidence of what was agreed and done.
- Then
- We keep these records without the personal fields we no longer need.
Your rights and how to use them
You can ask to:
- See the personal data we hold about you, or export it. Owners can request an export in the portal: we build a JSON file and give you a download link that works for 5 minutes.
- Correct it. Ask us, or change it in your portal where the portal offers it.
- Delete it. Owners can request deletion in the portal, and anyone can ask us. We delete what we have no reason to keep. Where we must keep a record, such as a ledger entry or an audit event, we remove the personal fields and keep a record that the deletion was done.
- Withdraw a submission. Owners can do this in the portal whenever they choose.
- Withdraw consent, for example to being contacted or to bounty alerts. Withdrawing consent does not affect what we did before.
We confirm a request by asking you to sign in with the email address on file, or by another check if you cannot. We do not treat you differently for using these rights.
California rights
If you live in California, you can ask us to tell you what personal information we collected, used and disclosed, to give you a copy, to correct it and to delete it. You can limit the use of sensitive personal information, though we do not collect it. You can opt out of sale and sharing, though we do not sell or share personal information.
You can use an authorized agent. We may ask the agent for proof of your permission and ask you to confirm your identity. We will not discriminate against you for using these rights.
If you are outside the United States
Rightmark is a US company and serves the United States at launch. If you are in another country, your local law may give you more rights. Contact us and we will help.
Children
Rightmark is a service for businesses and the adults who act for them. It is not directed to children, and we do not knowingly collect personal information from children. If you believe a child has given us personal information, contact us and we will delete it.
How we protect information
- Connections use HTTPS with strict transport security.
- Sign-in is passwordless. Staff must also use a passkey or an authenticator app.
- Every request is authorized on the server by role. Owners, Scouts and buyers see only their own records.
- Documents are stored privately and download only through links that expire after 5 minutes, and only as attachments.
- Uploads are checked: the file type must match the file’s contents, and sizes are limited.
- Sign-in, forms and exports are rate limited. Public forms have bot protection.
- Staff actions, exports and downloads are written to an append-only audit log that our application cannot edit or delete.
- Secrets live only in protected settings, never in code.
No system is perfectly secure. If we learn of a breach that affects you, we will tell you as the law requires.
Changes to this notice
When we change this notice, we update the date at the top. Every intake form records which version of this notice you saw.
Contact us about privacy
Write to us with "Privacy" in the subject line. We reply to every request.
Our contact inbox opens before launch, and its address will appear here.