🌿NoiseGate

Privacy Policy

Effective date: April 30, 2026

NoiseGate is committed to protecting your privacy. This policy explains what information we collect, how we use it, who we share it with, and what rights you have over your data. By creating an account or using NoiseGate, you agree to the practices described here.

1. Information we collect

Account information
Email address — used for authentication, password resets, and product updates
Display name
Password — stored as a secure hash, never in plaintext
Content you create
Posts: question text, question type, answer options, and any context images you upload
Responses: selections, ratings, rankings, or short text answers you submit to others’ posts
Behavioral data

To maintain result integrity, NoiseGate automatically collects:

Response submission time — used to detect and flag low-quality responses submitted too quickly
Attention check results — pass/fail flag (see Section 4 for full disclosure)
Signal Score — a numeric reputation calculated from your response history and quality
Technical & usage data
IP address (collected automatically by our hosting provider, Vercel)
Browser type and operating system
Pages visited and features used
Session duration

2. How we use your information

To create and maintain your account
To provide core product functionality: publishing posts, collecting responses, displaying results
To calculate signal clarity, confidence tiers, and your Signal Score
To filter low-quality responses using behavioral quality controls (see Section 4)
To send transactional emails: account confirmation and password resets
To send product updates and announcements — you may opt out at any time
To improve the product using aggregated, anonymized usage data
To comply with legal obligations

3. Data sharing & third parties

We do not sell your personal data. We do not share your data with advertisers. The only third parties that receive your data are the vendors who help us operate the product:

Supabase

Our database, authentication, and file storage provider. Supabase processes all account data, post data, and response data on servers located in the United States. Supabase is bound by a Data Processing Agreement (DPA) under GDPR Article 28.

Vercel

Our hosting and deployment platform. Vercel processes IP addresses and request metadata for all users who access the application.

GitHub

Our source code is hosted on GitHub. GitHub does not process user data directly.

If we add any additional third-party services, we will update this Privacy Policy and notify users before doing so.

4. Automated quality controls & silent filtration

NoiseGate uses behavioral quality controls to filter low-quality responses. These controls operate silently — respondents are not informed at the time of response that a quality check is occurring.

Every response session includes an embedded attention check with a verifiable correct answer
Responses submitted in under 4 seconds are automatically flagged as potentially low-quality
Responses that fail quality checks are recorded with a flag and excluded from filtered results
The respondent is never notified that their response was flagged or excluded
Post owners can see the count of filtered responses but cannot identify which respondents were filtered

This filtration is a core product function. It exists to protect the integrity of signal results. By using NoiseGate as a respondent, you acknowledge and consent to this automated quality assessment.

5. Signal Score

Every NoiseGate user has a Signal Score — a numeric reputation calculated from your response history and quality. Your Signal Score is:

Visible to you in the navigation bar
Displayed as one of four tiers: Seedling 🌱, Growing 🪴, Established 🌿, or Trusted 🌳
Used internally to weight responses in filtered results — high-trust scores carry more weight
Included in your data export if you request a copy of your data

If we ever use your Signal Score for automated decisions that significantly affect your access to the platform, we will disclose this and provide a right to human review, as required by applicable law.

6. Respondent anonymity

Post owners cannot identify individual respondents to their posts. Response data is presented only in aggregate. Individual response records are stored in our database for quality assurance purposes but are not exposed to post owners or any other user.

This is an intentional design decision — not a limitation. Anonymity produces more honest signal.

7. Data retention

Account data: retained while your account is active; deleted within 30 days of a deletion request
Post data: retained while your account is active; you may delete individual posts, which removes all associated responses
Response data: retained as long as the associated post exists
Behavioral / Signal Score data: retained while your account is active; deleted with your account
Server and access logs: retained per Supabase and Vercel’s default policies (typically 30–90 days)

8. Your rights

All users have the following rights, regardless of where they are located:

AccessRequest a copy of all personal data we hold about you.
DeletionRequest deletion of your account and all associated data.
CorrectionUpdate your account information at any time.
Data portabilityPost owners can export results as CSV. You may also request your full data in a machine-readable format.
Opt outUnsubscribe from marketing emails at any time using the link in any email we send.

California residents have additional rights under the CCPA. EU and UK residents have additional rights under the GDPR and UK GDPR, including the right to lodge a complaint with a supervisory authority. We will respond to verified requests within 30 days.

To exercise any of these rights, contact us at: [hunter@teamhat.org]

9. Cookies & tracking

Authentication cookies

Supabase uses session cookies to maintain your login state. These are strictly necessary and cannot be opted out of without losing access to your account.

No advertising cookies

NoiseGate does not use advertising networks, tracking pixels, or third-party analytics that track you across websites. We do not sell or share your data for advertising purposes.

10. Data security

All passwords are stored as secure hashes using bcrypt — never in plaintext
All data in transit is encrypted via HTTPS/TLS
Database access is controlled by Row Level Security (RLS) so users can only access their own data
API keys and secrets are never exposed in client-side code or public repositories

In the event of a data breach, we will notify affected users by email within 72 hours. If EU users are affected, we will also notify the relevant supervisory authority as required by GDPR.

11. Children's privacy (COPPA)

NoiseGate is not intended for children under the age of 18. We do not knowingly collect personal information from children under 18. If you are under 18, do not create an account or submit any information through this service.

If we become aware that we have collected information from a child under 18, we will delete that account and all associated data immediately.

12. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email and update the effective date at the top of this page. Your continued use of NoiseGate after a material change constitutes acceptance of the updated policy.

13. Contact

Questions about this Privacy Policy or want to exercise your data rights?

Contact us at: [hunter@teamhat.org]

⚠️ This document has not yet been reviewed by a licensed attorney.
Terms of Service →