Last updated: August 1, 2026
What we collect, and when
If you join the waitlist: your email address, plus a short attribution note about how you found us (the referring site's hostname or campaign tags in the link you clicked). Each signup also gets a randomly generated referral code, shown to you once you've joined so you can share your own invite link.
If you arrived through someone's referral link: the link carries their 8-character referral code (never their email or name). Your browser remembers that code locally for up to 30 days, and if you then join the waitlist, it is stored on your signup record so the person who invited you moves up the list. We can see that a code referred a signup — we never show anyone who signed up with their code, and the code says nothing about you.
If you ask to be emailed when an ingredient's evidence grade changes (the "watch this ingredient" option): your email address, the list of ingredients you chose to watch, the same kind of attribution note, and — once we have emailed you an update — a record of which update batch you were sent, so we never send you the same change twice. Unsubscribing deactivates the subscription rather than erasing the row, so re-subscribing later works; you can ask us to delete it outright at any time (see below).
If you answer the optional one-tap question after signing up (your biggest focus challenge): your answer is stored anonymously. It is not linked to your email or to you, and we couldn't connect it back to you if we tried.
If you use the free Stack Audit: the list of ingredients you selected is stored anonymously so we can see, in aggregate, what real visitors already take. It is never linked to your email or to you — even if you also join the waitlist. If you create a shareable results link, your ingredient list is encoded in the link itself: anyone you send it to can see the list, but nothing in it identifies you.
If you just browse: we use cookieless, privacy-focused analytics (Vercel Web Analytics, and PostHog configured cookieless) that record page views and anonymous product events — things like "a signup form was seen" or "a stack audit was run" — so we can tell which pages and tools are useful and where people give up. PostHog is configured to keep nothing on your device: no cookies, no local storage. It assigns a random identifier that lives only in your browser tab's memory — it links the events of a single visit together (that's what makes "how many people who saw the form joined" answerable), disappears when you close or reload the tab, and is never written to disk, so separate visits can't be connected to each other or to you. No cross-site tracking, no advertising identifiers, no session recording, and nothing that identifies you personally.
When you submit one of our forms: a bot check by Cloudflare Turnstile runs to keep automated abuse out. Cloudflare receives standard technical signals from your browser — including your IP address — to make that human-or-bot call, and may set its own functional cookies while doing so (see the cookies section below). We never see or store those signals ourselves.
Briefly, in server memory: your IP address is used to rate-limit our signup endpoints so they can't be abused. It is held in memory only and is not written to our database as part of your record. Where our own code writes to server logs, it refers to your email by a one-way hashed stand-in rather than the address itself.
What we use it for
Your email is used to send you what you signed up for: the Clean Focus Stack Guide, a short welcome series introducing how we grade evidence and the free tools (a handful of emails over your first days on the list, each with one-click unsubscribe), occasional product updates, and ingredient research from The Signal — including a digest when our published evidence grades change. If you opted into evidence alerts, we also email you when a watched ingredient's published grade changes — nothing else rides along, and we confirm that subscription by email so you always have a record and an unsubscribe link. To make sure we never send the same thing twice, we keep a record of which of these emails each address has been sent. The anonymous demand-signal answers and Stack Audit entries guide what we build and write (we read the demand-signal answers only as aggregate counts). That's it.
What we never do
- We do not sell, rent, or trade your email or any other data.
- We do not run advertising trackers or third-party ad pixels on this site.
- We do not use cookies for tracking, advertising, or analytics. The only cookies that can appear at all come from Cloudflare's bot check, described next.
- We do not send daily emails, and unsubscribing is honored immediately.
Cookies and browser storage, exactly
This site sets no cookies of its own, and our analytics are cookieless. The one exception comes from a service we use: Cloudflare Turnstile, the bot check on our signup forms, may set Cloudflare's own functional cookies (such as __cf_bm) while it verifies you're human. Those cookies exist to tell people from bots and to secure the form — they are not used to track you across sites or to advertise to you.
None of these are cookies, but they deserve the same detail: three things can be saved in your browser's local storage, on your device. Two of them never leave it.
ssl-watchlist-v1— the ingredients you have tapped "watch" on. This is what lets the Evidence Updates page put your ingredients first without asking you to create an account. It stays on your device; we never receive it.ssl-alert-optin-v1— which ingredients this browser has already requested email alerts for, so the form shows a confirmation instead of asking you again. A display hint only; it stays on your device.ssl-ref-v1— a referral code from an invite link and the time it arrived, kept for up to 30 days as described above. This is the one that can leave your device, and only if you join the waitlist. It identifies the person who invited you, never you.
Clearing your browser's site data removes all three. None of them are used to profile you or to follow you to another site.
Where your data lives
The site runs on Vercel. Our database — waitlist signups and evidence-alert subscriptions — is a Postgres database hosted by Supabase in the United States (AWS us-west-2, Oregon). Emails are sent through Resend, our email service provider, which processes your address solely to deliver our messages and, if you're on the list, keep you in our contact audience there (including your unsubscribe status, so an opt-out sticks). Analytics are processed by Vercel Web Analytics and PostHog (US cloud), both running cookieless here; the anonymous events they receive contain no email and no name, and the only identifier involved is the per-visit, memory-only one described above — it never survives past closing or reloading the tab. Cloudflare processes the bot-check signals described above on its own network. These providers act on our instructions; none of them may use your data for their own purposes.
If you live in Canada or anywhere else outside the United States: your information is stored and processed in the United States, which means it can be subject to lawful access by US authorities under US law. Canadian privacy law permits this kind of cross-border storage as long as we tell you clearly — this paragraph is us telling you. If we ever move storage to Canada, this page will say so.
We can optionally route new signups to one additional tool via a webhook (for example, a newsletter platform). That integration is currently switched off. If we ever enable it, it will receive only your email, attribution source, and signup time — never anything else — and this page will be updated first to name the specific tool before it goes live.
Your choices and rights
Every email we send includes a one-click way to unsubscribe, and you can also just ask. Unsubscribing stops all of our emails, evidence alerts included. To unsubscribe, or to have your email permanently deleted from the waitlist, our evidence-alert list, and our email provider's records, contact hello@signalstatelabs.com and we'll confirm once it's done. Depending on where you live (including under Canadian privacy law — PIPEDA and BC's PIPA — the GDPR, and California's CCPA), you may also have formal rights to access, correct, or delete your personal information — the same email address is the way to exercise them.
Changes
If our data practices change, this page changes first, with a new date at the top. We won't quietly expand what we collect.
Contact
Questions about this policy: hello@signalstatelabs.com or the contact page.
Signal State Labs is pre-launch. This policy describes the site as it operates today and will be reviewed by counsel before commercial launch; if anything changes, the update will be posted here.