Privacy
What the registry stores, why, and how long. Written against what the code actually does. If the two ever disagree, the code is the bug.
Last updated 2026-08-19Company profiles are not personal data by design
Cards describe companies and what they sell. The format has no field for an individual: no named contacts, no job titles, no personal email addresses. The one contact channel a card carries is a role address the company published itself (sales@, a quote form, a switchboard number).
Where a published source names an individual, the generator is instructed not to carry it across. If one slips through, report it and it will be removed.
If you claim a profile
Request logs
Every profile view, JSON fetch and search query is logged. This is deliberate and it is a product: sellers get to see which buyer-agent questions their category attracts and whether they appeared in the answer.
If we contacted you
We write to a small number of people at companies whose profiles we published, once, to tell them the profile exists and how to claim or remove it. If that was you, this section is the notice the law requires and it is live before the first message goes out.
Every message carries a one-click unsubscribe, and the link in it takes effect immediately. Unsubscribing stops the email; it does not remove your company’s profile, which is a separate request with its own path. To have your contact details deleted outright rather than suppressed, write to hello@itha.ai.
There is no tracking pixel in these messages and no open tracking of any kind. The links in them carry a single parameter so we can tell whether a message led to a company claiming its profile; that is the whole of it, and it is why we cannot tell whether anybody read one.
Retention
Retention period for request logs: 12 MONTHS.
Requests
To remove a company profile, use the opt-out path. It is instant and needs no correspondence. For anything else, including a request about personal data, write to hello@itha.ai.