← RedlineEffective 13 August 2026
Legal

Privacy Notice

Redline Labs operates Redline and is the data controller for the personal data described below. Questions go to privacy@redline.app.

1. Our role

We decide why and how your personal data is processed for the Redline service, so we act as controller. Our payment reseller acts as an independent controller for purchases; see section 4.

2. What we collect and why

DataPurposeLegal basis
Account email and authentication identifiersCreate and secure your account, sign you in, contact you about the servicePerformance of a contract
Benchmark results: subsystem scores, index, grade, timestampsShow your history, compute deltas between runs, render shared reportsPerformance of a contract
Device profile: CPU thread count, reported memory, GPU string, form factor, user agentInterpret scores and produce the written analysisPerformance of a contract
URLs you submit to the delivery audit and the resulting metricsRun the audit and return results; enforce fair use and abuse limitsPerformance of a contract; legitimate interest in preventing abuse
Anonymous device benchmark contributions (score plus hardware class, no account link)Build the percentile ranking that compares devicesConsent (opt-out available before the run is contributed)
Consent record: choice, timestamp, detected region, sourceProve and honour your advertising consent decisionLegal obligation; stored on your device and mirrored in a cookie
Security and usage logs: hashed IP address, route, timestamp, API key identifierRate limiting, abuse prevention, incident investigationLegitimate interest in keeping the service available and secure

Benchmarks themselves execute in your browser. A run is only stored on our servers when you are signed in, and a report is only publicly readable when you explicitly publish it.

3. Cookies and advertising

Essential cookies keep you signed in and remember your consent choice. On the free tier we show advertising through Google AdSense, which sets its own cookies and identifiers. In the EEA, UK and Switzerland the ad script is only loaded after you opt in; elsewhere you can opt out at any time, including a "do not sell or share" control for California residents.

You can review and change your decision, and see a full log of your consent changes, in the privacy panel on the home page. Team subscribers see no advertising at all.

4. Who we share data with

  • Lovable Cloud (Supabase infrastructure)Application hosting, database, authentication and file storage.
  • Lovable AI Gateway (Google Gemini models)Generating the written analysis of a benchmark run.
  • Paddle.com Market LtdMerchant of Record: checkout, payments, tax, invoicing, refunds.
  • Google AdSenseAdvertising on the free tier, only after consent where required.
  • Professional advisers (legal, accounting) where necessary.
  • Authorities where we are legally required to disclose.

The full list with data categories and regions is on the subprocessors page. We do not sell your personal data.

5. International transfers

Some providers process data outside the UK and EEA. Where that happens we rely on adequacy decisions or Standard Contractual Clauses with the provider.

6. Retention

Run history is kept until you delete it or close your account. Published reports stay live until you unpublish or delete them. Security logs are kept for up to 90 days. Anonymous device contributions cannot be linked back to you and are retained indefinitely as aggregate statistics. Billing records are retained by our reseller for the period tax law requires.

7. Your rights

You can request access, correction, erasure, restriction, portability, or object to processing, and withdraw consent at any time. Signed-in users can export every stored run as JSON and permanently delete their account and data from the account panel, without contacting us. For anything else, email privacy@redline.app; we respond within one month. If you are in the UK or EEA you may also complain to your supervisory authority.

8. Security

We use encryption in transit, row-level access rules so users can only read their own rows, hashed API keys, hashed IP addresses in rate-limit records, and least-privilege server access. See the security page for details and how to report a vulnerability.

9. Changes

We will update this notice as the service evolves and will announce material changes in the app before they take effect.