Skip to main content
Policy

Privacy Policy

2ndSight is a product of 2nd Gen Kitchens, Inc.. This page says what we collect, who else touches it, how long we keep it, and how to get it back or have it erased. It describes what the product actually does today — not what we intend to build.

Last updated 3 September 2026

The short version

We collect your email, the addresses you look up, and what you bought. We do not sell personal information, and we have never done so. Usage analytics is on unless you turn it off, session replay is off unless you turn it on, and the panel further down this page controls both. You can download everything we hold about you, or delete your account, from your account page, and both take effect immediately. That covers what we hold against your email as well as what we hold against your account, which are not the same set. Four things listed below are described here before we collect them, and each one says so.

What we collect

  • Account details. Your email address, and your name if you sign in with Google. We use magic links and optional Google sign-in, so most accounts have no password for us to store.
  • What you look up. The addresses, concepts and neighbourhoods you request reads for, the answers you give in the intake questions (such as how many restaurants you have opened before), and the reads and watches you save. These are the product working, and they are tied to your account.
  • Purchases. What you bought, when, and for how much. Stripe handles the payment itself — card numbers never reach our servers.
  • Email activity. Whether a report or digest we sent was delivered, and whether it bounced, so we can tell a broken address from an uninterested reader.
  • Technical records. Standard server logs, and — when something breaks — an error report containing the message, the page you were on and your browser's user-agent string. These go into our own database, not a third-party monitoring service.
  • Usage analytics, on by default. Which pages and features get used, so we can make them better. This is on unless you turn it off, and you can turn it off at any time in the panel further down this page or from the notice you saw on your first visit. If your browser sends Global Privacy Control we treat that as turning it off, without you doing anything. The product works exactly the same either way.
  • Things you asked us for. A market you asked us to cover, an enquiry you sent us, access we granted you, a team you were invited to. Some of these arrive before you have an account and some instead of one, which is exactly why they used to be invisible to the buttons below. Nothing is owed to a departed account here: asking us to delete removes them outright.
  • Data errors you reported. If you tell us a record is wrong, we keep the report, the address it was about, and your email if you gave one. Deleting your account takes your address and your browser string off it and leaves the finding, because we may already have corrected the record because of it and undoing that would help nobody.
  • Email we sent you, and what happened to it. Which messages went to your address and whether they arrived, bounced or were marked as spam. Deleting your account takes the address off and leaves the delivery record: bounce rates are a property of our sending, not of you.
  • Requests you have made about your own data. Every export and every deletion is logged with the date and the outcome. This is the one thing a deletion does not delete, and the reason is the same reason it exists: erasing the record of a deletion would leave us unable to show we had honoured it. You can read it in full in your export.
  • Feedback you give us. If you rate a report or write us a note about one, we keep your answer and anything you typed, attached to your account and to the report it was about. Deleting your account deletes it, which moves our own historical satisfaction figures. That is the correct trade: we are not going to keep your written opinion after you have asked to be forgotten.
  • API call history. If you use an API key, we record which key called and when, so we can apply rate limits and show you what your key has been doing. It is deleted outright with your account.
  • Score audit trail. Every score the product produces is written to an append-only log with the inputs it used, so a number you quote back to us months later can be reconstructed exactly. Deleting your account removes your identity from those rows and leaves the calculation, because breaking the audit trail would cost you more than it saves you.
  • What you looked up, kept as a record. When the product scores an address, a ZIP or a neighbourhood for you, we keep a row saying what was scored, which concept you asked about, the score we gave and the date. It carries a random identifier for your browser so that reads you ran before signing in can be joined to your account afterwards, which is the only reason they are not lost at the sign-in step. It carries no IP address, no user-agent string and no email. This is part of usage analytics: turn that off, or send Global Privacy Control, and no row is written. If you ask us to delete your account we clear both the account link and the browser identifier, leaving an address, a concept and a date that are no longer about anybody.
  • What you tell us you came to do. We are building a single question, asked once after you have saved something, about what brought you here: scoring an address, watching an area, looking a business up, taking the data, checking the method. Your answer will sit on your profile and decide what the product opens on and what a digest leads with. It is optional, it changes nothing you can reach, and it is deleted with your account. Not collected yet: this paragraph describes it before the first answer is stored.
  • A phone number, if you give us one. We are adding an optional phone field to the business enquiry forms, and to nothing else. It will never appear on the sign-up step, and giving it is never a condition of using anything. We do not send SMS and we will not start without asking you separately and in writing. Enquiry records are deleted on request and aged out after two years in any case. Not collected yet: this paragraph describes it before the first number is stored.
  • What you type into the search box. We keep the text of searches, including the ones that find nothing, because a search we cannot answer is the clearest signal of what the database is missing. A row holds what was typed, what it resolved to if anything, which page it came from, a session identifier, the date, and your account if you are signed in. The text is kept for 90 days and then the identifiers come off it. Please do not type anything into a search box that you would not want kept for 90 days.
  • Which pages you open, while signed in. We keep a plain record of which parts of the product a signed-in account opens and when, in our own database and not with any third party, so we can tell which surfaces are worth keeping. It is your account, the page and the time, and nothing else. It is kept for 180 days and deleted with your account. Signed out, none of this is recorded.
  • Session replay, only if you switch it on. A recording of what you did on the public pages, with everything you type masked out. This one is off unless you deliberately turn it on, because recording a screen is a different thing from counting a page view and we are not going to treat silence as a yes for it.

We do not ask for and do not want financial account details, government identifiers, or any of the special categories of data — health, biometrics, precise geolocation of a person, and so on. Please do not send them to us.

Names we publish from the public record

Chicago requires a licence to serve food, and the city publishes who is named on each one. We republish those names on our address record pages and in our records and forecast tables, beside the business they were filed for and the years its licence ran. On the records page you can search by a name, because the city’s register is searchable that way too. The sources are the City of Chicago’s business licence and business owner registers, both open data. If your name is on one of our pages, this is the section that covers it. You did not give it to us, and unless you have separately opened an account, we hold nothing else about you.

What we do not do with it. We do not sell it, we do not build a profile of you, and we do not link you to any account, advertising identifier or mailing list. None of those pages rates, scores or judges a person. Where a page carries an estimate, it is about the address or the business, never about anybody named on a filing. A role on a licence is a role on a form: it is not our claim that you cooked, managed, invested in or closed a restaurant, and the pages say so where the names appear.

Corrections and removals. Email hello@use2ndsight.com and tell us which page and which name. If we have got something wrong against the city’s record we will correct it, and that is the fastest thing we do. If you want your name taken off a page, ask and we will consider it and reply. We will not pretend that is more than it is: the City of Chicago publishes the same record independently and will go on publishing it whatever we do, so taking a name off our page removes it from our page and from nowhere else.

Why we have it

To run the product and give you what you asked for; to take payment and keep tax records; to send the emails you signed up for; to keep the service secure and debug it when it breaks; and, in aggregated and de-identified form, to improve the model. Where the law requires a lawful basis, ours is performing our contract with you, our legitimate interest in operating and securing the service and in understanding how it is used, your consent for session replay and for non-essential email, and compliance with legal obligations for records we must keep. Usage analytics runs on that legitimate interest rather than on consent, which is why it is on by default, and the opt-out below is how you object to it. The same legitimate interest will cover the search text and the signed-in page record described above, on the same terms and with the same opt-out. A phone number is different: we would have it only because you chose to type it into an enquiry form, and we will not use it for anything you did not ask for.

Who else processes it

We use a small number of vendors to run the product. They process data on our instructions, and none of them is permitted to use it for their own purposes. This is the real list, verified against our own code:

VendorWhat it doesWhat reaches it
Supabase (via Lovable Cloud)Database, authentication, file storage and the server functions that score a readAccount email, saved reads, watches, purchase records
LovableApplication hosting and deploymentStandard web-server request data
StripePayment processing for Site Reports and subscriptionsBilling email, payment details (we never see or store card numbers)
ResendTransactional and digest email — reports, magic links, watch alertsRecipient email address and message content
GoogleOptional sign-in with a Google accountEmail address and name from the Google account you choose to use
MixpanelProduct analytics — which parts of the product get usedPseudonymous usage events, and account email once signed in. On by default, and not loaded at all once you turn analytics off or if your browser sends Global Privacy Control
PostHogSession replay and heatmaps on the public funnel only — the landing page, the read and the paywall. Not on the signed-in dashboardsA recording of what you did on those pages, with everything you type masked out. Not loaded at all unless you switch session replay on yourself, which is off by default and separate from usage analytics
ApifyEnriching business records with public listing data (open/closed status, ratings)None. Queries name Chicago businesses, never our users

Parts of this product use Google Maps Platform services (Places data), and your use of those parts is also subject to Google's Terms of Service and Privacy Policy. Where a figure is derived from Google data we say so and attribute it to Google.

We may also disclose information if the law requires it, or to protect our rights or someone's safety. If we are ever compelled to hand over customer data, we will tell the affected customer unless we are legally barred from doing so.

We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are used in California law.

How long we keep it

Account data and saved reads stay while your account is open, because a saved read losing its history would defeat the point of saving it. Purchase records are kept for seven years for tax and accounting. Error reports and server logs are kept for up to 12 months. Analytics events are kept according to our Mixpanel project's retention setting. Search text will be kept for 90 days and then stripped of its identifiers; the signed-in record of which pages you opened will be kept for 180 days; a business enquiry, including any phone number on it, will be kept for 2 years. Those three are periods for data we do not collect yet, and each is enforced by a job that ships with the collection rather than after it. The record of what you looked up has no expiry, because it is what the market history is built from; it stops being about you the moment you delete your account. When you ask us to delete your account we anonymise rather than delete purchase records — the amount and date survive, your identity does not — because we are required to keep the financial record.

Your rights, and how to use them

Wherever you live, you can ask us for a copy of what we hold, ask us to correct it, ask us to delete it, or ask us to stop sending you non-essential email. If you are in California, that includes your rights under the CCPA as amended by the CPRA — to know, to delete, to correct, and to opt out of sale or sharing, which is moot here because we do neither. We will not discriminate against you for exercising any of them. We honour Global Privacy Control: a browser sending that signal is not counted, and no email to us is needed for it to take effect.

How: email hello@use2ndsight.com from the address on your account and say what you want. We will confirm receipt and complete it within 30 days. There is no charge. You do not have to wait for us, though: your account page does both immediately. Deleting your account removes your profile, reads, watches, entitlements, email settings and API call history outright. It does not delete purchase records or the score audit log — those keep their amount, date and content, and lose your identity, because we are required to retain the first and rely on the second to reconstruct a score you might quote back to us.

Every marketing or digest email we send carries an unsubscribe link. Transactional email — a report you bought, a magic link, a receipt — is part of the service and does not.

Your analytics settings

These take effect in this browser as soon as you change them. Nothing is submitted and there is nothing to save.

Loading your current settings. These live in this browser, so they need JavaScript to read.

Cookies and local storage

We use browser storage for the things the product cannot work without: keeping you signed in, remembering your analytics and replay settings, and holding a read you started before you signed in so it is not lost at the sign-in step. While analytics is on, Mixpanel sets its own identifiers; turning it off stops that. We do not run advertising trackers and there are no third-party ad cookies on this site.

Security, breaches and children

How we protect data is described on our Security page, along with how to report a vulnerability. No system is perfectly secure; if a breach affects your personal information we will notify you and the relevant authorities as required, including under Illinois' breach notification law, without unreasonable delay.

This is a tool for commercial real estate and restaurant businesses. It is not intended for anyone under 18 and we do not knowingly collect data from children. Our servers and vendors are in the United States; if you use the product from elsewhere, your data is processed there.

Changes

If we change this policy materially — a new vendor, a new category of data, a new purpose — we will update the date at the top and email active accounts. The version history matters here, so we will not rewrite the past silently.

Questions about this page? Email hello@use2ndsight.com. We answer within one business day.