Beta Service Notice
Sentimentary is operating as an open beta while Sentimentary Corporation is being incorporated. During this period the service is operated by Laurel Pines Limited Company, doing business as THEBIZFIXER (“THEBIZFIXER,” “Laurel Pines LC,” “we,” “us,” or “our”). Features may change substantially during beta. Your account, research configurations, and extracted data may be reset or deleted at the end of the beta period, and will otherwise transfer to Sentimentary Corporation under §10A below.
1. Introduction
This Privacy Policy explains how THEBIZFIXER collects, uses, stores, and shares information in connection with the Sentimentary beta research platform (the “Service”). The Service extracts quotes from public web sources, scores them for sentiment, and delivers sourced, traceable results to registered subscribers.
- Effective date: July 19, 2026
- Last updated: July 19, 2026
- Operator: Laurel Pines Limited Company, a Utah limited liability company doing business as THEBIZFIXER
- Governing law:State of Utah (the Service’s principal place of business). Governing law is independent of Sentimentary Corporation’s future charter state, which will be set at incorporation.
By creating an account, submitting a waitlist email, or using the Service in any way, you agree to the terms of this Privacy Policy and our Terms of Service.
2. Information We Collect
- Account data. Email, username, password (stored only as a salted hash), optional photo URL, and settings such as timezone and datetime format.
- Waitlist data. Email address only, collected pre-registration to notify you when the Service opens to your segment.
- Research data. Project names and snapshot configurations — the research questions, keywords, target URLs, channel selections, and population targets you direct us to run on your behalf.
- Extracted data. Quotes from public web sources, source URLs, channel metadata, and computed sentiment scores or polarities. This is publicly available information; authors of extracted content are anonymized at ingestion under our connected-channels policy.
- Usage data.Last-active timestamps, JWT tokens held in your browser’s
localStorage, andsessionStorageentries used to preserve UI state across navigations. - Admin audit. For our own administrators only: actions taken in administrative panels and the IP addresses those actions came from.
- Billing data. Not applicable during beta. All access is free; we do not process payments or store card information.
3. How We Use Your Information
We use the information above to (a) deliver the Service and your research results; (b) create and secure your account; (c) score and analyze publicly extracted content you direct us to; (d) prevent abuse, fraud, and unauthorized access; (e) improve the Service; and (f) comply with our legal obligations.
4. Third-Party Services and Data Sharing
Data controller and sub-processors
During the beta, Laurel Pines Limited Company is the sole data controller. The vendors listed below act as sub-processors on our behalf. The current list is published at /subprocessors and is versioned independently of this Privacy Policy so we can add or remove a vendor without republishing the whole document.
Beta sub-processors
| Vendor | Purpose |
|---|---|
| TinyFish | Web-agent extraction of public content |
| MongoDB Atlas | Primary data store |
| Google Cloud Platform (GCP) | Backend hosting, Secret Manager, logging |
| Vercel | Frontend hosting and edge delivery |
| AgentMail | Transactional email, notifications, and administrative communications during beta |
Additional sub-processors (Stripe, Alguna, Composio, Fireworks AI, MixedBread, ElevenLabs, and Laurel Pines LC as an R&D sub-processor) are expected at the Sentimentary Corporation launch and will be listed at /subprocessors at that time. AgentOps (audit trails and circuit breakers for agent workflows) is planned for post-launch and will be added to that list when deployed.
What we do not share
Our sentiment scoring engine, lexicons, thresholds, and scoring pipeline are proprietary to Laurel Pines Limited Company and are not shared with any sub-processor. We do not sell personal information.
5. Cookies and Storage Technologies
localStorage— holds your JWT access and refresh tokens so you stay logged in.sessionStorage— holds transient UI state for the current tab.- We do not deploy third-party analytics or advertising cookies during the beta. A privacy-first analytics tool (PostHog or equivalent) may be added at launch and will be reflected in an update to this policy and the sub-processors list.
- Global Privacy Control (GPC). We honor GPC signals as opt-out-of-sale and opt-out-of-targeted-advertising signals under the California Consumer Privacy Act (CCPA) and the Utah Consumer Privacy Act (UCPA), even though we do not currently sell personal information.
6. Data Retention
- Account data is retained while your account is active.
- Research configurations and extracted data are retained for the lifecycle of the associated project and snapshot, plus a short export window after deletion.
- Waitlist emails are retained until you register or request deletion.
- Admin audit logs are retained for the period required by our internal compliance and incident-response policies.
- Beta-specific note.Your data may be reset or deleted at the end of the beta period. We will give you at least 30 days’ advance notice and an export window before any reset; see §10A.
7. Your Rights
All users
You have the right to access, correct, port, and delete the account data and research configurations you have submitted, and to terminate your account at any time.
§7.A California residents (CCPA)
You have the right to know what personal information we have collected, to delete it, to correct it, to opt out of sale or sharing, and to exercise these rights without discrimination. Because we do not sell personal information, no opt-out-of-sale workflow is required beyond honoring Global Privacy Control (see §5).
§7.B US State Privacy Rights (omnibus)
If you are a resident of Utah (UCPA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), or another US state whose omnibus consumer privacy law is in effect at the time of your request, you have the right to: know what personal data we process, delete it, correct it, obtain a portable copy, opt out of targeted advertising and sale, and opt out of profiling for decisions that produce legal or similarly significant effects (where applicable). Sensitive-data processing requires your consent under UCPA, VCDPA, CPA, and CTDPA.
To exercise any US state right, contact us at the address in §11.
§7.C GDPR / UK GDPR / Swiss FADP (European Economic Area, UK, Switzerland)
You have the right to: access, rectify, erase, restrict, and object to processing; withdraw consent; receive a portable copy of your data; and lodge a complaint with your supervisory authority. Our lawful basis for processing account, research, and extracted data is Article 6(1)(b) GDPR (performance of our contract with you) or, where you ask us to extract content that includes personal data about third parties, Article 6(1)(f) (legitimate interest in operating a research platform that preserves author anonymization at ingestion).
Children aged 13–15. Where a GDPR member state has set the digital-consent age above 13 (up to 16 under Article 8 GDPR), we require verifiable parental or guardian consent before account creation. The consent record is stored with the account and is available to the parent on request.
§7.D COPPA (children under 13)
We do not knowingly collect personal information from children under 13. If we learn that a child under 13 has created an account, we will delete the account and any associated data and notify the parent or guardian where contact information is available.
8. Data Security
We protect your data with:
- Password hashing with industry-standard salt + KDF, never storing plaintext passwords.
- JWT access tokens (HS256) with revocation tracked in Redis / Google Cloud Memorystore.
- TLS 1.2 or higher for all API and browser traffic.
- Secrets stored in GCP Secret Manager; no secrets in source control.
- Encryption at rest on MongoDB Atlas; VPC and Private Service Connect between Cloud Run and Atlas.
Incident and breach notification
If we become aware of a personal-data breach, we will notify the relevant supervisory authority within 72 hours (GDPR Article 33), and notify affected individuals without unreasonable delay where required (CCPA §1798.82; UCPA §13-61-302; comparable state and national laws). We will describe the nature of the breach, the categories and approximate number of individuals affected, the likely consequences, and the remediation steps we are taking.
9. International Data Transfers
The Service is hosted in the United States. For transfers of personal data from the European Economic Area, the United Kingdom, or Switzerland to the United States, we rely on the European Commission’s Standard Contractual Clauses (SCCs) Module Two (controller-to-processor) and supplementary organizational and technical measures described in this policy. A Data Processing Addendum incorporating the SCCs is available from Sentimentary Corporation at the Launch.
10. Changes to This Policy
We may update this Privacy Policy to reflect changes in our Service, our sub-processor list, or applicable law. Material changes will be communicated by email or in-app notice. The “Last updated” date at the top of this document will always reflect the most recent change. This beta policy will be superseded by Sentimentary Corporation’s Privacy Policy at launch; see §10A.
10A. Transition from Beta to Launch
When the Service transitions from the THEBIZFIXER beta to Sentimentary Corporation (post-incorporation), the service operator will change. We will notify you at least 30 days in advance of the transition by email and in-app notice. Your account, project configurations, and extracted data will be transferred to Sentimentary Corporation as part of the transition.
- Lawful basis for EEA / UK / Swiss users. The transfer is made under Article 6(1)(b) GDPR (performance of contract), re-established with Sentimentary Corporation on your first login after the transition. Accepting the Sentimentary Corporation Privacy Policy on that first login completes the re-establishment.
- Decline window. During the 30-day notice window you may decline the transition and export or delete your data through the in-app data tools or by contacting us at the address in §11. Data you export or delete will not be transferred.
- Continuity of this policy. Until the transition date, this Privacy Policy continues to govern. After the transition date, the Sentimentary Corporation Privacy Policy governs your use of the Service.
11. Special AI and Sentiment Disclosures
- Automated scoring, not user profiling. Our scoring engine (lexicon-based today, with optional machine-learning models in the future) assigns sentiment polarity to publicly extracted text. It does not profile individual subscribers.
- Proprietary engine. The scoring engine, lexicons, and algorithms are proprietary to Laurel Pines Limited Company and are not shared with any sub-processor.
- No biometric or emotion recognition. We do not process biometric data, voice or facial features, or emotion-recognition signals derived from subscribers.
- EU AI Act Article 50 transparency. In compliance with Regulation (EU) 2024/1689, we disclose that sentiment polarity scores are produced by an automated scoring system, not human judgment. You should not rely on these scores as definitive characterizations of the underlying content or its authors.
12. Contact Us
For privacy questions, requests to exercise your rights, sub-processor questions, or any other concern related to this policy, contact us at:
- Email: [email protected]. You may also use [email protected] during the beta-to-launch transition window described in §10A.
- Postal mail: Laurel Pines Limited Company, DBA THEBIZFIXER — [street address to be inserted before public beta launch], Utah, United States