PRIVACY POLICY
Privacy at Worthi
Effective August 24, 2026. Last updated August 24, 2026. This policy reflects the current Phase 1 launch behavior.
Scope and privacy principles
This Privacy Policy explains how Worthi handles personal information in the current consumer purchase-intelligence service. Worthi is designed around data minimization, user control, purpose limitation, and recommendation independence. Worthi does not sell personal data or use personal data for targeted advertising at launch, and affiliate compensation does not change Worthi Score, ranking, verdict, Evidence Confidence, Reliability Intelligence, seller trust, or SYM fit.
Worthi is intended for adults and is not directed to children. You must be at least 18 years old to create an account or use account-based Worthi services. Worthi does not knowingly seek to collect personal data from children for the launch service.
Information Worthi handles
Depending on what you use, Worthi may handle account and authentication data; recommendation requests and answers; purchase-fit context you provide such as budget, country, or postal code; SYM preference signals; Watch/Pulse state and verified price/timing observations; KIN purchase outcomes or feedback; notification preferences; limited quote/concierge information when that functionality is used; privacy-minimized launch analytics; eligible retailer or affiliate click attribution; and support reports you choose to submit.
Product catalogs, merchant records, public price observations, and evidence about products are shared reference data rather than data owned by an individual Worthi account.
Support and security signals
A Help report contains the support category, the description you type, optional product or surface context, a timestamp, and your account identity only when you are already signed in. Worthi does not automatically attach raw SYM, KIN, Watch, Pulse, browsing-history, recommendation-evidence, or sensitive-profile payloads to a support report. The Help form asks you not to submit passwords, payment-card details, government IDs, medical information, or other unnecessary sensitive information.
For anonymous Help intake and guest abuse prevention, Worthi may use short-lived pseudonymous network-source signals solely for security, fraud prevention, abuse control, and service availability. Raw network addresses are not intentionally persisted in the support report. These signals are not used for advertising, recommendation ranking, Worthi Score, SYM, KIN, Watch, Pulse, or cross-session behavioral profiling.
Launch analytics
Worthi uses privacy-minimized launch telemetry to understand whether the service is working and where consumers encounter friction. Worthi uses a random session-scoped identifier and may keep only registered coarse Worthi campaign/source labels or an external referring hostname. Launch telemetry does not retain the raw purchase query, full referrer URL, arbitrary UTM campaign/source values, raw SYM or profile payloads, or raw recommendation-evidence payloads.
Unowned guest launch-funnel events are limited to the current session for identity and are opportunistically removed after 30 days. User-linked analytics are included in the verified account-deletion purge described below.
How Worthi uses information
Worthi uses launch-scope data to provide and secure recommendations, explain evidence, support user-requested personalization, operate Watch and Pulse, preserve user-directed SYM controls, process account functions, investigate support reports, improve reliability, and record eligible commerce actions for attribution without allowing compensation to affect the recommendation.
Support reports are operational records and are not inputs to Worthi Score, recommendation ranking, verdict, SYM learning, Watch, Pulse, or KIN personalization.
SYM, Watch/Pulse, KIN, and Nerve Net
Behavioral SYM learning is off by default. If you explicitly turn it on, newly learned behavior- or outcome-derived signals may be used for future personalization. Turning it off deactivates those learned signals. Previously revoked learned signals are not silently reactivated.
Watch/Pulse at launch monitors verified price and timing information. Worthi does not promise availability, warranty, policy, or better-option monitoring unless a future evidence pipeline is actually implemented and disclosed. Shared Nerve Net contribution is disabled for the Phase 1 launch.
Your controls
Authenticated users can inspect stored SYM signals, turn behavioral learning on or off, ask SYM to forget an active signal, and permanently delete their Worthi account through the Privacy controls surface.
Account deletion requires explicit confirmation and targets only the authenticated account. Worthi first purges user-linked support reports, recommendation, usage, and affiliate- attribution payloads that would otherwise survive owner deletion, then removes account-owned launch data through the verified database deletion path. Shared product/catalog/evidence reference data remains.
Worthi does not intentionally retain deleted-user recommendation text, location/context snapshots, affiliate session metadata, SYM/KIN/Watch/Pulse state, signed-in support reports, or equivalent consumer payloads for personalization, advertising, affiliate attribution, model training, or growth measurement after account deletion. Narrow security, fraud, legal, or operational records may be retained only where legitimately required and may not be used as an active personalization source.
Service providers
Worthi currently uses the following launch-relevant service-provider categories and services: Render to host the web, API, and worker services; Supabase for authentication, database, row- level security, support intake, and account-owned application data; Upstash Redis for the recommendation work queue and short-lived guest rate limiting; Serper when configured for product/evidence research queries; and Supabase Auth email delivery for sign-in links.
Worthi limits provider payloads by purpose. For example, the current Serper adapter sends normalized product-research terms and locale rather than Worthi account IDs, email addresses, postal codes, support text, SYM/KIN/Watch/Pulse payloads, guest capability tokens, or raw launch-funnel identifiers. The Redis recommendation queue carries recommendation identifiers and, for authenticated work, the associated user identifier rather than raw request text or profile payloads.
A configurable checkout-verification provider exists in the architecture but is inactive at launch unless checkout verification is separately and explicitly requested, a specific provider is configured and reviewed, and the associated disclosure and data-use conditions are accepted. Provider configuration alone does not authorize transmission of postal-code or checkout-verification data.
Retailers, affiliates, and third-party destinations
When you choose a retailer or manufacturer purchase action, you leave Worthi for that third party, and that destination applies its own privacy practices. Worthi may record an eligible outbound commerce action for attribution. Marketplace seller identity and retailer trust remain separate from compensation.
Future affiliate or licensed-data integrations may add partner-specific tracking or content rules. Worthi will not activate a material new personal-data use merely because an affiliate program becomes available. If a future integration materially changes the categories of personal data processed or the purposes for which they are used, this Policy and the product controls must be updated before that change is treated as active.
Cookies and similar technologies
Worthi may use essential session, authentication, security, and measurement technologies needed to operate the service. At launch, Worthi does not use personal data for targeted advertising. Retailer and affiliate destinations may use their own cookies or tracking after you leave Worthi, subject to their own policies.
Data sharing
Worthi shares personal data only as reasonably necessary to operate the service, provide a user-requested feature, protect users and the service, comply with law, or work with service providers under the applicable purpose. Worthi does not sell personal data at launch.
Worthi does not provide raw SYM/profile data, support reports, or unnecessary user-level information to retailers merely because a retailer participates in an affiliate program.
Security and Florida data-protection requirements
Worthi uses authenticated ownership checks, database row-level security, purpose-limited provider payloads, and other administrative and technical controls appropriate to the launch service. Privacy, Watch/Pulse, SYM, KIN, support, and related user-owned records are designed so another consumer cannot inspect or mutate them. No security system is perfect, and Worthi does not promise absolute security.
Worthi will maintain reasonable measures to protect electronic personal information and will address legally reportable security incidents in accordance with applicable law, including Florida's requirements for covered entities when those requirements apply.
Retention
Launch-scope account data is retained while needed to provide the features you use and is subject to the user-control and account-deletion behavior described above. Phase 1 support reports carry an operational maximum retention of 90 days and are removed sooner when a signed-in user deletes the associated account. Anonymous reports are not retroactively linked to a later account and expire under the same maximum-retention rule.
Short-lived abuse and rate-limit signals expire on substantially shorter operational windows. Queue data is operational and transient. Provider-side logs, backups, and contractual retention may follow the applicable provider's service terms and operational controls, but Worthi does not treat provider-side operational retention as authority to reuse deleted-user data for personalization or advertising.
Florida and other U.S. privacy rights
Privacy laws vary by jurisdiction and often apply only when statutory thresholds or business characteristics are met. Worthi does not represent that every statutory privacy regime applies to the launch service merely because a user resides in that jurisdiction. Where an applicable law gives you additional rights, Worthi will honor those rights as required by law.
Florida's Digital Bill of Rights uses a narrow statutory definition of covered controller. Worthi's launch policy therefore does not promise that statute-specific access, correction, portability, appeal, or opt-out procedures apply unless Worthi actually falls within the statute or another applicable law requires them. This does not reduce the account inspection, SYM control, or deletion functionality Worthi voluntarily provides today.
To exercise the controls Worthi currently provides, use the Privacy controls. For another privacy request or a question about whether a legal right applies, use Worthi Help. Worthi will not require you to create a new account solely to submit a legally required request when applicable law prohibits doing so.
International and provider processing
Worthi's current application infrastructure is configured in U.S. regions where identified in the launch processor inventory, but service providers may use subprocessors or operational systems in other jurisdictions under their applicable terms. Worthi will not describe a specific cross-border legal mechanism or provider transfer commitment unless that mechanism has actually been established for the applicable provider relationship.
Policy changes and effective date
This Policy is effective August 24, 2026. Material changes will be versioned and, where required or reasonably appropriate, accompanied by additional notice. Worthi will not materially expand the categories of personal data collected or use existing personal data for a materially new purpose without updating this Policy and implementing any notice or consent required by law.
Contact
Use Worthi Help for privacy questions and requests and the Privacy controls for account and SYM actions. Worthi will use these available channels to receive privacy requests unless applicable law requires another method.