Trust & Security

Trust & Security

Pickrate is operated by PurelySearch LLC (Delaware, United States). This page is the plain account of what data we hold, who processes it, and how we protect it. Last updated June 25, 2026.

The short version

What we collect

Security practices

Sub-processors

We use the third-party providers below to operate Pickrate. We will update this list and aim to notify account holders before a new sub-processor that handles customer data takes effect.

Sub-processorPurposeDataLocation
SupabasePrimary database and authenticationAccount, authentication, and application dataUnited States
RailwayApplication hostingAll application traffic in transitUnited States
StripePayment processing and billingBilling details (Stripe stores card data; Pickrate does not)United States
ResendTransactional email deliveryEmail address and message contentUnited States
InngestBackground job and workflow processingApplication data in transit during processingUnited States
AnthropicAI model provider (eval engine)Eval prompts, including Custom Eval inputsUnited States
OpenAIAI model provider (eval engine)Eval prompts, including Custom Eval inputsUnited States
Google (Gemini API)AI model provider (eval engine)Eval prompts, including Custom Eval inputsUnited States
Google AnalyticsWebsite usage analyticsUsage and device data (no account credentials)United States
CloudflareDNSNone (DNS resolution only)United States

On the AI providers: data sent to Anthropic, OpenAI, and Google through their APIs is not used to train their models, per each provider's API terms.

Compliance

Reporting a vulnerability

Found a security issue? Email security@pickrate.io with the details and steps to reproduce. We'll acknowledge it and work with you in good faith. Please don't publicly disclose until we've had a chance to fix it.

Legal

See our Privacy Policy, Terms of Service, and Data Processing Agreement.

Questions about how we handle data?

Email us — we answer.

privacy@pickrate.io