Privacy Policy
Last revised on August 25, 2026.
The gist
Rated 11 is a reference for agents and a small catalog of curated gifts. The conversation you have with your agent is not ours. We do not receive it and we do not keep it. If you buy a credit pack or open the catalog, we keep only what we need to bill and enforce a credit. Card numbers go to Stripe, not to us.
Reuse
This document is an adaptation of the open SaaS / web application privacy policy template published under the MIT License. The original work has been modified for Rated 11. PolicyForge and the template authors are not connected with or sponsors of Rated 11.
Who we are
Rated 11 ("we," "us") is the operator of the website at https://rated11.com, the agent brief, the API, and the curated shop and gift lists (the "Service"). This Privacy Policy explains what we collect when you use the Service, including when your agent calls the API for you.
Your host agent (ChatGPT, Claude, Grok, Copilot, Gemini, or another) is a separate service. What that agent stores, forgets, or shares with its own provider is between you and the agent. We do not control it and we make no promise about it.
Information we collect
We do not ask for a name, email, or password. There is no Rated 11 login. An account is an id and a bearer token minted when you (or your agent) call the accounts API. We store a hash of the token, not the token itself.
If you use the catalog, we store:
- Account id and token hash.
- Occasion keys used to enforce a credit: a normalized recipient, occasion type, and date.
- Ledger entries for purchases, the first free occasion, and spends (including a Stripe event id when a pack is granted).
- The search query sent with a first-pass call, used to filter shops and the corpus for that request.
We do not receive the interview you do with your agent: dates you mention in chat, taste notes, constraints, or the day plan. Those stay with the agent, or nowhere, only if the agent treats them that way. That is not a promise from us.
When you pay, Stripe processes the charge. We receive payment status and an event id so we can grant credits. We do not store full card numbers.
The website and API run on hosting providers. They may log technical data such as IP address, user agent, and request path, as any host does.
How we use it
- Provide the Service: mint an account, open an occasion, return a first-pass from the catalog.
- Process a $5 credit pack and grant credits after Stripe confirms payment.
- Enforce the first free occasion, daily caps, and that one credit covers one occasion key.
- Detect abuse of the API.
- Comply with law if we are required to.
We do not use this information for marketing. We do not send promotional email. We do not have an email list.
Where it is stored
The site is hosted on Vercel. Account, token hash, occasion, and ledger records are stored in Supabase. Payments are processed by Stripe. Those providers may store data in the United States.
We use TLS for the site and API. The bearer token is the secret. Anyone who has it can use the credits. We cannot reset it for you if it is lost.
Who we share with
We do not sell personal information. We share only as needed to run the Service:
- Stripe, for payment and checkout (including the terms and privacy links shown on Checkout).
- Vercel, to host the site and API.
- Supabase, to store account, token hash, occasion, and ledger records.
- When required by law, or as part of a sale or reorganization of the Service.
Each of those services has its own privacy policy.
How long we keep it
Credits do not expire. We keep the account, token hash, occasion keys, and ledger for as long as the account exists, so a credit can still be redeemed. Payment records Stripe keeps are subject to Stripe's retention and to tax and accounting rules.
We do not currently offer a self-serve delete button. If you want an account removed, contact the operator of Rated 11 through any contact method published on rated11.com.
Your rights
Depending on where you live, you may have the right to ask what we hold, to correct it, to delete it, or to export it. California residents may also ask us to confirm that we do not sell or share personal information for cross-context advertising (we do not). We do not discriminate for exercising a privacy right.
To make a request, contact the operator of Rated 11 through any contact method published on rated11.com. We may need enough information to find the account (for example the token or a Stripe receipt).
Cookies
The Rated 11 site itself does not use advertising cookies. Stripe Checkout and our hosts may set their own cookies to run payment and keep the site working. You can control cookies in your browser.
Children
The Service is not for children. You must be at least 18 to buy a credit pack. We do not knowingly collect personal information from anyone under 18.
Changes
We may change this Privacy Policy. The date at the top will change when we do. Continued use of the Service after a change is acceptance of the updated policy. We do not have emails on file, so we will not email you a notice.
Contact
Rated 11 is operated from Issaquah, Washington, United States. Privacy questions: use any contact method published on rated11.com. This policy is governed with the Terms of Service.