Driftmark Privacy Policy
Driftmark is operated by Lacontech, LLC, a Texas limited liability company doing business as Driftmark, located in Austin, Texas. In this policy, "Driftmark," "we," "us," and "our" mean Lacontech, LLC. "You" means the person using the service at www.driftmarkapp.com.
Driftmark monitors companies you choose to follow and sends you intelligence about them, framed for your role. Doing that requires us to hold information about you, and to collect and process information about companies and about the executives who lead them. This policy explains both, in plain language, including the parts that are still rough. Driftmark is in private beta and this policy describes the service as it works today.
If you have a question about anything here, write to privacy@driftmarkapp.com.
1. How you sign in
Driftmark uses Google Sign-In. We request only three things from Google: your OpenID identifier, your email address, and your basic profile (name and profile picture).
We do not request access to your Gmail, Calendar, Drive, Contacts, or any other Google service, and we cannot read them. We do not ask Google for offline access, so Google never issues us a refresh token. The access token Google returns during sign-in is used once, in memory, to read your identity, and is then discarded. We do not store Google tokens anywhere.
From your Google account we save: your Google identifier, your email address, your display name, and your avatar URL.
2. What you tell us
When you set up your account and use the product, you provide:
- Your professional context. Your name, your title, the company you work for, your market, your focus areas, the deal types you care about, your partner criteria, the signals you want prioritized, and any additional context you write.
- Your watchlist. The companies you follow, how you relate to each one (for example prospect, current partner, competitor, acquisition target, strategic vendor, target employer, market watch), plus any description, context, or private notes you attach to a company.
- Your job search intent, if you use that feature. If you tag a company as a target employer, you may also tell us the role you are pursuing. See section 6 for how that is handled, because it is the most sensitive thing in the product.
- What you type. Every question you ask your Driftmark AI Analyst is stored, verbatim, associated with your account. Feedback you give on a briefing or an opportunity is stored with any context you write.
3. What we record as you use the service
- Which items you have seen, pinned, dismissed, or saved, and when.
- Which briefings were included in each email we sent you.
- Days on which your account was active, and timestamps of calls made on your behalf to our data vendors.
- Your reading position in publications you subscribe to.
- Email delivery events from our email provider: whether a message was delivered, opened, bounced, or had a link clicked, including which link, together with the raw event payload the provider sends us.
What we do not record. Driftmark has no field anywhere for your IP address, your browser user agent, or your referring page. We do not store them. We do not run analytics on any page. There is no advertising, no tracking pixel from us, and no third party analytics script in the product. Our landing page loads no external resources at all.
4. Cookies
Driftmark sets exactly one cookie, named session. It holds a signed reference to your user ID, nothing more. It is HttpOnly, it is SameSite Lax, and in production it is Secure. It has no expiry date set, which means it is a browser session cookie and your browser discards it when you close it.
We do not set any other cookie, and we do not use cookies for advertising or cross site tracking.
The signed-in application loads one external library, a charting library, from the jsDelivr content delivery network. Loading it exposes your IP address, browser user agent, and referring page to that network in the ordinary way any web request does. We do not receive that information and we do not set cookies through it.
5. Who we share your information with
We do not sell your personal information. We do not share it for advertising. We share it only with the vendors below, only to run the service.
| Vendor | What it does | What it receives about you |
|---|---|---|
| Sign-in identity provider | Your sign-in, handled by Google under Google's own policy | |
| Anthropic | AI synthesis of intelligence | Your title, employer, market, role context, watchlist companies and how you relate to them, your private notes on a company, and the questions you type into the AI Analyst. Not your name and not your email address. |
| Perplexity | Web research on companies | One company at a time. No information about you. |
| NinjaPear (Nubela) | Company and executive profile data | Company domains only. No information about you. |
| Alpha Vantage | Market and pricing data | Ticker symbols only. No information about you. |
| SEC EDGAR | Public company filings | Company identifiers only. No information about you. |
| X (Twitter) API | Public posts by tracked executives | No information about you. |
| Resend | Sends your email digests | Your email address, your name, and the company names in your digest, which appear in both the body and the subject line. Returns delivery and engagement events to us. |
| Railway | Hosts the application and database | Processes everything, as our infrastructure provider. |
We do not send your name to our AI vendor. Your name is stored in your profile and is used inside the product, for example on the cover of a PDF you export, but it is deliberately not attached to any request we make to Anthropic. This is enforced by an automated test that fails our build if anyone re-introduces it.
There is one honest limit on that. Anything you type in free text goes to Anthropic exactly as you wrote it, because that is the point of writing it: your notes on a company, your description of a company, your focus areas, your additional context, and every question you ask the AI Analyst. If you type a person's name into any of those, including your own, it is sent. We cannot strip it without breaking the feature.
Separately, executive names are sent on purpose. Monitoring what executives say and do publicly is the core of what Driftmark does. See section 7.
Driftmark also fetches publicly available web pages, news feeds, and newsrooms in order to monitor the companies you follow. The set of sites we fetch is not fixed, because it follows the companies and publications users choose. If you paste a URL into the product, we will fetch it.
We may disclose information if we are legally required to, or to protect the rights, safety, or property of Driftmark or others.
6. The target employer feature, stated plainly
If you tag a company as a target employer and tell us the role you are pursuing, then when we generate intelligence about that company we send Anthropic, in a single request: your current title, the role you are pursuing, your focus areas, the name of the company, and an explicit statement that the user is a job candidate at that company.
We do not send your name, and we do not send your current employer on this path. Leaving out your employer is deliberate: it stops the analysis being framed around your current company's commercial interests when what you actually need is hiring and organizational signal.
Two things you should still know before you use it. First, the fact that someone is job searching at that company is stated in the request, even though you are not named in it. Second, it runs automatically on our nightly cycle, without any action from you, for as long as the company carries that tag.
Anthropic processes this to generate your intelligence. Under our arrangement with Anthropic, this content is not used to train their models. It is not sent to your employer, to the target company, or to anyone else. If you would rather not have this in the system, change the relationship tag or remove the company, and tell us at privacy@driftmarkapp.com if you want the associated profile field cleared.
One caution that is yours to control: if you type your own name, or your employer's name, into a free text field such as your additional context or your notes on that company, it is sent with everything else. See the end of section 5.
7. Information about other people
This is the part of Driftmark that most needs explaining, because the product is about companies and companies are run by people.
What we hold. For executives at companies our users follow, Driftmark may hold: name, title, role, LinkedIn URL, X handle and public posting activity, personal website, profile picture, biography, country, state, city, work history (prior employers, roles, and tenure), education, and an AI generated research summary about that person. We also hold a roster of notable executives for each company we track, which is refreshed periodically whether or not any user follows those individuals.
We do not hold email addresses or phone numbers for these individuals.
Where it comes from. Biography, profile picture, city, work history, education, personal website, and X profile come from NinjaPear (Nubela). Company executive rosters come from the same vendor. Public posts come from the X API. The AI research summary is generated by Perplexity. Name, title, and LinkedIn URL may also be entered by a user.
How it is used. It is used to attribute public statements and public activity to the right person, and to include that in intelligence for users who follow that person's company. It is not used for advertising, it is not sold, and it is not compiled into any product sold to third parties.
Correction and deletion. If you are one of these individuals and you want your information corrected or removed, write to privacy@driftmarkapp.com and we will handle it manually. We will honor the request. You should know two honest limitations about what that means today:
- Removing a person from our records stops future intelligence being attributed to them, but their name may still appear inside previously generated narrative text, stored transcripts, and archived briefings, because that text is prose and not a database field. We will remove such material on request where we can identify it, but we cannot guarantee we will find every occurrence.
- Our executive rosters refresh on a recurring cycle from our vendor. Unless we also record a suppression, a person removed from our system can reappear in a suggested roster. If you ask us to remove your information, tell us you want it suppressed permanently and we will record that, not just delete the row.
We are working to make both of these better. In the meantime we would rather tell you exactly how it works than imply a cleaner process than we have.
8. How long we keep things
Detailed source intelligence is deleted automatically after 90 days on a weekly cycle.
Most other information is kept for as long as your account exists. Briefings that were synthesized from source intelligence are kept even after that source material ages out, because the briefing is the product. Your watchlist, your profile, your chat history, and your activity records are kept until you ask us to delete them or you close your account.
Our hosting provider retains application logs for a short period. Those logs can contain email addresses, because that is how we diagnose a failed email send, and they can contain executive names and search terms. They are transient and are not part of our database. We are progressively removing personal information from what we write to logs.
Our hosting provider also takes database backups. Deleted information may persist in a backup until that backup rotates out.
9. Your choices and your rights
Access. Write to privacy@driftmarkapp.com and we will tell you what we hold about you.
Correction. You can edit your profile and your company notes in the product at any time. For anything else, write to us.
Deletion. Write to privacy@driftmarkapp.com and we will delete your account and the information associated with it. This is currently handled manually by us rather than through a button in the product. We will confirm when it is done. As with section 7, your name may persist in a backup until it rotates, and we will tell you if anything cannot be removed.
Email. You can change your digest preference in the product, or reply to any digest and ask us to stop.
Depending on where you live, you may have specific rights under laws such as the California Consumer Privacy Act or the Texas Data Privacy and Security Act, including rights to know, delete, correct, and to not be discriminated against for exercising them. We honor these requests from everyone, regardless of where you live. We do not sell personal information and we do not share it for cross context behavioral advertising, so there is nothing for you to opt out of on that front.
10. Security
Access to the service requires Google Sign-In and an entry on our invite list. Session cookies are signed, HttpOnly, and secure in production. Traffic is encrypted in transit. Vendor credentials are held as environment variables and are not in our source code.
Driftmark is a small operation in private beta. We do not claim to have the security program of a large company, and we will not pretend otherwise. If you find a problem, please tell us at privacy@driftmarkapp.com and we will take it seriously.
11. Children
Driftmark is a business tool and is not directed to anyone under 18. We do not knowingly collect information from children. If you believe a child has provided us information, write to us and we will delete it.
12. Where your information is processed
Driftmark is operated from the United States and information is processed in the United States by us and by our vendors. If you use the service from elsewhere, you are sending your information to the United States.
13. Changes
If we change this policy we will update the effective date at the top, and if the change is material we will tell active users by email. Continuing to use Driftmark after a change means you accept the updated policy.
14. Contact
Lacontech, LLC (doing business as Driftmark)
Austin, Texas, United States
privacy@driftmarkapp.com