Privacy Policy
Introduction
This Privacy Policy explains how the Assurcast platform (the "Platform"), including the website at assurcast.com (the "Site"), the Assurcast API, and the Assurcast Chrome Extension (the "Extension"), operated by CPE.io LLC, a Georgia limited liability company, doing business as Audit Risk Media, collects, uses, and protects your information. By using the Platform, you agree to this policy.
1. Data Collection and Processing
1.1 Data We Collect
Assurcast is a broadcast-style news feed and jobs board for internal audit and assurance professionals. We collect different types of data depending on how you interact with the Platform:
Account Information (Registered Users)
- Registration data: Name, email address, and password (stored as a bcrypt hash; we never store your plaintext password)
- Profile preferences: Theme preference (dark/light mode), notification settings (submission status updates, digest enrollment)
- Role assignment: Your account role (contributor, editor, or admin) which determines your permissions on the Platform
Content Submissions
- Story submissions: Title, summary, body text, source URL, category, and region
- Job submissions: Job title, company name, summary, description, location details, salary information, employment type, work mode, seniority level, industry, and application URL
Subscriber Information
- Email subscriptions: Email address, name (optional), category and region preferences, job alert preferences (industry, work mode, seniority, country), and digest frequency (immediate, daily, or weekly)
Analytics and Tracking Data
- Page views: Pages visited, timestamps, hashed IP address, hashed session ID, user agent, referer, and platform identifier (web, Chrome Extension, or API)
- Content clicks: Which stories and jobs you click on, the source (web, Extension, email, or API), and platform
- Feed requests: RSS, Atom, and JSON Feed access with hashed IP address, user agent, feed type, and platform identifier. Feed access is monitored to enforce our Terms of Service, including prohibitions on rebroadcasting and automated harvesting.
- Email engagement: Whether broadcast and digest emails are opened (via a 1x1 transparent tracking pixel)
- Ad impressions and clicks: Interactions with sponsored content and ad units, including campaign attribution
API Keys
- Personal API keys: If you generate API keys for programmatic access, we store a bcrypt hash of the key, a key prefix for identification, assigned scopes, and usage timestamps. The full key is shown once at creation and cannot be retrieved afterward.
Chrome Extension Data
- Stored locally in your browser: Personal notes attached to stories, tracked job applications (status, priority, tags, checklists, dates), and notification preferences. This data is stored in your browser's IndexedDB and is never transmitted to our servers.
- Optional cross-device sync: If you enable sync, tracked job data is stored in Chrome's sync storage for access across your devices. This data is managed by Google and subject to Google's privacy policies.
- API key: If you enter a personal API key in the Extension settings, it is stored in your browser's local storage and used to authenticate API requests.
1.2 How We Use Your Data
- To deliver curated news stories, job listings, and sponsored content relevant to internal audit and assurance professionals
- To personalize content delivery based on your category, region, and subscription preferences so that the stories, jobs, and emails you receive are professionally relevant to you
- To send email broadcasts and digests based on your subscription preferences
- To process and review content submissions from contributors, which may include AI-assisted editorial review
- To provide analytics and reporting on platform usage, content performance, and audience engagement
- To measure advertising campaign effectiveness using aggregate metrics (impressions, clicks, and click-through rates) — we do not share individual user data with advertisers or sponsors
- To detect and prevent abuse, including API rate limiting, bot detection, and spam prevention
- To improve the Platform's features, content curation, and user experience
1.3 Privacy-Preserving Measures
Assurcast is designed with privacy in mind. We apply the following measures to minimize the personal data we retain:
- IP address hashing: All IP addresses are hashed using SHA-256 with a server-side salt before storage. We do not store raw IP addresses in our analytics tables.
- Session ID hashing: Session identifiers used for analytics are hashed before storage.
- No third-party trackers: We do not use Google Analytics, Facebook Pixel, or any third-party tracking scripts.
- Minimal cookies: We use only a session cookie for authentication and an optional theme preference cookie. No advertising or tracking cookies are set.
1.4 Advertising, Sponsored Content, and Data Sharing
Assurcast features sponsored stories and job listing boosts from advertisers and sponsors. We want to be clear about how your data relates to advertising on the Platform:
- We do not sell your personal data. We never sell, rent, lease, or trade your personal information to any third party, including advertisers, sponsors, or data brokers.
- We do not share individual user data with advertisers. Sponsors and advertisers never receive your name, email, browsing history, or any other personally identifying information.
- Sponsors receive only aggregate metrics. Campaign reporting provided to sponsors includes only aggregate, anonymized data such as total impressions, total clicks, and click-through rates. These metrics cannot identify individual users.
- No third-party ad networks. We do not use third-party advertising networks (such as Google Ads or programmatic ad exchanges). All sponsored content is served directly from our own servers with no external ad tracking scripts.
- Content targeting is preference-based, not behavioral. Sponsored content placement is determined by category and region alignment — not by individual user profiling, browsing history, or behavioral tracking. If you subscribe to the "Tools" category in the "North America" region, you may see sponsored content relevant to that category and region.
We may use aggregate, anonymized analytics data internally to improve content curation, inform editorial decisions, and deliver more relevant professional content to our audience. This data cannot identify individual users.
1.5 AI-Assisted Tools
The Platform provides AI-assisted tools that may be used in the following ways:
- Content creation: Users may use AI-assisted tools (via the API, MCP server, or built-in Platform features) to help draft story submissions, job listings, and campaigns. When you use these tools, your input and the resulting AI-generated content are processed through the Platform's API infrastructure.
- Editorial review: Submissions to the Platform may be reviewed using AI-assisted tools to evaluate quality, relevance, accuracy, and compliance with editorial standards. AI-assisted review may be used in addition to or in lieu of manual editorial review.
- Third-party AI assistants: If you connect a third-party AI assistant (such as Claude Desktop or other AI tools) to the Platform via the MCP server or API using your personal API key, that AI assistant may access Platform data within the scope of your API key permissions. You are responsible for the data handling practices of any third-party AI tools you choose to connect.
We do not send your personal data to third-party AI services. AI-assisted editorial review and content processing are initiated through the Platform's API by authorized administrators or users. We do not transmit your account information, subscription data, or analytics data to external AI providers. Any AI processing that occurs is initiated by the user or administrator interacting with the Platform through its standard API interfaces.
2. Data Storage and Security
2.1 Server-Side Architecture
Assurcast uses a server-side architecture with the following characteristics:
- Account data, content, subscriptions, and analytics are stored in a MySQL database hosted on our server infrastructure
- Passwords are hashed using bcrypt and never stored in plaintext
- API keys are hashed using bcrypt; only the key prefix is stored in readable form
- All connections to the Platform are encrypted via HTTPS
- The Platform is hosted on a Pair Networks business-class dedicated managed server in the United States with no other tenants
2.2 Chrome Extension Data
The Assurcast Chrome Extension stores personal data (notes, tracked jobs, preferences) locally in your browser using IndexedDB. This data is not transmitted to our servers. If you enable cross-device sync, Chrome's built-in sync storage is used, which is managed by Google.
2.3 Third-Party Services
We use the following services to provide our functionality:
- Pair Networks: Web hosting, database infrastructure, and SMTP email delivery (United States)
- Google Chrome: The Chrome Extension uses browser-local storage (IndexedDB) and optionally Chrome sync storage for cross-device data
3. Data Processing and Subprocessors
Web Platform
When you visit the Site, create an account, subscribe to emails, or submit content, your data is processed and stored on our servers hosted by Pair Networks. All data transfers between your browser and our servers occur over HTTPS.
Email Delivery
Broadcast emails, digest emails, account verification emails, and password reset emails are sent via Pair Networks' SMTP email service. Email content is generated on our servers and delivered through the same hosting infrastructure.
Chrome Extension
The Extension communicates with the Assurcast API over HTTPS to fetch feed content and job listings. Personal data (notes, tracked jobs, checklists) is stored locally in your browser and is not transmitted to our servers. If you configure an API key in the Extension, authenticated requests include your API key for identity verification.
AI-Assisted Processing
AI-assisted tools for content creation and editorial review operate through the Platform's standard API interfaces. When AI-assisted review is performed, submission content (title, summary, body, metadata) is processed via the API by authorized users. We do not transmit user data to external AI services as part of our standard Platform operations. Users who connect third-party AI assistants via the MCP server or API control their own data flow and should review the privacy practices of those third-party tools.
Each subprocessor is bound by appropriate data protection agreements.
4. Your Rights
You have the right to:
- Access your data: View your account information, submissions, and subscription preferences at any time through your account settings
- Update your data: Edit your profile, change your email, update your password, and modify your notification preferences through your account settings
- Delete your account: Request deletion of your account and associated data by contacting us
- Unsubscribe from emails: Unsubscribe from broadcast and digest emails at any time using the one-click unsubscribe link in every email, or by managing your subscription preferences
- Revoke API access: Revoke your personal API keys at any time through your account settings
- Delete Extension data: Clear all locally stored Extension data (notes, tracked jobs) by uninstalling the Extension or clearing browser data
5. Data Retention
- Account data: Retained as long as your account is active. You may request account deletion at any time.
- Subscriber data: Retained until you unsubscribe. Unsubscribed records are retained with an unsubscribe timestamp for compliance and to prevent duplicate opt-in requests.
- Content submissions: Published stories and job listings remain on the Platform indefinitely. Draft, rejected, and archived submissions are retained for administrative review purposes.
- Analytics data: Page views, feed requests, content clicks, and email open records are retained indefinitely for aggregate reporting. All records use hashed identifiers (IP, session) rather than directly identifying information.
- Activity logs: Administrative and API activity logs are retained indefinitely for security monitoring and audit purposes.
- Chrome Extension data: Stored locally in your browser for as long as the Extension is installed. Automatically deleted when you uninstall the Extension or clear browser data.
6. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any changes by:
- Updating the Policy Version
- Updating the "Effective Date"
- Posting a notice on the Platform
7. Contact Us
If you have any questions about this privacy policy, please contact us at:
Email:
CPE.io LLCDBA Audit Risk Media
1063 Sheridan Park NE
Atlanta, GA 30324
8. Compliance
This Platform is designed to comply with:
- GDPR requirements
- CCPA requirements
- CAN-SPAM Act requirements (one-click unsubscribe, RFC 8058 compliance)
- Other applicable privacy regulations
9. Data Processing Agreement (DPA)
We are committed to transparency in our data processing practices. The following Data Processing Agreement (DPA) applies to all users of the Assurcast Platform:
Data Processing Agreement (DPA) for Assurcast
Definitions
- "Platform Data" means all data processed by Assurcast, including account information, content submissions, subscriber data, and analytics.
- "Applicable Data Protection Laws" means all laws and regulations relating to the processing and protection of personal data, including GDPR and CCPA.
- "Services" means the Assurcast website, API, Chrome Extension, and related email delivery services.
Data Processing Details
- Subject Matter: Processing of user data for the purpose of providing a news feed, jobs board, email broadcast, and analytics platform for internal audit and assurance professionals.
- Duration: For as long as the user utilizes the Platform and Services.
- Nature and Purpose: To deliver curated content, job listings, email broadcasts, and engagement analytics to users and subscribers.
- Types of Data Processed: Account information (name, email, password hash), content submissions, subscriber preferences, analytics data (hashed IP, hashed session, page views, clicks, email opens), API key hashes, and activity logs.
- Categories of Data Subjects: Registered users (contributors, editors, administrators), email subscribers, and anonymous site visitors (tracked via hashed identifiers only).
Technical and Organizational Measures
- All data is transmitted over HTTPS encryption.
- Passwords and API keys are hashed using bcrypt before storage.
- IP addresses are hashed using SHA-256 with a server-side salt; raw IPs are not stored in analytics tables.
- Session identifiers are hashed before storage in analytics records.
- CSRF tokens protect all form submissions against cross-site request forgery.
- API access is controlled via scoped API keys with rate limiting (60 requests per minute per IP).
- Chrome Extension personal data (notes, tracked jobs) is stored locally in the browser and not transmitted to our servers.
- Personal data is never sold, rented, or shared with advertisers, sponsors, or data brokers. Sponsors receive only aggregate, anonymized campaign metrics.
- AI-assisted processing operates through the Platform's standard API interfaces; user data is not transmitted to external AI services as part of standard Platform operations.
Subprocessors
Subprocessors are limited to Pair Networks (web hosting, database infrastructure, and SMTP email delivery; United States) and Google (Chrome browser storage for the Extension). Each subprocessor is bound by appropriate data protection agreements.
Data Subject Rights
Users may access, update, or request deletion of their data at any time via their account settings or by contacting us. Subscribers may unsubscribe from emails at any time using the one-click unsubscribe link included in every email.
Data Breach Notification
In the event of a data breach affecting user data, users will be notified promptly in accordance with applicable laws via email, notices on the Platform, and on our website.
Data Transfers
Assurcast is hosted in the United States. All user data is stored on servers located in the United States. Users accessing the Platform from outside the United States consent to the transfer of their data to the United States.
Data Retention
Account data is retained as long as the account is active. Subscriber data is retained until the subscriber unsubscribes, with an unsubscribe timestamp retained for compliance. Analytics data using hashed identifiers is retained indefinitely for aggregate reporting. Users may request deletion of their account and associated data at any time.
Termination
Upon termination of services or account deletion, user account data, submissions, and associated records will be removed from our systems. Anonymized analytics data (which cannot identify you personally) may be retained for aggregate reporting purposes. Subscribers may unsubscribe at any time, which immediately stops all email delivery.
Contact Information
For DPA inquiries, please contact us by email at or by mail at: CPE.io LLC, DBA Audit Risk Media, 1063 Sheridan Park NE, Atlanta, GA 30324
Governing Law
This DPA is governed by the laws of the State of Georgia, USA.
Changes to DPA
This DPA may be updated. Users will be notified of significant changes.