Privacy Policy

Last updated: 2026-07-26

NavSignal ("we," "us," or "our") respects your privacy. This policy explains what information we collect when you use NavSignal, how we use it, and the choices you have.

Who controls your data

NavSignal is operated by Chalupa Productions LLC, a Texas limited liability company, which acts as the controller for the data described here. Questions and deletion requests: echalupa@whtnxt.io.

Information we collect

When you create an account, we collect your email address and the domain you register. If you try a free scan, we collect the email address you provide there too. When you connect Google Search Console or GA4, you grant NavSignal read-only OAuth access to that account's data for the properties you choose. We request only the scopes needed to pull impressions, clicks, and session data. We also collect the results of any crawl or audit you run, the conversations you have with NavSignal's chat assistant, and the facts it extracts and stores from those conversations to make future answers more relevant. If you connect a GitHub repository, we collect the repository access you grant and store the code changes we propose on your behalf. We also use Vercel Analytics to collect aggregated, cookieless pageview data, such as pages visited, general location, and device type, from anyone who visits the site. It does not identify you personally or track you across other websites.

How we use your information

Your data is used to run audits, correlate signals across your connected sources, and generate the journey map and action briefs you see in your account. We do not sell your data or use it to train models for other customers.

Where your data is stored

Account and audit data is stored in Supabase (PostgreSQL), scoped to your workspace by row-level security. Search Console and GA4 access tokens are stored encrypted and used only to fetch the data you've authorized. GitHub access tokens, when you connect a repository, are stored encrypted through that same path.

Third-party services

NavSignal uses Supabase (storage), Google Search Console and GA4 APIs (with your authorization), DataForSEO (rankings), OpenRouter (AI briefs and chat), and Vercel (hosting and cookieless site analytics). If you connect a GitHub repository so NavSignal can open pull requests for fixes, GitHub receives the repository access you grant and the changes we propose on your behalf. Each service receives only the data necessary to perform its function.

Systems we host ourselves

Some of the systems behind NavSignal run on infrastructure Chalupa Productions LLC controls directly, not a third party's, which is why they're listed separately from the services above. Twenty, our CRM, holds contact and lead records, including emails captured from a free scan. Langfuse logs the prompts and responses from chat conversations for debugging and quality review. Crawl4AI fetches the pages of the site you're auditing so we can analyze them.

How long we keep it

Audit data and the signals behind it are retained while your account is active. When you ask us to delete your account, we delete the associated audit data as part of handling that request. Emails captured from a free scan are retained until you ask us to remove them. Public scan results are temporary: an automated job runs hourly and removes any that are more than six hours old.

Your rights

You can revoke Search Console/GA4 access at any time from your Google Account settings or from NavSignal's Sources page. You can request deletion of your account and associated data by contacting us.

Children

NavSignal is not directed at children under 13, and we do not knowingly collect information from them.

Changes to this policy

We may revise this policy. The "Last updated" date above reflects the most recent revision.

Contact

Questions about this policy: echalupa@whtnxt.io