What we measure, and what we never collect
The Public Trust Agent is a tool for checking the evidence behind food claims. We measure how well it does that job, not who you are or what you buy. This page spells out exactly what that means, in plain English.
The short version
- • We use only our own first-party analytics. No Google, no Meta, no ad networks.
- • We never sell, rent, or trade your product checks, preferences, or any inference from them.
- • A shop can see aggregate demand for its products, never who checked, or what they care about.
- • You can turn analytics off, download your data, or delete it, any time.
What we measure, and why
Every measurement answers a real question. If we can't name the question and what we'd do with the answer, we don't collect it.
- Can a new visitor paste a link and get a result without confusion?
- So we can fix confusing wording, supported shops, and slow steps.
- How often is a product identified wrongly, or a conclusion later corrected?
- This is a release guardrail. A growth number never outranks it.
- Do people understand what a badge does and doesn't prove?
- So we can rewrite the benefit and limitation language.
- Which claims, shops, and sources produce incomplete or conflicting results?
- So we know which integrations and sources to build next.
- What makes someone come back for a second check?
- So we prioritise saved checks, alerts, and faster repeat entry.
These are recorded as short, bucketed events: “a result was viewed,” “a claim card was opened,” “the check took 10 to 30 seconds.” Each one carries a random, first-party identifier that you can clear at any time.
What we never collect
- The web address you paste (it can contain order numbers or account IDs). We turn it into an anonymous product code and delete the original within 24 hours
- Your name, email, phone, or address in analytics
- Your IP address (used once to guess a country, then discarded, never stored)
- Your dietary needs, allergies, medical priorities, or family profile details
- Anything you type into a box: searches, messages, report descriptions
- Any advertising identifier, and no advertising or session-replay tracker runs on these pages at all
A check on a Gluten-Free claim, viewed by someone managing celiac disease, is not ordinary web analytics. We treat that whole context as sensitive. Even the individual pieces stay out of our general analytics.
What a shop can and can't see
Consumer demand can tell us which shops would benefit from stronger public proof. But it never becomes a list of people.
- ✓ A shop can be told “at least N people checked your products this month,” but only once that number passes 50, and rounded to the nearest 10.
- ✕ A shop is never shown who checked, what they care about, which family profile viewed a result, a daily timeline, or a small-area location.
How long we keep things
- • The address you paste: deleted within 24 hours of a successful check.
- • Detailed usage events: 90 days, then removed or reduced to anonymous totals.
- • A minimal “did they come back” record: up to 13 months.
- • Anonymous, aggregate totals: kept while useful, reviewed yearly.
Your controls
On the privacy controls page you can:
- • Turn product analytics on or off (it's independent of anything else).
- • Download a copy of your data.
- • Delete your data.
We also honour the Global Privacy Control browser signal. If your browser sends it, we treat analytics as off, and you don't have to do a thing.
This page describes the Public Trust Agent consumer experience. For the full legal notice covering the whole TilliT platform, see the Privacy Policy.