Privacy, in plain language.
This notice covers the Smethe product-preview website and the authenticated Cloud evidence preview operated by TalkDoc, Inc.
Effective July 22, 2026
What we collect
When you submit an access request or contact form, we collect the information you provide: name, email address, company or project, role, product interest, technical context, and message. If the page URL contains campaign parameters, the submitted request may also include those parameters and the referring site’s hostname so we can understand which launch channel produced the request. We do not collect that attribution in the background.
When authenticated Cloud access is enabled and you sign in with GitHub, we process your GitHub user id and login plus the organizations, App installations, repository names, and repository permissions needed to decide which evidence you may inspect or delete. The short-lived GitHub access token used during sign-in is not retained after authorization.
Cloud evidence contains repository and commit identifiers, Git ref and pull-request number, Smethe and controller-adapter versions, scenario and configuration hashes, seeds, finite metrics, assertion outcomes, verdicts, and timestamps. A paid run may include an optional private HTML report attachment. The upload contract has no controller-source or scenario-source field.
If billing is enabled after a written pilot scope is accepted, authenticated billing controls require organization-owner authorization. We process organization-level subscription identifiers, customer id, plan, status, and renewal period. Stripe processes payment-card and tax information; Smethe does not store full card details.
Our hosting providers may process ordinary request data such as IP address, browser type, requested URL, timestamp, and error or security logs. Public pages do not load advertising trackers or third-party social pixels. When configured, limited server-side analytics record form-submission and organization-level product lifecycle events; they do not receive controller source, scenario contents, employee email addresses, or secret values.
How we use information
- Respond to questions and evaluate design-partner or beta requests.
- Plan onboarding and understand aggregate product needs.
- Authenticate authorized GitHub users, display repository evidence, deliver pull-request checks, and administer subscriptions.
- Protect the website and investigate abuse or operational problems.
- Meet legal obligations and enforce our terms.
Submitting a form does not create a Smethe Cloud account or start billing. We do not sell personal information.
Service providers and disclosure
We may use Google Cloud for application and storage infrastructure, GitHub for identity and repository workflow, Stripe for billing, Resend for operational email, PostHog for limited server-side product events, and security or professional-service providers needed to operate the preview. They process information for us under their applicable agreements. We may also disclose information when legally required, to protect rights or safety, or as part of a merger, financing, acquisition, or sale of assets.
Retention
We retain preview inquiries for as long as needed to respond, evaluate a potential relationship, maintain business records, and satisfy legal or security needs. You may request deletion of an inquiry. Some limited information may remain in backups or records we must retain by law.
When Cloud access is enabled, paid private run evidence is configured to expire after 90 days and Cloud Free metadata after seven days. Authorized repository maintainers can request immediate deletion of an individual run from the evidence ledger. Essential browser sessions expire after the configured session window, which is no longer than 24 hours.
Cookies and local storage
Public preview pages do not set analytics or advertising cookies. GitHub sign-in uses an HttpOnly OAuth-state cookie for up to ten minutes and, after successful authorization, an HttpOnly Cloud session cookie for the configured session window. These cookies are essential to prevent sign-in forgery and keep the evidence ledger authenticated. Campaign parameters are carried only through same-site links and submitted with a form; the site does not place them in a tracking cookie or local storage.
Your choices
You can ask to access, correct, or delete information you submitted, or opt out of product email. Depending on where you live, local law may provide additional rights. Contact us with enough detail to verify and fulfill the request.
Children and international use
Smethe is a business-to-business developer product and is not directed to children. TalkDoc is based in the United States; information may be processed there and in locations used by our service providers.
Contact
Send privacy questions or requests to support@talkdoc.com with “Smethe privacy request” in the subject. For product security, see our security page.