Skip to main content
Forelandby Blindspot Labs

Trust

Data security

The shortest version: we mirror only public planning data, we collect the minimum needed to run an account, and we never sell user data or feed it to AI training. The longer version is below.

Public planning data only

Every planning record on the platform is published by an Irish local authority under the Planning and Development Act 2000. We mirror what the council publishes; we do not edit, anonymise, or supplement application contents.

Authentication via Clerk

Sign-in is delegated to Clerk, an SOC 2 Type II–certified identity provider. We never see your password. Sessions are HTTP-only cookies; we exchange them for a stable user ID on the server. Magic-link and OAuth methods are available.

Database hosted on Neon (Frankfurt, EU)

User accounts, saved searches, saved precedents, and project content live in a managed PostgreSQL database in Neon's Frankfurt region. Connections are TLS-encrypted in transit. Rows are scoped by user ID at the query layer; ownership is enforced before any read or write.

No personal data beyond account info

We collect: a Clerk-issued user ID, your email address, an optional display name, and the work you explicitly save (searches, precedents, projects, plain-text notes). We do not collect: marketing analytics, IP-based location tracking, third-party advertising IDs, or any special-category personal data.

AI processing with no-training clause

AI search runs on Anthropic's Claude API under their commercial terms — your prompts are not used to train Anthropic's models. The full content of your AI conversations is never logged on our servers unless you press "Save" on a response, in which case it lives only under your account, deletable at any time.

Project isolation

Projects, saved searches, and saved precedents are owner-scoped. Other users of the platform cannot see your work. Every API endpoint that reads or writes user content checks the owning user ID before responding.

Sub-processors

We use a small set of named operational providers to run the service. We do not sell, rent, or barter user data with anyone else.

  • VercelHosts the Next.js frontend; logs request metadata for security and abuse prevention.
  • RenderHosts the API backend that serves planning-record search.
  • ClerkAuthentication; stores email + issued sessions.
  • NeonManaged PostgreSQL (Frankfurt) for accounts, saved searches, projects.
  • AnthropicProvides Claude for AI question-answering. Prompts are not used to train Anthropic's models.

Reporting a security issue

If you find a security issue, please email info@blindspotlabs.ie with the subject “Security issue” and a description of what you found. We respond within two business days. Please do not publicly disclose the issue until we've had a chance to patch it.

See also the Privacy Policy for data rights, retention windows, and GDPR information, and the Methodology page for how answers are produced and cited.