Privacy
What we hold, who else sees it, and how to get it back.
Delphi Monitor measures brands rather than people, so most of what it stores is about companies and public web pages. This page says exactly what the exceptions are. It covers Delphi Monitor, operated by Phantasm and Brain, and was last changed 5 September 2026.
What we hold about you
Five things. Everything else in the product is about brands, not about people.
- Your name
- So a colleague can see who invited them, and who is in the account.
- Your email address
- It is how you sign in, how a password is reset, and where a measurement lands.
- A one-way hash of your password
- So a password can be checked without anybody, including us, being able to read it.
- Which organisation you belong to, and your role in it
- It decides what you can see and whether you can spend the organisation's money.
- When you signed in, and when a founder entered the account to help
- So an operator opening your account leaves a record that you could be shown.
We do not hold your card. The payment page is Stripe’s own and the card number never reaches us. We do not buy lists, we do not enrich your record from anywhere else, and we do not build a profile of you.
What we hold about your business
This is the bulk of it, and almost none of it is personal data.
- The brands you measure
- Name, website, category and market. You give these during onboarding and can edit them.
- The questions put to the assistants
- Drafted for your category, then edited by you. They are the measurement.
- The rivals you are measured against
- Name and website. Public companies, named by you or proposed and then kept or removed.
- What each assistant answered, word for word
- It is the evidence behind every figure. Without it a score is an assertion.
- What was read from your public website
- Delphi identifies itself when it fetches, obeys robots.txt, and reports a refusal as a finding rather than working around it.
One rule shapes all of it: nothing in a measurement is designed to hold personal data. Delphi asks assistants what they recommend to a buyer, and it does not know or ask who any buyer is. If you type something personal into a question or a brand name, it is stored because you typed it, so please do not.
Who else sees it
Every company that receives any part of your data, what they get, and the part of Delphi that sends it.
- OpenAI
- One of the five assistants a question is put to. The buying questions in a workspace and the market they are asked in. No name, address or account detail.
- Anthropic
- One of the five assistants, and the model that reads the answers back and labels what each one said. The buying questions, and the answers every assistant gave, so they can be read and classified.
- One of the five assistants. The buying questions in a workspace and the market they are asked in.
- Perplexity
- One of the five assistants. The buying questions in a workspace and the market they are asked in.
- xAI
- One of the five assistants. The buying questions in a workspace and the market they are asked in.
- Supabase
- The database everything is stored in. Everything the account holds.
- Vercel
- Hosting, and the cookieless count of visits to our public pages. Every page and every request passes through it. Requests, and the server logs they produce. For a public page it also receives the address of that page with anything after the question mark removed, the site or search that linked to it, and the country and browser it was opened in. It never receives a signed-in page.
- Stripe
- Taking payment, and holding the card. The billing name, address and card. Delphi never sees or stores a card number: the payment page is Stripe's own.
- Resend
- Sending the email this product sends. The address a message goes to, and what it says.
- Inngest
- Running a measurement in the background so a browser is not holding it open. The identifiers of a run, never its content.
- Cloudflare
- Telling a person from a script on the sign-up and enquiry forms, through the Turnstile check. A one-time token from the form. No account data.
That list is the whole of it. Each entry names the module inside Delphi Monitor that talks to that company, so the claim can be checked rather than trusted, and when an integration is removed its row goes with it. We do not sell your data and we do not share it with advertisers. What Delphi learns across accounts, and the rules that bound it, is the next section.
The five assistants are asked your buying questions. They are not sent your name, your address, your account or anything about the people in it. Their own terms govern what they do with a prompt, and those terms are published by each of them.
What we learn across accounts
Delphi is a measurement product, so what it knows about how the assistants behave grows as more brands are measured. Four rules bound that, and each one is enforced in code rather than promised.
- No customer, brand or category is ever named
- A finding is a count or a share. The queries behind them return numbers and third-party publishers, and a domain belonging to any measured brand is excluded from every list that names one.
- Nothing is reported from fewer than three independent companies
- Below that floor the answer is that there is not enough to say. A pattern drawn from one or two companies is that company's data wearing a lab coat, and a reader cannot tell it from a real finding.
- Nothing another account did can change your score
- Your Delphi Index is computed from your own measurement alone. It would be indefensible for a score to move because a stranger signed up, so there is no code path from a cohort reading to any figure of yours.
- What we publish is about the assistants, not about you
- Published research answers how the assistants behave: how often one repeats itself, how much they disagree, how many brands they will name. Those need no customer identified and none is.
The cohort reading on your Claims page is this working for you rather than on you: it is how you find out which sources the assistants keep reaching for in your kind of business, which no single measurement can show. The same floor applies to it. Where fewer than three independent companies have been measured on the same footing, it says there is not enough to say rather than showing you a number computed from one.
Where we publish a finding, it is about the assistants rather than about any brand, and it carries the number of measurements behind it inside the sentence so it cannot be quoted without its own denominator.
Cookies, and what we count
- A sign-in cookie
- One cookie keeps you signed in. Without it you would sign in again on every page.
- A check on two forms
- Sign-up and the enquiry form ask Cloudflare Turnstile to tell a person from a script, which may set its own cookie in the process. It is a fraud check and nothing else.
- A count of visits to our public pages
- We keep a running count of how many times each of our public pages is served. A row is the name of the page, the hour it happened in, and one mark saying whether the request called itself a crawler. Nothing else is kept: no cookie is set or read for it, no address, no browser details, no account and no brand. The time is deliberately blunt, to the hour rather than the instant, so that a row is one of many in that hour rather than a moment we could line up against anything else. It counts requests rather than readers, and it can never tell us who visited.
- What is used inside your account
- Inside a signed-in account we record which pages of the product are opened, which panels are expanded and which controls are pressed. A row is the brand it happened in, the page, what was opened or pressed as it is labelled on screen, and when. We keep this so we can see which parts of the product are worth building on and which are not being used, and so we can tell that a measurement somebody paid for has not been looked at.
It records the brand and not the person. There is no name, no address, no device and nothing that separates one colleague from another, so it can tell us that a page was opened and never which of you opened it. No cookie is set or read for it beyond the one that keeps you signed in. It covers the product only: nothing you type, no question you write and no answer we measure is part of it. - Where a visit to our public pages came from
- On our public pages we also record the site or search that linked you to us, along with the country you opened the page in and the kind of browser and device you used. We keep this so we can tell which of the places we write and appear actually sends anyone.
No cookie is set or read for it and your address is not kept. Anything a link carries after the question mark is removed before the page address is recorded, so a link sent to you privately cannot travel with it. It covers our public pages only and is never switched on inside a signed-in account. - Nothing that follows you across the web
- There is no advertising pixel, no tag manager and nothing that could recognise you on another company’s website. The one measurement tool on our public pages is cookieless: it stores nothing on your device and reads nothing from it. That is why this site has no cookie banner. Nothing above stores or reads anything on your device except the sign-in cookie and the fraud check, and both are necessary for the thing you asked for.
How long we keep it
- While you have an account
- Everything, and deliberately. A measurement is only useful next to the ones before it, so nothing is thinned out or aged away. If you cancel, we keep it: the account drops to the free level, every past measurement stays readable, and resubscribing puts you back where you were rather than starting you again.
- When you ask us to delete it
- We delete it. See below.
- Diagnostic logs
- Server logs are held by our hosting for a short window and are used to work out why something broke. They are not a copy of your account.
Your rights
- See it
- Every workspace exports as CSV and as a document from inside the product, at any level, at any time, including after a cancellation. If you want the whole account in one go, ask and we will send it.
- Correct it
- Your name, the brands, the questions and the rivals are all editable in the product. For anything else, write to us.
- Delete it
- Write to contact@delphimonitor.com from the address on the account. We remove the account, the organisation, its workspaces and every measurement taken for it. We will confirm when it is done. Export anything you want first, because after this there is nothing to send you.
- Object, or take it elsewhere
- Tell us and we will stop. The export above is a machine-readable copy you can take to anybody.
- How long we take
- We aim to answer within a few days and will not take longer than a month. There is no charge.
Security
- Passwords
- Stored as a one-way hash, so nobody at Phantasm and Brain can read yours, and neither could anyone who obtained the database.
- Separation
- Every read of your data is scoped by your membership of your organisation. There is no path in the product by which one customer can reach another’s workspace.
- The database
- Encrypted at rest and in transit by our hosting, and not reachable from a browser: the data interface our database provider offers is switched off, and the application talks to it directly.
- If something goes wrong
- If we ever hold a breach affecting your data, we will tell you what happened, what it touched and what we did, without waiting to be asked.
The rest
- Where it is processed
- The companies listed above operate internationally, so your data is processed outside the country you are in. Each of them publishes the safeguards they use for that.
- Children
- Delphi Monitor is sold to companies and is not for anybody under 18.
- Changes
- If we change how we handle your data in a way that matters, we will email everyone with an account before it takes effect. The date at the top says when this last changed.
- Ask us anything
- contact@delphimonitor.com. A person reads it. The terms and the refunds page cover the commercial side, and the method covers what is measured and how.