Privacy Policy
Product: RecallRadar
Operator: AppForgeLabs LLC
Site: https://recallradar.withglint.app
Effective date: 13 September 2026
This Privacy Policy explains how AppForgeLabs LLC (“AppForgeLabs,” “we,” “us,” or “our”) collects, uses, and shares information when you use RecallRadar (the website, API, MCP server, feeds, alerts, and related services, together the “Service”).
RecallRadar is a product of AppForgeLabs LLC, a New Mexico limited liability company.
Contact:
AppForgeLabs LLC
1209 Mountain Road Pl NE Ste N
Albuquerque, NM 87110
USA
[email protected]
1. Scope
This policy covers personal information we process as operator of the Service. It does not cover government agency websites we link to, or Telegram, Discord, Slack, or email providers acting on their own platforms after we hand off a message.
2. Information we collect
2.1 You provide
- Email address, if you create an account or subscribe to email
- Billing details processed by Stripe (we receive customer id, subscription status, and limited billing metadata; we do not store full card numbers)
- Watchlist configuration: brand/firm terms, agencies, class filters, webhook URLs, channel destinations
- Messages you send to [email protected]
2.2 Collected automatically
- Server logs: IP address, user agent, request path, status code, timestamp
- Approximate usage metrics: endpoint, row counts, outcome (success/error)
- A session cookie when you sign in to the account page
- Umami analytics on the public site and docs: page path, referrer, browser/OS, device type, and coarse country/region; not used to identify you across sites or for advertising
2.3 Payments other than Stripe
If you pay via the x402 protocol, we may store the payer wallet address, network, amount, resource requested, settlement reference, and timestamp.
2.4 Recall index data
The index contains product, firm, brand, and related fields copied from public agency feeds. That material is government-published recall information, not information we collect from you. If your name or firm appears in an official recall notice, it may appear in our index because it appeared in the source.
2.5 We do not sell personal information
We do not sell your personal information and we do not share it for cross-context behavioral advertising.
3. How we use information
- Operate, secure, and debug the Service
- Match watchlists and send alerts you requested
- Authenticate API keys and MCP clients
- Bill Stripe subscriptions and record x402 usage
- Enforce rate limits, prevent abuse, and keep an audit trail
- Respond to support and legal requests
- Improve coverage, matching, documentation, and understand aggregate public-site usage via Umami
- Send service and (if you opt in) product email; every marketing email includes an unsubscribe link and our postal address
Legal bases where GDPR/UK GDPR or similar laws apply: contract (to provide the Service you asked for), legitimate interests (security, product improvement, public index), consent (optional marketing email), and legal obligation.
4. How we share information
We share information with processors who help us run the Service, only as needed:
| Processor category | Typical use |
|---|---|
| Stripe | Subscriptions, invoices, tax-related billing data |
| Email delivery (e.g. Resend) | Transactional mail and briefs you subscribe to |
| Hosting / VPS / DNS | Store data and serve the Service |
| Umami | Privacy-oriented website analytics |
| x402 facilitator / networks | Verify and settle pay-per-request calls |
| Telegram, Discord, Slack | Deliver alerts to destinations you configure |
We may also disclose information if required by law, to protect the Service or persons from harm, or in a merger, acquisition, or sale of assets, subject to this policy.
We do not publish your email, keys, or watchlists on the public site.
5. Retention
- Account, keys, and watchlists: until you delete them or we close the account
- Stripe customer and invoice records: as required for tax and accounting (often several years)
- Usage and payment logs: up to 24 months, unless needed longer for disputes or security
- Server logs: typically 90 days, longer if investigating abuse
- Umami analytics events: according to our Umami retention setting (we aim to keep them no longer than 24 months)
- Email briefs: until you unsubscribe; we keep a suppression record so we do not email you again
- Agency raw payloads and the public index: for as long as we operate the index
You may ask us to delete account data. We may retain limited records where we must (law, billing, security). Public recall pages derived from government sources are not “your” data and are not deleted because you ask us to hide a government notice.
6. International transfers
We may process information in the United States and in other countries where our hosting or processors operate. If you access the Service from elsewhere, you understand that information may be processed in the United States, including New Mexico and the state of our hosting provider.
7. Security
We use reasonable administrative and technical measures (hashed API keys, HTTPS, access-limited databases). No method of transmission or storage is perfectly secure. You must keep keys and webhook URLs secret.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal information, to object to or restrict certain processing, and to withdraw consent.
To exercise rights, email [email protected] from the address we have on file. We may need to verify your identity. We will respond within the time required by applicable law (often 30 days).
If you are in the EEA or UK, you may also complain to your local supervisory authority.
Do-not-sell / do-not-share: We do not sell or share personal information as those terms are used in the CCPA/CPRA. To make a request even so, email the address above.
9. Cookies and analytics
The public index does not require advertising cookies.
We use Umami to count visits and basic technical information (pages viewed, referrer, browser, OS, device class, and coarse location). Umami is used for first-party product analytics only, not for ads or cross-site tracking. We configure it without a separate advertising identifier.
Signing in to the account page sets one strictly necessary session cookie that keeps you signed in. It is not used for analytics or advertising. You can use the public index and most docs without logging in.
10. Children
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have, contact us and we will delete it.
11. Email and CAN-SPAM
Commercial email from RecallRadar will include:
- AppForgeLabs LLC
- 1209 Mountain Road Pl NE Ste N, Albuquerque, NM 87110, USA
- A working unsubscribe link
Transactional mail (receipts, security, watchlist confirmations) may not include marketing. You can stop marketing mail anytime via unsubscribe or by emailing us.
12. Automated decisions
We do not make legally significant automated decisions about you. We do use automated matching to decide whether a new recall matches a watchlist you configured.
13. Changes
We may update this policy. The effective date will change. Material changes will be posted on the site and, where we have your email, we will try to notify you.
14. Contact
Questions about privacy or this policy:
AppForgeLabs LLC
1209 Mountain Road Pl NE Ste N
Albuquerque, NM 87110
USA
[email protected]
https://recallradar.withglint.app
https://appforgelabs.com