Legal
Privacy policy
Effective 27 August 2026. Last updated 27 August 2026.
This policy describes what Sniffs (the app at sniffs.bork.zip) stores when you use it. The operator’s intent is not to track people. We do not run advertising, we do not sell data, and we do not try to learn where you are. A few records still exist because an account, a signed-in desk, and a hosted website cannot work without them.
What we do not do
- No advertising networks, no pixels, no “share with partners.”
- No analytics product that profiles you, fingerprints you, or maps a location.
- No sale or rental of personal information.
- We do not ask the product to infer city, country, or GPS.
Counts we keep (users and traffic)
The only product metrics we want are how many accounts exist and how much the site is used.
- User count comes from the account table itself (a count of signed-up users and company desks). That is not a separate tracker.
- Traffic volume may appear in ordinary hosting logs (how many requests the site served). We use that as a load number, not a dossier on a person.
What Sniffs stores on purpose
If you create an account or join a desk, we keep:
- Account: a seat id we mint, plus whatever Google or X send so “Continue” can find you again (typically an email and a provider account id). That identity row belongs to sign-in and is never shown on the desk. After login you pick a nickname teammates see. Admins can change that nickname on the roster. Email/password sign-up is off so you never type an address into this site.
- Session: a signed-in cookie so you stay logged in. The sign-in library may also attach an IP address and browser user-agent to that session row. That is for keeping the session honest and spotting abuse. It is not used to advertise or to plot where you live in the product.
- Company desk: company name, search brief, queries, source toggles, Bork chat, sniff history, lead cards, and up/down ratings (including optional notes). Team membership and invite codes live here too.
- Keys you paste: API tokens for X, YouTube, Meta, and similar. They are stored so the desk can search on your company’s behalf. Treat them as secrets. We do not display them after save.
Company admins see seat ids and permissions, not emails. A platform operator view can see company names, queries, result headlines, and ratings — not who is on the team — so search tuning can be supported later.
Cookies
We use a first-party session cookie (and a short-lived session-data cookie) only to know who is signed in. No third-party tracking cookies. If you never sign in, we do not set an account cookie for you.
What other parties see (we do not control this)
Using the desk necessarily sends some data off this site:
- Sign-in with Google or X: you authenticate through Grok’s sign-in broker. Google or X (and that broker) still process the login. We keep the identifier they return so the next “Continue” is the same seat — we do not put that identifier on any page.
- Grok / xAI: when you onboard, sniff, rate, or talk to Bork, we send the brief, queries, and the public posts being ranked so Grok can search and write results. xAI’s own terms and privacy policy apply to that processing.
- Hosting: the app is published on xAI’s Grok Build platform (served in production through their host). Standard web logs (time, path, status, approximate volume; often IP at the infrastructure layer) may exist there for uptime, abuse, and the traffic count described above. We do not get a marketing profile from that, and we do not add extra trackers on top.
- Social APIs you connect: if a company saves an X, YouTube, or Meta token, those providers receive the searches the desk runs with that token, under that company’s developer account — not a Sniffs reseller key.
How long it stays
Account and desk data stay until the account or company is removed, or until you ask us to delete it and we can do so. Session rows expire. Hosting logs follow the host’s retention, which we do not set in this app.
Your requests
You can ask to see or delete the account data we hold. There is not a self-serve delete button yet — write the operator of sniffs.bork.zip (the publisher of this app). We will need enough detail to find the right account. Deleting an account does not erase copies already processed by Google, X, xAI, or a social API you connected; those follow their own policies.
Children
Sniffs is a work desk. It is not directed at children under 13.
Changes
If this policy changes, we will update this page and the date above.