Ascently Stack Audit — Privacy Policy
Effective: 2026-09-09 Applies to: audit.ascently.com (US-only alpha). Not the main website, not any future product. Version: 0.1 — interim, founder-signed, not yet reviewed by outside counsel
Ascently is operated by Stanislav Chentsov, Miami, Florida, United States. Contact: privacy@ascently.com.
The short version
There is no account. We do not ask for your name, and we do not want it. What you type into the audit form is used to run the audit and is then gone. We keep a small numeric record that an audit happened. If you join the waitlist, we keep your email address for that and nothing else.
What we collect when you run an audit
- A session id our server assigns to each request (a random identifier returned to your browser in the
X-Correlation-IDheader). It is not linked to you, and we do not use it to recognise you on a later visit. - Country and age band — used only to check that you are eligible before anything else runs.
- Your supplement list with the doses you enter.
- Medication names you select or type, up to 50.
- Free-text notes, up to 1,024 characters, if you write any.
- Your choice on the aggregate-research checkbox (off by default).
We also process your IP address while the request is in flight, to apply rate limits and the bot check. We do not store it in the audit record.
The notes box
Anything you write in the notes box is scanned for emergency red flags — chest pain, severe bleeding, thoughts of self-harm, anaphylaxis. If one fires, we stop and show you an emergency message instead of a result. The text itself is used for that check and for nothing else, and it is not written to storage.
What we do not collect
No name. No email address (except the separate, optional waitlist below). No date of birth — an age band only. No postal address. No health-plan or medical-record identifier of any kind. No lab values. No genetic data. No payment details; the tool is free.
The audit record, and how long we keep it
Every audit writes one row to an append-only log. The row records that an audit ran and what shape it had: the session id, country, age band, how many items were in the stack, how many medications, how many issues came back, whether an emergency red flag fired, and a hash of the text you were shown. It does not record the names of your supplements, your medications, or your notes.
During the alpha we keep audit rows indefinitely. The audit store is append-only by design, so nothing deletes a row today; a scheduled expiry has not been built yet. When it is, this sentence will state the period and the date it took effect.
Our host keeps ordinary server logs, which include IP addresses, for its own operational period.
Waitlist
If you ask to hear about the personalised engine, we store your email address, the time you signed up, and your consent flag. We use it for one thing: to tell you when that product opens. We do not sell it, we do not share it, and we do not add you to anything else. Reply to any message to come off the list, and we delete the row.
Cookies and scripts
We set no analytics cookie and run no advertising script. Cloudflare Turnstile — the check that you are not a bot — runs a script from Cloudflare and may set a cookie in your browser. Cloudflare sees your IP address as part of that check.
Who else handles this data
- Fly.io — hosting and the database, United States region.
- Cloudflare — the bot check described above.
- GitHub — source code hosting. It holds no data of yours.
We have not yet put a reviewed data-processing agreement in place with Fly.io or Cloudflare. That review is on the list for our first engagement with outside counsel, after funding. We are telling you this rather than implying a review that has not happened.
Aggregate research
The checkbox on the form is off by default and you get the same audit whether or not you tick it. If you tick it, we may include your submission in counts and distributions used to improve the rule set — how often a class of interaction appears, which nutrients stack up past their upper limit. Those outputs are aggregate; nothing in them points back at a person.
Your choices
There is no account to delete, because we hold nothing keyed to you. If you are on the waitlist, write to privacy@ascently.com and we remove the row. We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are used under California law.
If you live in Washington State, note that your supplement and medication entries may count as consumer health data under Washington's My Health My Data Act. We do not sell that data and do not share it beyond the processors named above.
Security
Traffic runs over TLS. The audit database sits in our hosting provider's private network. We hold no security certification and we do not claim one: no SOC 2 report, no HIPAA attestation. This tool is built not to hold health information tied to a person, which is a design choice, not a certificate.
Children
The service is for adults, 18 and over. We do not knowingly collect anything from a child.
Changes
If we change this policy we change the effective date at the top and post the new version here.
Contact
privacy@ascently.com