PRIVACY NOTICE · OCTOBER 1, 2026
How we handle your information
This notice covers Latchgrove’s free browser demo, account preview, and private sandbox checkout test, operated by Gabriel Cohen.
Live paid access remains disabled. When private sandbox checkout is enabled, it is limited to the configured test account. Use Stripe test payment details and synthetic or redacted examples only. Do not submit real payment information, tax identifiers, banking details, resident information, access codes or other confidential personal data.
The browser demo
The free demo checks packet inputs in your browser. Its application code does not send those inputs to a checking server or save them to browser storage. A file you choose to download is saved on your device.
Account sign-in
When you request an email code, your email address is sent to Supabase for authentication and processed through Resend to deliver the message. Signing in can create an account. Supabase stores authentication information, including your email, account identity and session records. Latchgrove stores your account identifier and account creation information to keep your workspace separate from other accounts.
The account page keeps its access token in memory. It does not save that token in cookies, localStorage or sessionStorage. Reloading or closing the page requires a new sign-in. This does not erase records held by the authentication provider.
Saved rules and server checks
If you save a rule profile, its definition, identifier and version are stored on the server. Account and usage records support access checks, limits and retries. If an API key is created, the server stores its hash, identifying prefix, label and revocation information rather than the complete key.
Server checks process the structured packet you submit. The application does not store the raw packet request body. It stores a request hash, references needed to track the check, and the result. Saved findings can contain identifiers or other values supplied in your packet. A hash is not a substitute for removing sensitive information before submission.
Result replay through the API expires after 24 hours. An hourly cleanup job is configured to permanently clear expired result contents from the active database, normally within about 25 hours of the check when it runs successfully. Errors, backlogs or service interruptions can delay cleanup. This does not erase provider backups or delete the remaining check records, including request hashes, references and usage information. Saved rules, account information, usage and billing records do not currently have an automatic deletion schedule.
Private sandbox checkout
When you start test checkout, Latchgrove sends Stripe your account identifier (UUID), an order identifier, the test price reference and quantity, return URLs, and an integration label. The account and order identifiers also identify the simulated payment. The application does not send or prefill your sign-in email address in this request. Any email or other details you enter on Stripe’s checkout page are sent directly to Stripe.
Stripe processes test checkout details and creates sandbox transaction and event records. Its responses and signed payment events are processed by Latchgrove’s server. The application stores account and order identifiers, the simulated amount and currency, checkout-session and payment references, checkout URL, event-processing outcomes, test-disclosure version and acknowledgment time, and sandbox usage records in Supabase. It does not copy checkout contact or card details into its payment tables.
These test records do not currently have an automatic deletion schedule. Signing out or finishing a test does not delete them. Read the sandbox test disclosure before continuing. Test checkout does not purchase paid service or grant live-service access.
Service providers and support
The website host processes requests to deliver the site. Supabase provides authentication, database storage and the server API; Resend delivers sign-in email; Stripe processes sandbox checkout. These providers may retain technical, delivery, security and authentication logs under their own practices. We have not added advertising trackers or analytics scripts to the application.
If you contact gcohenbr@gmail.com, your address and message are handled through the support mailbox to respond to your inquiry. Avoid sending sensitive documents or identifiers.
Questions and requests
Contact Gabriel Cohen at gcohenbr@gmail.com with privacy questions or requests about information you have submitted. Include enough detail to identify the account or inquiry, but do not send passwords, one-time codes or API keys. Requests may require verification of account ownership.
We will update this notice when the service’s data handling changes. The date above identifies this version.