Your conditions stay private.
Your raw future-purchase request, price policy, individual-option research, destination city/region/ZIP and lifecycle history are private to you, authorized Condi operators, and an agent or capability holder you explicitly authorize. They are not published as a product-country market.
Anonymous drafts are stored privately for activation, expire after seven days, and are not counted as active demand. Short activation links last twenty minutes and are removed from the address bar. Knowing an intent ID is not access. Keep read-only status tokens private; they expire and can be revoked in the purchase page.
Your email is held by Supabase Auth. Purchase records use a pseudonymous account ID. City, state or ZIP can help research delivered cost; Condi does not request a street delivery address. In existing paid Israel rounds, the seller collects checkout and shipping information.
Public market pages show aggregate active purchase-intent counts with counts below five suppressed. These are potential purchases, not guaranteed buyers. Private clusters can overlap and must not be summed as executable demand. A reviewed price baseline is not a supplier offer.
Tagged links preserve the latest valid source/campaign token in a browser-session cookie through navigation and sign-in. A new purchase preserves its original source, capture transport and verified OAuth client when present. Activation, editing and withdrawal do not rewrite origin. Tags are self-reported metadata, not a verified referral, endorsement or payout claim.
OAuth connections require your approval of specific soft-purchase permissions. You can revoke them in your account. No connection grants payment, seller or administrator access. Optional single-purchase capability access is read-only and can be revoked separately.
Email subscriptions are optional and can be stopped on the purchase page. Local development messages go to the test inbox. Hosted delivery requires a configured provider; provider acceptance is not proof of inbox delivery or attention. Private polling records when an agent checked, separately from when you last confirmed interest.
Versioned conditions, research evidence and important lifecycle events are retained for recovery and audit. Closing soft demand revokes polling capabilities and subscriptions and cancels pending messages. A configured scheduler expires stale records and redacts unclaimed expired draft content and its raw revisions. Minimal source/capture/lifecycle metadata remains. Owned future-purchase records remain available for history and export. You can download your private future-purchase data in your account. Full account deletion and owned-record retention need a finalized production policy before invitations.
For existing seller-held paid rounds, a seller sees deposit reference codes and clearing outcomes. A release because a limit is below clearing can reveal which of the seller’s own price bands the limit reached. Exact reservation prices are not published to sellers.