← Back to Thorost

Privacy

Privacy Policy

Effective date: July 24, 2026

What information is collected

Thorost collects the business name, city or area, selected public listing, and public business details needed to prepare a checkup. If you submit a request form, it may also collect the contact method and notes you choose to provide.

Why it is collected

The information is used to find the correct business, run public-facing checks, prepare a diagnostic report, and respond if you request follow-up.

Business search terms and submitted records

The live business search sends search terms to the Thorost API so it can query public listing providers. Reports created in the browser are saved to localStorage on your device. The separate request form currently stores submissions in your browser localStorage unless a production storage destination is configured.

Geolocation

If you choose “Use my current area,” your browser asks for permission. Approximate coordinates are used only to narrow the business lookup. You can deny location access and search by city or area instead.

Third-party APIs

Business names, locations, and selected listing identifiers may be sent to public data providers such as Google Places to find and check the business. Website URLs may be requested by Thorost’s website audit endpoint to test public customer-action paths.

Analytics

No analytics provider is configured in the current codebase. If analytics are added later, this policy should be updated to identify the provider and data collected.

Data retention and deletion

Browser-saved reports and request drafts remain on the device until the browser storage is cleared. If a server-side contact or database destination is configured later, retention and deletion procedures must be documented here. You may request deletion using the contact method below if server-side records exist.

Security limitations

Thorost does not ask for Google passwords or listing access for the initial scan. No internet service can guarantee perfect security. Do not submit secrets, passwords, private account credentials, or confidential customer data through the checkup form.

Contact method

A real contact email is not configured yet. Set NEXT_PUBLIC_CONTACT_EMAIL before collecting real customer submissions.

Policy updates

This policy should be updated whenever the product adds new storage, analytics, data providers, or customer communication workflows. Material changes should be dated clearly.