Privacy Policy
Effective date: 13 August 2026
Last updated: 25 September 2026
Normascope is operated by Harsha Attray, trading as Yutic (“Yutic”, “we”, “us”, or “our”). This Privacy Policy explains how we handle information collected through normascope.com, including the Normascope Cloud waitlist, and through Normascope Cloud, the paid hosted service. Cloud is not on sale yet; the Cloud sections below apply once it opens.
What we collect
When you join the waitlist, we collect:
- your email address;
- the page or placement through which you joined, where available;
- the referring origin, where available; and
- the date and time of the signup.
We may also receive ordinary technical information needed to operate and protect the site, such as request timestamps, IP address, browser or device information, and security or rate-limit signals. We do not use this information to build a cross-site advertising profile.
We do not ask for screenshots, source code, DOM content, repository names, prompts, API keys, or AI responses through the public waitlist.
Free CLI product analytics
Collection is currently release-gated off. Preview testers can explicitly opt in with NORMA_TELEMETRY=1. Before default-on release, the CLI displays the same field disclosure. We collect only these eight fields:
| Field | Values and purpose |
|---|---|
installation_id | Random UUID v4, generated locally; identifies an installation, not a verified person. |
cli_version | Numeric major.minor.patch release, without custom build metadata. |
platform | macos, windows, linux, or other. |
day | UTC calendar date; no exact event or receipt timestamp. |
event_type | activation, usage, report_generated, or publish_succeeded. Activation is first attempted telemetry use, not package download. Usage is a completed CLI command; report and publish producers also cover Action/MCP callers. publish_succeeded means the client reported a publish it believed succeeded. It is not an account, a subscription or a payment, and no telemetry can grant Cloud access. |
report_generated | Boolean; true only for a report-generation event. |
frame_bucket | none, 1-10, 11-50, 51-200, or 201+; no frame names. |
report_size_bucket | none, under-1MiB, 1-10MiB, or over-10MiB; report bytes are never sent. |
Non-report events use none for both size buckets. We do not collect names, email, repository or organization names, URLs, paths, commits, screenshots, source, DOM, Figma data, prompts, model output, API keys or retained IP addresses through this telemetry system. Network providers necessarily process an IP to transport a request; default-on collection requires verified IP-free telemetry logging across the hosting path. The ordinary site logging paragraph above does not authorize retaining telemetry IPs. No telemetry request headers or bodies are logged by the collector.
norma telemetry status shows the state and disclosure without generating an ID. norma telemetry disable persists opt-out and removes the local ID. Once it succeeds, no analytics event is sent and no installation can be distinguished.
What still happens after `norma telemetry disable`, stated plainly. The CLI sends one empty request per invocation to a separate endpoint, and we add one to a per-date counter. That request carries no identifier, no version, no platform and no client date, and the counter is a single number per UTC date with no column an identifier could be written to. It measures service volume and cannot measure unique users, distinguish installations, or be joined to anything.
To send nothing at all, set NORMA_TELEMETRY=0 or DO_NOT_TRACK=1. These suppress every request including the volume count, and do so without changing saved preferences. DO_NOT_TRACK is honoured in full rather than in part.
The volume counter is unauthenticated, so anyone can add to it. We treat it as a bounded tally of received requests, not a measurement, and it is capped per date so it cannot grow without limit. It expires on the same schedule as everything else below. Previously accepted events remain until expiry; disabling does not send an identifier to request remote deletion.
Events live in free_cli_events and the volume counter in free_cli_volume, both separate from organization data, with no account linkage or Cloud access. Only the operator analytics surface reads them. They are excluded from customer exports and account/organization deletion. Retention covers today and the preceding 89 UTC dates, for both tables. A daily scheduled sweep removes older rows (up to 24 hours of sweep delay); metrics exclude expired rows immediately. Before collection is enabled, telemetry must be excluded from backups or those backups must expire within the same retention period. Restores must run the telemetry sweep before serving analytics. No installation-level rollups are retained beyond this window.
We also count visits to the public pages using Vercel Web Analytics. It sets no cookies and stores nothing on your device. For each page view it records the page address, the referring site, campaign parameters in the link you followed, and general technical details such as browser, operating system, device type, and country. Visitors are counted using a value recalculated each day, so it cannot be used to identify you, follow you across other websites, or connect a page view to a waitlist signup. Our Cookie Notice describes this in full.
Normascope Cloud
When your organization uses Cloud, we collect:
- Account details: your email address, and your GitHub username if you sign in with GitHub. - Organization details: the organization's name, its members and their roles, and invitations. - What you upload: screenshots, comparison reports, scores, page names, repository and branch names, and commit identifiers. - Billing records: your plan, subscription status, payment amounts and dates, credit balance and credit usage, and Paddle's customer, subscription and transaction references. We never receive or store your card number. Paddle collects payment details under its own Privacy Policy. - Security records: sign-in events, API key use, and rate-limit signals.
We use this to sign you in, keep each organization's data separate, host and share reports, show history and trends, answer AI requests you make, bill correctly, prevent fraud and abuse, and support you. Organization members see what their role allows. Anyone with a share link sees what that link shows.
We do not sell Cloud data, and we do not use it for advertising.
AI explanations
When you ask Cloud to explain a difference, we send the AI provider cropped images of the areas that differ, and the comparison's measurements. Nothing is sent to the AI provider unless someone in your organization asks for an explanation, or turns on automatic explanations. The AI and Cloud Disclosure explains Anthropic's commercial API retention and training terms, including exceptions. Deleting a report in Cloud does not immediately delete a copy already processed by Anthropic under those terms.
How long Cloud data is kept
- Runs and reports are kept for up to 90 days, then deleted. - When a subscription ends, remaining reports stay readable and exportable until they reach their normal 90-day retention limit or are deleted sooner. The organization and its remaining content are deleted 90 days after the subscription ends. Resubscribing before organization deletion restores access to remaining data; it does not restart retention or recover deleted data. - You can delete a run, a repository or the whole organization yourself at any time. - Backups and database recovery copies can retain data after it is removed from the active service. Their retention depends on the configured database recovery window and the expiry rules for exported backups. These Cloud settings are still being finalized before paid launch. We will publish the verified maximum retention periods here before paid checkout opens; the 90-day report limit is not a promise that every backup copy expires then. - Billing and tax records are kept as long as the law requires, even after an organization is deleted.
Why we use waitlist information
We use waitlist information to:
- record and manage early-access interest;
- contact you about Normascope Cloud if you have asked to hear from us;
- measure signup sources, page traffic, and demand at an aggregate level;
- prevent duplicate, fraudulent, or abusive submissions; and
- operate, secure, and troubleshoot the website.
We do not sell waitlist information or use it for unrelated advertising.
Email communications
Joining the waitlist is not a purchase, account creation, or subscription. We may send a limited early-access or product update related to your request. We will provide a reasonable way to stop these messages. We do not promise a launch date or access to Normascope Cloud.
Cloud sends account email: sign-in links, invitations, and notices about your subscription and payments. These are part of the service. Paddle sends your payment receipts.
Service providers
We use service providers for hosting, the database, file storage, email, AI explanations, payments and sign-in. Each receives only what it needs for its job. Our Subprocessors and other providers page distinguishes processing on our behalf from payment and sign-in services that also handle information under their own privacy notices.
Our database and application servers are in the United States. Providers may process data in countries other than yours. Where required, international transfers need an applicable legal safeguard, such as an adequacy decision or standard contractual clauses. Before paid launch, we will verify the arrangements covering Cloud providers and publish the applicable safeguards and how to request information about them here.
Waitlist retention
We retain waitlist information while it is reasonably needed to operate the early-access program, measure demand, communicate with people who requested updates, resolve disputes, and meet legal or security obligations. We may remove or anonymize records that are no longer needed.
Your choices and requests
You may ask us to access, correct, export or delete your information, or to stop related emails. For waitlist information, email waitlist@normascope.com. For Cloud information, email queries@normascope.com. We may need to confirm who you are, and that you may act for your organization, before we act on a request.
If you believe we have not handled your information appropriately, you may also contact the data-protection or privacy authority available in your jurisdiction.
Security
We use reasonable technical and organizational measures to protect your information. No internet transmission or storage system can be guaranteed to be completely secure. If we become aware of a relevant incident, we will take the steps required by applicable law.
Children
The site and Cloud are not directed to children under the age at which they can lawfully provide consent in their jurisdiction. Please do not submit a child's personal information.
Changes
We may update this Policy as the site or Cloud changes. The “Last updated” date above shows when the current version was published.
Contact
Normascope is operated by Harsha Attray, trading as Yutic. For privacy questions or requests, email queries@normascope.com.