Privacy Policy
Last updated: 2026-08-06
TL;DR
We take a privacy-first approach to analytics. We do not use cookies, client-side tracking, or persistent visitor identifiers. We do not record the content of your search queries — only the type and frequency of searches you perform. Your IP address is truncated and hashed before storage, never stored raw. We collect only what we need to operate the service, prevent abuse, and understand aggregate traffic patterns.
1. Introduction and Scope
This Privacy Policy describes how De Novo Chem LLC (“De Novo Chem”, “we”, “us”, or “our”) collects, uses, and protects information when you visit the De Novo Chem website at denovochem.com (the “Website”) or use the Saguaro Chem search application (the “Search App”), collectively the “Services”.
This policy applies to information collected through the Services only and does not apply to information collected through third-party services such as our authentication provider (Clerk) or our hosting provider (Railway), each of which has its own privacy policy.
By using the Services, you consent to the data practices described in this policy. If you do not agree with these practices, you should not use the Services.
2. Data We Collect
2.1 Frontend Analytics (Server-Side, No Cookies)
We collect server-side analytics about how visitors interact with the Website. This system is designed to minimize privacy exposure:
- Page views: The URL path of each page you visit (e.g.,
/about,/saguarochem). - File downloads: When you download a tracked asset from the Website.
- CTA clicks: When you click a tracked call-to-action button, we record the button identifier and destination.
- Referrer domain: The domain of the website that referred you to us (e.g., google.com, github.com), if available.
- UTM parameters: Marketing campaign parameters in the URL (utm_source, utm_medium, utm_campaign, utm_term, utm_content), if present.
- Anonymous IP hash: Your IP address is truncated (last octet for IPv4, last 80 bits for IPv6) and then hashed with a daily-rotating salt using SHA-256. The raw IP address is never stored or transmitted.
- Browser and OS family: Coarse-grained values only (e.g., “Chrome”, “Windows”). The full user-agent string is discarded.
- Timestamp: The date and time when each event occurred.
We do not use cookies, localStorage,sessionStorage, fingerprinting scripts, client-side analytics beacons, or persistent visitor identifiers. Approximate unique-visitor counts are derived only from anonymized daily IP hashes and cannot be used to track individuals across sessions or days.
2.2 Backend Usage Analytics (Search App)
When you use the Saguaro Chem Search App, we record privacy-safe metadata about your searches for service monitoring, rate limiting, and product improvement:
- Search kind: The type of search performed (e.g., compound, reaction, document, resolve, detail).
- Search mode: The search method used (e.g., exact, similarity, substructure, text).
- Endpoint: The API endpoint called (e.g., /api/search, /api/resolve).
- Result metrics: Result count (exact count and coarse bucket for aggregation), page number, page size, whether results were capped.
- Performance: Total latency, database latency, cache hit/miss.
- Plan tier: Your subscription plan (e.g., free, individual, team).
- IP and user-agent: Stored as HMAC hashes only, never raw values.
- Timestamp: The date and time when the search was performed.
We do NOT record the content of your search queries. We do not store SMILES strings, InChI keys, chemical names, structure drawings, or any other search input. This is an intentional design decision to protect potentially sensitive research directions, particularly in pharmaceutical and proprietary chemistry research.
To enrich search results with compound properties, safety data, and bibliographic metadata, the Search App sends certain identifiers to third-party public APIs on an as-needed basis. Specifically, chemical identifiers (including PubChem CIDs, SMILES strings, and InChI keys) are sent to the PubChem REST API, and DOI identifiers are sent to the CrossRef REST API. These transmissions are necessary to retrieve and display data within the Search App. Neither PubChem nor CrossRef receives your account information, IP address, or any other personal data — only the identifier needed to fulfill the request.
2.3 Account Data
When you create an account through our authentication provider, Clerk, the following data is collected and stored:
- Email address: Used for account identification and communication.
- Clerk user ID: A unique identifier assigned by Clerk.
- Plan tier: Your current subscription plan.
- Organization ID: If you are part of a team subscription.
- First and last seen timestamps: When you first registered and last accessed the service.
2.4 Contact Form Submissions
When you submit the contact form on the Website, we collect:
- Name, email address, organization (optional), how you heard about us (optional), and your message.
A truncated, salted SHA-256 hash of your IP address is stored with contact form submissions for spam prevention. The raw IP address is never stored. This is a GDPR-compliant design decision.
2.5 Feedback
If you submit feedback through the Search App, we collect:
- Your Clerk user ID, a rating (1–5), feedback type (General, Bug Report, Feature Request, Performance), and feedback content (up to 1,500 characters).
3. What We Do NOT Collect
We have made deliberate design choices to avoid collecting sensitive data:
- Search query content: We never record what you searched for.
- Raw IP addresses: IPs are truncated and hashed before any storage.
- Raw user-agent strings: Only coarse browser/OS family is retained.
- Cookies: No cookies are set for analytics purposes.
- Cross-site tracking identifiers: We do not track you across other websites.
- Persistent visitor IDs: No identifier that persists across sessions or days.
- Biometric or precise location data: Not collected.
4. How We Use Your Data
We use the data we collect for the following purposes:
- Service operation: To operate, maintain, and improve the Services.
- Analytics: To understand aggregate traffic patterns, page popularity, and acquisition channels.
- Performance monitoring: To monitor and optimize Search App performance, latency, and cache effectiveness.
- Rate limiting and abuse prevention: To enforce fair usage limits and detect automated abuse.
- Communication: To respond to contact form submissions and feedback.
- Billing: To manage subscriptions and process payments through Clerk Billing (powered by Stripe).
- Legal compliance: To comply with applicable legal obligations.
We do not use your data for targeted advertising, and we do not sell personal data to third parties.
5. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), United Kingdom, and Switzerland, our processing of personal data is based on the following legal grounds under the GDPR:
- Legitimate interests (Art. 6(1)(f)): For analytics, security monitoring, rate limiting, and service improvement, where our interests do not override your rights and freedoms.
- Contract performance (Art. 6(1)(b)): For account management and subscription billing, where processing is necessary to provide the Services you requested.
- Consent (Art. 6(1)(a)): For contact form submissions, where you voluntarily provide your information.
- Legal obligation (Art. 6(1)(c)): Where processing is required to comply with applicable law.
6. Data Retention
We retain data only as long as necessary for the purposes described in this policy:
- Frontend analytics events: Raw event data is retained for 13 months, after which it is permanently deleted. Aggregate rollup data (daily/monthly summaries) is retained indefinitely for trend analysis.
- Backend search analytics: Retained for up to 13 months for the same reasons. No query content is retained at any point.
- Cached search results: Search results may be cached in an in-memory cache for up to 4 hours to improve performance.
- Account data: Retained for as long as your account is active. Deleted upon account termination, except where retention is required by law.
- Contact form submissions: Retained as needed for business purposes, typically up to 3 years from last contact.
- Feedback: Retained for as long as your account is active or as needed to address the feedback.
7. Data Sharing and Sub-Processors
We do not sell, rent, or trade your personal data. We share data only with the following service providers who act as our sub-processors:
- Clerk — Authentication and billing provider. Processes your email, account credentials, session information, and subscription billing. Clerk uses Stripe as its underlying payment processor. Clerk's privacy policy applies to data processed by Clerk.
- Stripe — Payment processing. Processes your credit card and billing information. Stripe's privacy policy applies to data processed by Stripe. De Novo Chem does not store your full credit card number.
- Railway — Hosting provider for the FastAPI backend and PostgreSQL database. Railway processes server infrastructure data but does not have access to application-level data.
Third-Party Public APIs
The Search App queries the following public APIs to retrieve chemical and bibliographic data. Only the identifiers needed to fulfill each request are transmitted; no personal data, account information, or IP addresses are sent to these services:
- PubChem (National Library of Medicine) — Receives chemical identifiers such as PubChem CIDs, SMILES strings, and InChI keys to retrieve compound properties, safety data, and synonyms. PubChem's privacy policy is available at pubchem.ncbi.nlm.nih.gov.
- CrossRef — Receives DOI identifiers to retrieve bibliographic metadata such as article titles, authors, and publication dates. CrossRef's privacy policy is available at crossref.org.
We may also disclose data if required by law, court order, or governmental authority, or to protect our rights, property, or safety.
Some sub-processors may be located outside the European Union. Where applicable, data transfers are carried out in compliance with applicable data protection laws, including appropriate safeguards such as Standard Contractual Clauses or the EU-U.S. Data Privacy Framework.
9. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data (“right to be forgotten”). Note: Cached search results may persist in our cache for up to 4 hours after deletion is processed.
- Restriction: Request that we limit processing of your data.
- Data portability: Request your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interests.
- Withdraw consent: Withdraw consent for processing based on consent (e.g., contact form submissions).
California residents may have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information is collected, the right to delete personal information, and the right to opt out of the sale of personal information. We do not sell personal information.
To exercise any of these rights, please contact us at contact@denovochem.com. We will respond to your request within 30 days. You also have the right to lodge a complaint with your local data protection authority.
10. Children
The Services are not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If we learn that we have collected personal information from a child under 16, we will delete that information. If you believe we may have collected information from a child under 16, please contact us at contact@denovochem.com.
11. Security Measures
We implement the following security measures to protect your data:
- IP anonymization: All IP addresses are truncated and hashed with a daily-rotating salt before storage. Raw IPs are never persisted.
- User-agent hashing: Full user-agent strings are discarded; only coarse browser/OS family is stored. Backend user-agents are stored as HMAC hashes.
- Parameterized queries: All database queries use parameterized statements to prevent SQL injection.
- API authentication: Internal analytics endpoints are authenticated with Bearer token secrets.
- No PII in analytics tables: Analytics tables contain no email addresses, names, or other direct identifiers.
- HTTPS: All traffic to and from the Services is encrypted in transit.
No method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
12. Changes to This Policy
We may update this Privacy Policy from time to time by posting the revised policy on this page. The date the policy was last revised is identified at the top of the page.
If we make material changes to how we handle personal data, we will notify you by posting a notice on the Website. Your continued use of the Services after changes are posted constitutes your acceptance of the revised policy.
13. Contact
If you have any questions about this Privacy Policy or our data practices, please contact us at:
De Novo Chem LLC
20268 N. 52nd Drive, Glendale, AZ 85308, United States
Email: contact@denovochem.com