Privacy
What we store, and why
Short version: you can use the core of this product without an account and without identifying yourself. The places we do store something are listed below, along with who else can see it and how to opt out of anonymous usage events.
If you never sign in
Your shortlists live in your own browser’s local storage, not on our servers. Clearing your browser data deletes them and we cannot recover them, because we never had them.
Searching sends the word you typed to our server so it can look up associations and check domains. We don’t attach those lookups to you or build a profile from them.
If you run a web-use scan
We store the selected name, the public results returned, which sources and query forms were checked, and the original check and expiry times. The expiry controls whether a result can be reused as current evidence; it lets the evidence survive a reload without spending another provider request during the cache window. The record is keyed only by the normalized name—not by your account, shortlist, or IP address.
If you share a shortlist
Creating a share link copies that list of names, the list’s display title when one was set, and the screening results at that moment, to our database so the page can be loaded by anyone with the link. When a web-use scan has already run, a composition summary may be stored with the share. If the author opts in to a web-scan appendix at share time, hit lists, snippets, and source receipts are stored too; the default is overview only. Share pages are public and search engines are allowed to index them. Don’t put anything confidential in a name you intend to share.
If you were signed in when you made the link, we also record that the share is yours, so you can find it again and be told when someone leaves feedback on it. That connection is ours alone: nothing on the share page names you, and a reader cannot tell a signed-in author from an anonymous one. Sharing without an account works exactly as before and stores no owner at all. If you delete your account, the links you created keep working and simply become anonymous again, so people you sent them to are not cut off without warning.
If you give feedback on a shared shortlist
A share page lets anyone holding the link react to a name, write notes on it, and propose names of their own. We store what you write, the display name you type, and an identifier your browser generates and keeps so your own contributions can be edited later. There is no account and nothing is verified, so treat a display name as a label rather than proof of who wrote something.
Feedback is readable by anyone who has the link, which is the point of it, so it is as public as the link itself. Unlike the names, it is not part of the page search engines see. Write it as you would a comment on a document you have passed around, and leave anything confidential out.
If a first scan runs on its own
The first batch of names in a shortlist is scanned automatically so the evidence is there without being asked for. That costs us money per name, so we keep a running count of how many names have been spent this way, against your account id when you are signed in and against your IP address when you are not. It holds a number and two timestamps, never the names themselves. An explicit scan you ask for is free and is never counted.
If you share a comparison
Sharing a finalist comparison saves a separate point-in-time snapshot of the selected names and their screening results. That page is also public and indexable. Later shortlist edits do not change an already shared comparison. Domain and trademark status can still change in the real world after the snapshot is taken.
If you ask for availability emails
Opting in to “get notified if any of these open up” stores your email address against that one shortlist, plus a random unsubscribe token. We use it for exactly that purpose. We don’t sell it, and we don’t add you to anything else.
Every such email carries a one-click unsubscribe link that deletes the record outright rather than flagging it. The watcher count shown to a list’s owner is a count only. Subscriber addresses are never exposed through the app.
If you sign in
Signing in with Google or GitHub stores the name, email address, and avatar URL that provider gives us, so your shortlists can follow you across devices. We never receive your password. In a shared project we also store what you contributed: comments, votes, and candidates you added.
Who else processes this
Hosting runs on Vercel and the database on Neon. Word and definition lookups go to Datamuse. Meaning evidence on the seed row queries the public English Wiktionary API (CC BY-SA). Trademark evidence comes from public USPTO records. Domain availability is checked against DNS and the registries’ own RDAP services, not by querying a registrar’s search box. Notification email is sent through Resend. The optional AI lens and brief tools send your seed or brief text to Anthropic (or through the Vercel AI Gateway). If you upload a photo or screenshot of a name list, that image is sent to Anthropic only to read the list and produce the same reviewable text import. An on-demand finalist web-use scan sends only the names you selected to the public Wikipedia, npm, GitHub, and US Apple App Store search APIs and, when configured, Brave Search. It also requests the matching public .com homepage to record whether a page answered and what title that page supplied. Sign-in is handled by Google or GitHub depending on which you choose.
Tracking
There is no advertising or cross-site tracking on this site.
NameSheet uses Vercel Web Analytics to count page views, referrers, and broad device and country information. It sets no cookies, loads from this site’s own domain, and identifies a visitor only by a hash that resets daily. Shared shortlist addresses are recorded without their ID. The preference below and Do Not Track turn it off along with the usage events.
Domain checks are cached briefly, an hour for the common extensions and six for the rest, so that a name several people look at does not cost a fresh registry lookup each time. That cache holds the domain and its verdict, nothing else: no account, no address, no link to who asked. Rows are deleted a week after they were written.
Anonymous usage events
To learn whether the workspace is understandable, NameSheet records a small set of anonymous actions such as showing or using a recorded example, committing a seed, starring a candidate, running a scan, or sharing a shortlist. These records contain only fixed action labels, counts, booleans, and timing. They never contain the seed, candidate, part, shortlist name, or other text you entered.
A random identifier stored only in this browser lets us distinguish a first visit and measure whether a feature is revisited. It is not tied to an account or IP address and does not follow you across browsers or devices. Vercel handles the request and Neon stores the event. An IP address is used only for a short-lived in-memory abuse limit and is not written to the events table.
NameSheet honours your browser’s Do Not Track setting. You can also change this browser’s preference here; opting out deletes its random usage identifier and stops future events.
Anonymous usage events are off in this browser.
Deletion
Unsubscribe links remove a subscriber record immediately. For anything else, including an account and everything attached to it, email hello@namesheet.co and we’ll delete it.
This page describes how the software actually behaves. It has not been reviewed by a lawyer and isn’t a substitute for one if you need a compliance position for your own jurisdiction.