Privacy & cookies

Last updated: 7 July 2026

namewright.io helps you name things and check domain availability. This page lists everything we store in your browser, everything we log, what (if anything) leaves our systems, and how to change your mind. No legalese where plain words do.

What we store in your browser

We set no third-party cookies and load no third-party scripts — no analytics tags, no ad pixels. Everything below is first-party:

NameTypeWhat it doesHow longConsent
sb-…-auth-tokenCookieKeeps you signed in to your account.While you're signed inNot needed — required for the sign-in you asked for.
nc_anonCookieTells returning anonymous browsers apart so free usage limits can't be abused and links that browser to its trial token balance. Never used for analytics and never shared.90 daysNot needed — security.
nc_consentCookieRemembers the answer you gave on the cookie banner.12 monthsNot needed — it stores your consent choice itself.
nc_saved_v1localStorageThe names you starred, so your board survives a refresh.Until you clear itNot needed — part of the service you're using.
nc_sessions_v1localStorageYour recent conversations, so you can reopen and resume them on this device.Until you clear it (50 most recent kept)Not needed — part of the service you're using.
nc_session_idlocalStorage or sessionStorageLinks the prompts you type into one thread. With your consent it persists and links your visits over time; without it, it lives only until you close the tab.With consent: until withdrawn · without: current tab onlyConsent required for the persistent, cross-visit version.

What we log

When you describe what you're naming, refine a shortlist, or generate names, we keep a log of that prompt text and the resulting brief — it's how we learn what people ask for and make the consultant better. Prompt text is whatever you choose to type; if you type personal details into a brief, they end up in this log, so the log is handled as personal data either way. Logs are kept for 180 days, then deleted automatically.

We also keep a copy of the conversation itself — your messages and the consultant's replies — to review quality and investigate problems. If you're signed in, saved conversations are part of your account: they sync across your devices and stay until you delete them. Conversations from visitors who aren't signed in are deleted after 180 days, like prompt logs, and are never shared or exported.

Each log entry records the consent state it was written under. Entries from visitors who declined (or never answered) are linkable only within a single browsing session and are excluded from everything described in the next section.

To prevent repeated free signup grants, we keep a keyed hash of a confirmed signup email for up to 24 months. It is used only for abuse prevention, and may remain for that period after an account is deleted.

When you click Register to buy a domain at a registrar, we log that click server-side: the domain, the registrar you chose, and the page you were on. We never see payment details or whether you completed a purchase. For domains that were open when you clicked, we may re-check public registration records a few times over the next month to estimate whether the name was registered. These records are kept for 90 days, are never shared or exported, and are not included in the aggregated market insights below.

Feedback you send

Feedback submitted through the site is stored privately with its category, optional rating, the page it came from, and your email or account identifier when available. We use it to investigate problems, plan improvements, and reply when you ask us to. We only consider publishing an anonymous excerpt when you explicitly allow quoting it, and every excerpt is reviewed before publication. Feedback is deleted after 24 months. Optional email and account identifiers are removed sooner: when follow-up is marked complete, or after 12 months at the latest.

The two things we ask consent for

  1. Product analytics — a persistent identifier in your browser (nc_session_id) that lets us see how your naming sessions evolve across visits. This purpose also enables session replay for debugging — a sampled recording of page interactions in which all text and inputs are masked before anything leaves your browser. Decline it and the identifier becomes tab-scoped and no replays are recorded; the product works exactly the same.
  2. Market insights — your activity may be included in aggregated, anonymized trend data we share commercially: things like which domain endings are in demand, or what naming styles are rising in an industry.

Who we share data with, and in what form

Shared data goes to domain registrars and market-research partners, and only as aggregated, pseudonymized statistics built exclusively from consented activity. Hard rules, enforced in the export layer rather than by policy alone:

Processors we rely on

Supabase hosts our database and sign-in. Polar, our merchant of record, handles payments on their own checkout pages as the seller of record (their privacy notice applies there; we never see card details). OpenRouter relays your naming brief to a language model to plan the conversation, recommend markets, generate names, and evaluate candidates. Fastly Domain Research, when enabled, receives the domain being checked to help determine whether it is available, premium, or listed for resale. We also query the relevant public RDAP registry service with the domain being checked for authoritative registration status. Sentry receives error and performance reports so we can find and fix failures — reports are stripped of IP addresses, cookies, and headers, and session replays (all text masked) are recorded only with product-analytics consent. These providers process the submitted brief, candidate name, or domain only as needed to operate the service; Polar processes payment information under its own privacy notice.

Changing your mind

Withdrawing consent is one click: (also linked in the footer of every page). Withdrawal takes effect immediately for everything going forward — the persistent identifier is deleted from your browser and new activity is no longer linked across visits or included in shared data. It can't retroactively unlink what was already aggregated while your consent was active.

Contact

Questions, or want your logged data deleted? Email privacy@namewright.io.