Privacy Policy

Last updated: April 2026

Overview

CDMO Signal is a free, open-access intelligence platform for biopharma manufacturing. No account or registration is required to use the platform. We collect minimal data, and we are committed to handling it responsibly under applicable privacy laws including GDPR (EU/UK) and CCPA (California).

This policy describes what we collect, why, our legal basis for processing, how long we keep it, and your rights. Our primary legal basis under GDPR is legitimate interest (Article 6(1)(f)) for operating, securing, and improving the service and for business-to-business marketing analytics.

Data We Collect

IP addresses — Collected in-memory for rate limiting and country-level geolocation only. We do not store full IP addresses to disk; only an anonymized hash and country/region/city lookup are persisted.

Search queries — When you use the AI search, your query is sent to Anthropic's Claude API alongside our CDMO database context. We log search queries, timestamps, AI-classified intent categories, time spent on results, and which results were clicked, to improve search quality and the product. Anthropic does not use API inputs to train their models. See Anthropic's privacy policy.

Anonymous visitor ID — A random token stored in your browser's local storage to recognize returning visits and aggregate usage patterns. We may link this ID to a contact record we hold about you (for example, if you provide your email or engage with marketing communications from us) for engagement analytics and follow-up purposes.

Email addresses — When you export a PDF report or subscribe to search alerts, we ask for your work email so we can deliver the file or notification. We also link the email to your visitor ID so we can recognize returning visits from the same person.

Data Retention

Engagement events (searches, clicks, time on results) that can be linked to an identifiable contact are retained for 24 months from the date the event occurred. After 24 months, the link to the contact is automatically removed; the aggregate event itself is preserved for product analytics.

Contact records (name, email, company, title) uploaded to our internal CRM are retained as long as you remain in our contact database. You can request earlier deletion at any time (see Your Rights below).

Anonymized search analytics (aggregate counts, top queries, etc.) are retained indefinitely.

Cookies & Local Storage

We use the following browser storage:

  • localStorage — Anonymous visitor ID (cdmo_visitor_id) and your previously-entered export email (cdmo_export_email) for convenience.
  • sessionStorage — Search referrer tracking and marketing attribution parameters. These are cleared when you close your browser tab.
  • Session cookies — Flask login session for authenticated admin/CDMO claim access only.

We do not use third-party tracking cookies, advertising cookies, or behavioral analytics scripts. You can clear all browser data for cdmosignal.com at any time in your browser settings.

Your Rights

Under GDPR (EU/UK), CCPA (California), and similar laws, you have the right to:

  • Access — Request a copy of all data we have about you
  • Erasure — Request that we delete your data
  • Rectification — Correct inaccurate data
  • Object — Object to processing based on legitimate interests
  • Restriction — Limit how we process your data
  • Portability — Receive your data in a structured format

To opt out of marketing analytics: Use the opt-out link at the bottom of any email we send you, or contact us at hello@cdmosignal.com. Opting out permanently removes your data from our engagement analytics.

To exercise any other right or ask a question: Email hello@cdmosignal.com. We will respond within 30 days as required by law.

Data Sharing

We do not sell, rent, or share your data with third parties for their own purposes. We use the following processors to operate the service:

  • Anthropic (Claude AI) — Powers the AI search. Your search queries and CDMO database context are sent to Anthropic for processing. Anthropic does not train on API inputs.
  • Render — Hosting infrastructure for the platform.
  • SendGrid / SMTP provider — Email delivery for PDF exports, alerts, and notifications.

We do not share your personal data or engagement analytics with CDMOs or any other third parties.

Third-Party Services

Anthropic (Claude AI) — Powers the AI search. Your search queries and CDMO database context are sent to Anthropic for processing. Anthropic does not train on API inputs.

Web search — The AI search may perform web searches to supplement database results. When this happens, search terms related to CDMOs may be processed by web search infrastructure. No personal data is included in these searches.

CDMO Intelligence Data

All CDMO data displayed on this platform comes from publicly available sources: the FDA Data Dashboard, ClinicalTrials.gov, SEC EDGAR, and public press monitoring. No personally identifiable information is collected from these sources. This data is aggregated and scored to provide manufacturing intelligence.

Children

CDMO Signal is a B2B service intended for adult professionals in the biopharma industry. We do not knowingly collect data from children under 16.

Changes to This Policy

We may update this privacy policy from time to time. Material changes will be reflected in the "Last updated" date at the top of this page. Your continued use of CDMO Signal after changes constitutes acceptance of the updated policy.

Contact

Questions about this privacy policy, or to exercise your rights? Contact us at hello@cdmosignal.com.