Privacy, without euphemism

Privacy Policy

What we receive, what we keep, and the choices you have when you use The Carat Standard.

Updated September 27, 2026Current privacy policy
01

The short version

The Carat Standard has no user accounts and does not run behavioral advertising. We do not sell personal information or share it for cross-context behavioral advertising.

  • Questions you ask The Loupe are kept, with personal details removed, to improve its answers.
  • Usage analytics record which features are used—never report numbers, question text, or anything you type.
  • Reports you upload, and questions you ask The Loupe, are handled by an outside service provider under its own terms (see section 07). Please leave out personal details. When you look up a report number and we retrieve its record from the laboratory, that stone and its scorecard join The Collection, where anyone can see them. We save the scorecard from an uploaded report, never the file, so that report number opens the same scorecard for anyone. Uploads are never added to The Collection.
  • We do not store your IP address with questions or analytics.
02

Questions you ask The Loupe

The Loupe is an automated advisor, not a person or a gemologist. When you send it a question, we receive the question, the recent conversation, and the laboratory and report number of the stone you are viewing so it can answer about that stone.

To prepare an answer, the question, the recent conversation, and the report facts of that stone are sent to an outside service provider, which prepares the answer. Short built-in replies are handled without it.

What we keep

We keep a pseudonymized record of the exchange to understand what people ask and to improve The Loupe:

  • Before storage, we automatically remove personal details we can detect: email addresses, phone numbers, street addresses, long numbers other than the report you are viewing, and the query part of any web address. Automated redaction is not perfect, so please don’t include names or other personal information in questions.
  • The record is linked only to a one-way hash of a random visitor identifier created in your browser. It is not your name, email, or IP address, and your browser replaces the identifier with a new random one every 30 days.
  • The record notes which stone you were viewing (laboratory and report number).
  • We do not store your IP address with the record.
  • We derive short structured labels from each question—such as its topic (“cut”, “setting”), the shape or origin discussed, and a broad carat or budget range—for aggregate analysis.
  • We keep the question and answer text for about 90 days, then delete it. Aggregate counts derived from the labels may be kept longer.

Objecting or deleting

If you would prefer that your questions not be kept, or want saved questions deleted, email hello@thecaratstandard.com. Because we store no name, email, or IP address with a question, tell us roughly when you asked and which report was open so we can find it. The short built-in replies (for example “Who are you?”) are answered in your browser and never sent to us.

03

Reports you upload

When you upload a PDF or image, the document is sent to an outside service provider, which transcribes the report fields. We then score the transcribed facts.

  • We save the report details and the scorecard, not the file itself, so anyone who later looks up that report number sees the same scorecard. Uploaded reports are never added to The Collection or its ordering and never overwrite a record we retrieve from the laboratory.
  • We keep the transcribed report details and the scorecard, which contain grading information only. We do not keep the original file.
  • Your browser keeps the reading on your device for up to 30 days so you can reopen it.

Remove anything you would not want processed—such as a receipt with your name—before uploading.

04

Analytics

We record a small, fixed list of anonymous events to understand how the site is used. Each event carries the random visitor identifier described above, the page type, and a few non-identifying details.

  • Page views, Academy page and lesson views, and time on page.
  • Report lookups started, completed, or failed (with a short error code), example and random readings opened, and readings viewed—with the laboratory, shape, and origin, but never the report number.
  • The Loupe opened and a question sent (with a topic label when known, never the text).
  • The comparison view opened.
  • A returning visit, recorded at most once per day.

Scorecard pages are recorded as /scorecard/:key, so the report number in the address is never sent. Events may be stored in our application database and, when configured, sent to our analytics provider.

Error reports

If part of the site fails, your browser may send a technical error report so we can fix it. It contains the error message and technical trace, the page address with any report number replaced by a placeholder, and your browser’s user-agent string. Errors on our server are recorded with the requested address. Error reports do not include your name, email, IP address, or question text. We keep a limited number of recent error reports in a server log and, when configured, record them in our issue tracker hosted by GitHub.

05

Browser storage

The site uses your browser’s local storage—not advertising cookies—for: the random visitor identifier, the date of your first and most recent visit, recently viewed readings, your comparison selection, and completed readings for up to 30 days. You can clear this at any time with “Clear recently viewed” or your browser’s site-data settings.

Web fonts load from Google Fonts, which receives ordinary connection information such as IP address and browser details.

06

When you write to us

If you use the contact form or email us, we receive your email address, your name and topic if you give them, your message, and anything you include, such as a report number. Contact-form messages are delivered to us by an email provider. We use it only to reply and to keep a record of the conversation, and we delete it when it is no longer needed for that purpose.

07

Service providers and security

We use providers for hosting, database storage, security, analytics, email, error tracking, and automated report reading, Loupe answers, and comparison summaries. They process information under their own terms and retention settings. The provider that reads reports and prepares Loupe answers may retain what it receives and use it to improve its own services. We use an IP address briefly in memory to apply request limits and block abuse; it is not stored with questions or analytics. Hosting systems may keep ordinary request logs for security.

We use reasonable technical measures, but no internet service can promise absolute security. Providers may process information in other countries, where privacy rules may differ.

08

Your choices and rights

You can read Diamond Academy and The Collection without submitting a report or question, ask us to delete saved questions, and verify any report directly with its issuing laboratory.

Depending on where you live, you may have rights to request access, correction, or deletion. Because there are no accounts, email hello@thecaratstandard.com with the subject “Privacy request” and, if possible, the approximate date and the stone you asked about. We will reply within 30 days; sometimes no matching record will exist because of redaction and retention limits.

09

Children, changes, and contact

The service is not directed to children under 13, and we do not knowingly collect their personal information.

We may update this policy as the service or legal requirements change, and will change the date above when we do. Questions: hello@thecaratstandard.com.