Privacy policy

ProbativeVersion 1.0Effective September 30, 2026

1. The short version

This site sets no cookies and has no forms or advertising. Cloudflare hosts it and logs each request. If you email us, we use what you send to reply and to check whether we’re free to act. We also hold the names, business email addresses and companies of the people we send Reads to, which we take from public sources.

We don’t sell personal information or share it for advertising. You can ask what we hold about you and have it corrected or deleted, apart from the few records section 6 says we keep even then. You can also ask us to stop contacting you. Write to hello@probativehq.com.

2. Who runs this site

This site, probativehq.com, is run by Probative, a research firm based near Seattle, Washington, United States. In this policy “we,” “us” and “our” mean Probative.

Write to hello@probativehq.com about anything in this policy, including a request about your own information.

3. What we collect

When you read the site

Cloudflare hosts the site. Like any web host, it records each request with the IP address it came from, the page, the time and the browser’s user-agent string. We don’t use those records to find out who visited.

We use Cloudflare Web Analytics to count visits to each page. It sets no cookies and stores nothing on your device. It reports only totals to us, such as page views, referring sites, countries and browser types.

The site loads its fonts and images from its own domain. The only script from anywhere else is Cloudflare’s analytics script.

When you email us

If you write to hello@probativehq.com, we receive your message, your email address, your name as your email program shows it and anything you attach. We use it to reply, to check whether we’re free to act and, if you engage us, to do the work.

Please don’t send confidential material until we’ve confirmed we’re free to act and agreed terms in writing. Don’t send privileged material at all unless your counsel has engaged us and asks you to.

4. People we send Reads to

A Read goes to the people at a company best placed to judge it, usually the general counsel and the head of external affairs. To send it, we hold each recipient’s name, business email address and company, taken from public sources.

We use those details only to send the Read and to follow up on it. We don’t add recipients to a mailing list or pass their details to anyone, except as section 5 describes. If we talk by phone or video, we take notes and don’t record the call. The notes are kept with the Read and deleted with it.

If you’ve received a Read, a one-line reply asking us to stop is enough. We send nothing more and delete your details. We keep only your email address and the date you asked, so we don’t write to you again. The one exception is the notice in section 5.

5. Who else sees it

  • Cloudflare hosts the site and provides the analytics described in section 3.
  • Google Workspace holds our email, including the email you send us and the email we send you. Google processes it on our behalf.
  • Anthropic’s Claude helps us draft reports, on an account set so that nothing we send is used for training. Material a client sends during an engagement may reach it when we do the work.

Beyond these providers, nobody receives personal information from this site or from email with us. We do publish a response sent to us under our right of reply policy, or a fair summary of it, as that policy describes. Reads aren’t publications, so that policy doesn’t apply to them. We don’t sell personal information, share it for advertising or pass it to data brokers.

We’d disclose information if the law required it, for example under a valid subpoena or court order. If the demand concerns a client’s engagement or a Read, we’ll tell the client, or the company the Read went to, before we disclose anything, unless the law prevents it.

What a client sends us during an engagement is handled as the engagement letter and How engagements work set out.

6. How long we keep it

  • From people who don’t engage us, we keep email, inquiries and our notes of any call for 12 months after our last exchange, then delete them. Notes of a call about a Read are kept with the Read instead, as section 4 describes.
  • Everything a client sends, including the emails it arrives in, is returned or deleted when the work ends, as How engagements work sets out.
  • Read recipients’ details are kept with the Read for 12 months from the day it’s sent, then deleted. Email a recipient sends us before we’re engaged is kept for 12 months after our last exchange, then deleted. If they engage us, it goes with their material when the work ends.
  • If we’ve run a conflict check for you, we keep your name and the matter after everything else about you is deleted, so we can check for conflicts later.
  • If you’ve asked us to stop writing to you, we keep your email address and the date you asked.
  • Once we’ve published a response someone sends us under our right of reply policy, we don’t take it down. If something in it is wrong, write to us. Corrections are dated and noted, as our corrections policy sets out.
  • We keep anything longer only when the law or a legal process requires us to, or an engagement letter provides for it.
  • Cloudflare, Google and Anthropic keep what they process for us. How long is set by their own terms, which we don’t control.

7. Your rights

Wherever you live, you can ask us to tell you what we hold about you, give you a copy, correct it, delete it or stop contacting you. Write to hello@probativehq.com. Apart from the few records section 6 says we keep even then, we delete what we hold about you. We keep it longer only when the law or a legal process requires us to, or an engagement letter provides for it.

We reply within 30 days. We may need to confirm the request comes from you, usually by replying to the address the information is held under. We won’t treat you differently for asking.

Washington residents

Washington’s My Health My Data Act covers consumer health data. We don’t collect it. If you send us health information about yourself outside an engagement, we delete it unused as soon as we notice it.

California residents

The rights above apply to California residents on the same terms. The categories of personal information we collect are identifiers, such as names, email addresses and the company you work for; what you choose to tell us in an email; and, in Cloudflare’s request logs, the network information described in section 3. We share them only as section 5 describes.

No third party collects information through this site about your activity over time or across other websites.

8. Do Not Track

Some browsers send a Do Not Track or Global Privacy Control signal. This site works the same way whether or not your browser sends one. It doesn’t track visitors across sites.

9. Children

This site is written for people at companies in public disputes. It isn’t directed at children, and we don’t knowingly collect personal information from anyone under 16. If you think a child has sent us something, write to hello@probativehq.com and we’ll delete it.

10. Security

The site is served over HTTPS only and has no database or accounts. Apart from Cloudflare’s request logs, it holds nothing about you. Email you send us is held in Google Workspace. We don’t hold a security certification, but if information you sent us were exposed, we’d tell you promptly.

11. Changes to this policy

When what we do changes, we update this page and the date at the top. If we add a form, a cookie or another provider, this page changes before that goes live.

Version history
VersionDateChange
1.0September 30, 2026First published.

12. How to contact us