privacy · what we hold

The audit asks to read your public web presence. That is a bigger ask than a contact form, so this page answers it straight: what we take, who touches it, when it disappears.

last updated 11 August 2026

01 · who we are

Engram is the controller of the data on this site.

Engram is a creative studio that installs and operates media departments inside B2B companies. We decide what data this site collects and why, which makes us the data controller for it.

For anything on this page, including deletion requests, write to hello@engram.media and a person will answer.

02 · visiting the site

Reading the site leaves the usual traces.

Our host records standard server logs: IP address, browser and device type, the page requested, and the time. We use analytics to understand which pages get read and where readers arrive from.

We do not require an account to read anything here, and we do not ask for personal information to read the journal, the case studies, or any of the service pages.

03 · the audit

The audit collects what you type and, with your consent, reads what you publish.

The audit questionnaire asks for your name, work email, company, your role, and a set of answers about how your media gets made: what you sell, who buys it, your revenue band, team size, where the work gets stuck, who approves it, and what you want to change in the next ninety days. It also takes your website and, optionally, links to the places you publish and the places people talk about you.

On the last page we ask for two separate consents, and neither is ticked for you. The first lets our agents read your public web presence. The second lets us give you our own opinion on what we read. You can submit the audit without either. If you do, the report is built from your answers alone and will contain no traffic, social, reputation or competitor data.

We also record the IP address the submission came from and, if you arrived from an ad, the campaign identifiers that came with the click.

04 · what the scan reads

Public sources only, and only the ones you point us at.

With your consent, the audit reads publicly available information about your company: your homepage, the social profiles you name, public review listings, third-party traffic estimates, and public company records. It reads one competitor only if you name one. It does not access anything private, log into anything, or read anything behind a password.

Your answers decide where we look. Surfaces you do not tick are not fetched.

05 · why, and on what basis

What we rely on to process each thing.

Running the audit you asked for, replying to your enquiry and sending your report: we do this because you asked us to, as steps taken at your request before any engagement, and because we have a legitimate interest in answering people who approach us.

Reading your public web presence, and giving you our opinion on it: consent. These are the two tickboxes on the last page of the audit, and they are separate. You can withdraw either by writing to us, and we will delete what the scan produced.

Analytics and advertising measurement: legitimate interest in understanding which pages are read and which campaigns produce enquiries. You can block this at the browser, and we describe how below.

Keeping records of who we have spoken to: legitimate interest in running a business and honouring our obligations.

06 · who else processes it

The processors, and what each one sees.

We use third parties to run the site, read public sources, write the report and contact you. Each sees only what it needs to do its job.

Vercel
hosting and server logs for engram.media.
Upstash
encrypted storage of audit submissions and reports.
Firecrawl
reads your homepage when you consent to the scan.
Outscraper
public company, social and review listings: Crunchbase, LinkedIn, Instagram, Google Reviews, G2, Trustpilot, Reddit.
SimilarWeb
third-party traffic estimates for your domain and any competitor you name.
Anthropic
the language model that writes the report from your answers and the public data. It is not used to train models.
Resend
sends your audit code, the report link and follow-up email.
Close
our CRM, where your enquiry is recorded so we can reply.
Google Analytics, Meta, LinkedIn, PostHog
traffic and advertising measurement. See cookies below.

07 · cookies and measurement

Analytics and advertising cookies, and what we send to ad platforms.

This site sets cookies for Google Analytics (_ga), the Meta pixel (_fbp, _fbc) and the LinkedIn Insight Tag (li_fat_id), and uses PostHog for product analytics. They tell us which pages are read and which campaigns produce enquiries.

When you complete the audit we report a conversion to Meta and LinkedIn. Your email address is hashed with SHA-256 before it is sent, so those platforms receive an irreversible fingerprint rather than your address. Meta events are sent with the Limited Data Use flag set.

You can block these with your browser's tracking protection or an ad blocker, and the site works normally without them. If you would rather we deleted analytics data already associated with you, write to us.

08 · where it goes

Your data is processed outside the UK and EEA.

We are a small studio using services that run in the United States and elsewhere. Storage, hosting, the language model, email, the CRM, the public-source lookups and the advertising platforms above all process data outside the UK and EEA.

Where we transfer personal data out of the UK, the EEA or Switzerland, we rely on the Standard Contractual Clauses adopted by the relevant authority, together with the safeguards each provider offers, as the appropriate mechanism for that transfer.

09 · how long we keep it

Everything expires on a timer, not on a promise.

Retention is enforced by the storage itself, so it happens whether or not anyone remembers to run a cleanup.

Audit submission and report
90 days, then deleted automatically.
Processing records for a submission
30 days.
Follow-up and re-audit records
30 days.
Server and analytics logs
as set by the providers above.
CRM records
kept while we are in contact, and deleted on request.

10 · automated processing

The audit scores you, and we would rather say so.

The audit is run by software. It reads your answers and the public data, gives your media operation a score, sorts it into a band, and suggests which of our next steps fits. That is automated processing, and it is profiling: it is worth knowing that a machine formed a view of your company.

It does not make a decision with a legal or similarly significant effect on you. Nothing is approved, refused, priced or withheld automatically. A person reads the result before we act on it, and a person runs any conversation that follows.

You can ask what the automated part concluded about you, ask a person to look at it again, or disagree with it. Write to us and we will show you.

11 · your choices

You can ask for a copy, a correction, or a deletion.

Write to hello@engram.media with the audit code from your report, or the email address you used, and we will find your record. You can ask us to send you what we hold, correct it, or delete it. We will not charge you and we will not ask why.

Deleting an audit deletes the stored answers and the report together, so the report link and the code stop working.

If you are in the UK or the EU, you also have the right to object to processing and to complain to your national data protection authority.

12 · california and other US states

We do not sell your personal information, and never have.

If you live in California, or in another US state with a comparable privacy law, you have the right to know what personal information we hold about you, to have it deleted, to have it corrected, and to opt out of its sale or of sharing it for cross-context behavioural advertising. Exercising any of them costs you nothing and we will not treat you differently for it.

We do not sell personal information and we do not accept money for sharing it. We do report conversions to Meta and LinkedIn for advertising measurement, with your email hashed, and some US state laws treat that kind of sharing as a sale even where no money changes hands. If you would rather we did not, tell us and we will exclude you, or block the cookies in your browser and it will not happen.

To exercise any of these, write to hello@engram.media. We may need to confirm you are who you say you are before we act, which for an audit usually means replying from the address you used.

13 · security

Audit answers are encrypted before they are stored.

Audit submissions are encrypted with a secret key before they are written to storage, and decrypted only to render your report. The key is held in our deployment environment, not in the database and not in this repository.

No system is perfect. If you believe you have found a security problem with this site, write to hello@engram.media and we will take it seriously.

14 · the rest

Children, changes, and where to reach us.

This site is aimed at businesses. It is not directed at children and we do not knowingly collect their data.

If we change what we collect or who processes it, this page changes with it, and the date at the top moves. Material changes to how the audit handles your data will be explained here rather than buried.

Questions, requests, or corrections to this page: hello@engram.media.