Privacy Policy
Effective September 30, 2026 · Mintploy, Inc. · Los Angeles, CA
1. Who we are
9ONE0 is a product of Mintploy, Inc. ("we," "us," "our"). We run 9one0.com, where you can run a 9ONE0 Check on a phone number and keep private notes on the people you meet in The Vault. 9ONE0 is built for women and open to anyone 18 or older. Questions: privacy@9one0.com.
2. What we collect
Account. Your email address, the date and time you confirmed you are 18 or older, and, if you choose to give them, your date of birth (used only for star signs) and the green and red flags you choose for yourself.
Before you pay. If you answer our set-up questions and go on to payment, we keep your answers (what you want 9ONE0 for and the flags you picked) and your email. We use them to set up your account after you pay and to send you up to three reminders if you do not finish checking out. We never use them for advertising, and our pages carry no advertising pixels.
Billing. Your Stripe customer ID, your plan, when it renews, how many 9ONE0 Checks you have used this month, and the time you agreed to automatic renewal, if you chose a membership.
9ONE0 Checks. A 9ONE0 Check starts from a phone number you enter, or from a relative listed on a report you ran. What you entered or tapped is sent to our servers and to the data providers in Section 6. The list of people linked to a number you look up is kept for 24 hours, encrypted with a key unique to your account, so opening the same number again that day is free and does not count toward your daily limit. We keep a lookup log, used only to investigate misuse (Section 3): a keyed hash of what you searched and of the record it matched (a one-way code that lets us tell whether two lookups were for the same thing, but not read back what they were), your IP address, the outcome, and the time. The report we build for you is stored, encrypted with a key unique to your account, for up to 12 months, or until you delete it, run a fresh check on the same number, or close your account. While it is stored you can reopen it and save it to a card, and checking the same number again opens it at no charge.
The Vault. Everything you write about a person (their name, number, your notes, dates, flags, what they love, milestones) is stored encrypted under your own key. A report you save to a card is stored with the card. If you ask for a reminder, the person's name and number are stored encrypted until the reminder is sent. We also record which suggestion cards were shown to you and what you did with them (shown, tapped, dismissed), never the person or the flag that prompted them.
Safety contact. If you add one, we store their name and phone number, encrypted under your key. This is someone else's information, so please add only someone who would want to hear from you. We use it only to open your own phone's dialer or messages app, with a text filled in for you to send. We never contact them.
Sign-in codes. When you ask to sign in, we email you a 6-digit code and a link. We store only a keyed hash of the code, never the code itself. It works once and expires after 15 minutes.
3. How we use your information
Your plan and check count decide whether a 9ONE0 Check runs. What you search is used only to build the report you asked for.
The lookup log is read only when we look into misuse. A check that matches a person under 18 pauses the account. The same person looked up more than ten times in thirty days is noted for review and emailed to our operations address.
We use your email for sign-in codes, the reminders you ask for, and messages about your account and billing: your welcome, payment problems, plan changes, and renewal notices. We also send a small number of emails to help you use 9ONE0, for example when your monthly checks are back or when you have not added a safety contact yet, and up to three emails after a membership ends. To stop those, use the link in the email if it has one, or write to privacy@9one0.com and we will turn them off. Emails about sign-in, billing and your account keep coming while you have an account.
We do not sell your information, and we do not use it for advertising or profiling.
4. Payment processing
Payments are processed by Stripe. We never see, receive or store your card number or bank details. Stripe is certified to PCI Service Provider Level 1, and Stripe's privacy policy governs how it handles your payment data.
5. Cookies and browser storage
We use one session cookie ("verity-session") to keep you signed in for up to 30 days. It is secure and httpOnly. If you type a phone number before you have an account, it is held in a second cookie ("verity-pending-phone") for one hour so it is waiting for you after you pay; the page can read it, and it is cleared when used. When you ask for a sign-in code, a third cookie ("verity-signin-device", httpOnly) remembers which browser asked for a sign-in code, so a code only works there. A fourth cookie ("verity-device", httpOnly) holds a random id for this browser once you sign in, so we can email you when your account is signed in from a browser it has not used before; we store only a one-way hash of it, and never your IP address or location. Reports you open are cached in your browser's session storage until you close the tab or sign out. If you pay before you have an account, your browser's local storage remembers that checkout for one hour (the Stripe checkout id and a short code made from your email, not the email itself), so we do not offer you the same payment twice.
We do not use advertising cookies, analytics cookies, advertising pixels or third-party tracking.
6. Data sharing
To build a report we send what you searched to a licensed public records provider (phone, identity, address and property, employment, criminal and sex offender registry, marriage and divorce, and eviction records) and, by name only, to CourtListener (federal court dockets).
We also share data with Stripe (payments), Resend (email delivery), Supabase (our database host) and Vercel (our application host), each under its own privacy terms, and with anyone we are required to share it with by law or valid legal process. Our operations mailbox receives your email address when you create an account and when a lookup pattern is flagged for review.
We do not sell or rent your personal information.
7. Data retention and deletion
Account, billing and Vault data are kept while your account is open. Stored reports are kept for up to 12 months, or until you delete one, run a fresh check that replaces it, or close your account. A report saved to a card is kept with the card. Pick lists expire after 24 hours. Reminders are kept until sent. Sign-in codes and sign-in requests are deleted within a day or two of expiring. The lookup log keeps keyed hashes for 24 months, and IP addresses in it are cleared after 90 days.
You can delete your account at any time in Settings, under Delete account. Deleting it cancels any membership right away, removes your email from your Stripe customer record, and deletes your profile, your cards and notes, your safety contact, your stored reports and pick lists, your reminders, your Wrapped, your suggestion card history, your set-up answers, your sign-in codes, your email history with us, and the key that could decrypt any of it. Unused 9ONE0 Checks end with the account and are not refunded.
A few records stay after deletion: the lookup log and any review flags, with your email replaced by a keyed hash that no one can read back without our secret, so an account cannot be deleted to hide misuse; payment records, which Stripe and we keep as the law requires; and opt-out records (Section 8), which hold only keyed hashes. You can also ask us to delete your account by emailing privacy@9one0.com.
8. Your rights, and opting out
We do not sell your personal information. If you are a California resident, you have the right under the CCPA to know what we collect (Section 2), to delete it (Section 7), and to correct it (in Settings, or by emailing us). To use any of these rights, or to ask what a lookup log entry holds, contact privacy@9one0.com.
If you are someone who was looked up and you would rather not appear in 9ONE0, you can opt out at 9one0.com/opt-out. We confirm the request by email, then keep only keyed hashes of your name and state and of any phone numbers you give. We do not keep your email address. After that, no report is built on you and you are left off our pick lists. 9ONE0 does not hold the underlying public records; our FCRA notice explains where they come from and how to ask the source to correct them.
9. Security
There are no passwords. You sign in with a single-use 6-digit code or link, sent by email, that expires after 15 minutes. Sessions are signed tokens checked on every request. All traffic is encrypted in transit. Vault notes, saved reports, your safety contact and reminders are encrypted at rest with AES-256-GCM under a key unique to your account, which is itself wrapped under a master key that is never stored with the data. Access to your rows in the database is limited to requests made as you.
10. Changes to this policy
If we make material changes to this policy, we will tell you by email before they take effect. If you keep using 9ONE0 after that, the new policy applies.
Questions about this policy? Contact us at privacy@9one0.com. See also our Terms of Service and FCRA Notice.