Data Transparency

BackNova PII-0 Architecture — What we collect, what we don't, and how to verify.

✓ PII-0 Compliant

Zero Personally Identifiable Information

BackNova is designed from the ground up to make decisions without ever seeing, storing, or processing personal data. All identifying information is hashed client-side before transmission.

What We Collect

BackNova collects 47 behavioral and technical signals to evaluate lead quality. None of these are personally identifiable.

Behavioral Signals (15)

SignalDescriptionPII?
time_on_site_secSeconds spent on page✓ No
scroll_depth_pctHow far user scrolled (%)✓ No
page_viewsNumber of pages viewed✓ No
mouse_distanceTotal mouse movement (px)✓ No
clicksNumber of clicks✓ No
rage_clicksFrustration click patterns✓ No
form_completion_secTime to fill form✓ No
form_changes_countForm field edits✓ No
engagedUser engagement flag✓ No
returning_visitorHas visited before✓ No
fast_scrollBot-like scroll pattern✓ No
keystrokesKeyboard activity count✓ No
paste_eventsCopy-paste usage✓ No
tab_switchesTab focus changes✓ No
touch_eventsMobile touch count✓ No

Technical Signals (10)

SignalDescriptionPII?
user_agentBrowser identification string✓ No
browserBrowser name (Chrome, Firefox)✓ No
device_typedesktop / mobile / tablet✓ No
screen_resolutionScreen size (1920x1080)✓ No
viewport_sizeBrowser window size✓ No
languageBrowser language (en-US)✓ No
timezoneTimezone (Europe/London)✓ No
platformOS (Windows, macOS)✓ No
cookies_enabledCookie support flag✓ No
do_not_trackDNT header status✓ No

Traffic Source Signals (8)

SignalDescriptionPII?
utm_sourceTraffic source (google, facebook)✓ No
utm_mediumTraffic medium (cpc, email)✓ No
utm_campaignCampaign name✓ No
utm_termSearch keyword✓ No
utm_contentAd content variant✓ No
click_idTracker click ID for postback matching✓ No
referrerPrevious page URL✓ No
urlCurrent page URL✓ No

Hashed Identifiers (4)

SignalDescriptionPII?
session_idRandom session identifier✓ No
browser_fingerprintSHA-256 hash of browser config✓ No
email_hashSHA-256 hash of email (for AI learning)✓ No*
ip_hashSHA-256 hash of IP (for fraud detection)✓ No*

* Email and IP are hashed for AI learning and fraud detection. We also extract email domain and GEO (country) — these are not PII.

What We NEVER Collect

Plain text email addresses
Plain text phone numbers
Names (first, last, full)
Physical addresses
Credit card or payment information
Social security numbers
Government IDs
Passwords or credentials
Any other personally identifiable information

How Data Flows

1. Lead Data → Directly to Your PP

When a user submits a form, their lead data (name, email, phone) goes directly to your PP/broker via the route URL you configured. BackNova never stores this raw data.

// What happens: // 1. User submits: name, email, phone // 2. BackNova routes directly to your PP: // https://broker.com/[email protected]&phone=+1234567890 // 3. We only store hashes for AI learning

2. Hashes for AI Learning

For AI to learn from conversion patterns, we store SHA-256 hashes of email and IP. These cannot be reversed to reveal the original data.

// What we store: const stored = { email_hash: "a7f3b2c1...", // SHA-256(email) email_domain: "gmail.com", // For pattern analysis ip_hash: "b8d4e5f6...", // SHA-256(IP) - fraud detection geo: "US" // Country code only };

3. Your Tracker Data Stays Private

We only capture click_id from your tracker URL. Your sub IDs, pub IDs and other tracking parameters stay in your tracker — we don't see or store them.

4. Open Source SDK

Our SDK source code is publicly available. You can inspect exactly what data is collected and how it's processed.

View SDK Source Code →

Verify Yourself

Open your browser's Developer Tools (F12) → Network tab → Filter by "backnova" or "decision" to see exactly what data is being sent.

Real-time Data Inspector

If you have BackNova SDK installed, run this in your browser console:

BackNova.getPII0Report()

This will show you exactly what data is collected and confirm PII-0 compliance.

Compliance

Third-Party Audits

We welcome independent security audits of our SDK and infrastr