Waitlist privacy

Last updated: July 24, 2026.

Palette is a product of Isotropic, Inc. This notice covers Palette’s public waitlist. For information about the rest of Palette, see our Privacy Policy. You can review or change optional public-site measurement through the Cookiebot privacy trigger shown in the lower-left corner.

Information we collect

We collect your email address, where on our public site your signup began, and whether your receipt was accepted for delivery. We also process short-lived identifiers to prevent abuse. We do not store raw IP addresses in the waitlist database.

If you allow Statistics, Microsoft Clarity can process cleaned public-page URLs, origin-only referrers, clicks, pointer movement, scrolling, page structure, diagnostic events, and device, browser, network, IP address, and IP-derived approximate location information. If you allow Marketing, Google Ads can process the eligible public page, device, browser, network, timestamp, consent state, and a validated GCLID when present. Google receives a conversion event only for a backend-confirmed new signup completed while that purpose is allowed. LinkedIn Ads can receive similar technical information, IP address, URL and origin-only referrer, a LinkedIn ad-click identifier such as LI_FAT_ID when present, cookies, and, in supported regions, a first-party pseudonymous LinkedIn Ads ID (LI_ADSID). Its Website Actions capability can also classify page visits, button clicks, and form submissions using limited page structure such as page or button names, button click-or-view state, and a session-unique action hash. LinkedIn states that this classification data does not include form-field values. LinkedIn receives the selected conversion event only for a backend-confirmed new signup completed while Marketing is allowed. Palette does not pass the submitted email through either provider's conversion command or user-data API.

If Marketing is allowed, Palette can also save the first approved campaign or ad-click identifiers, landing path, and external referring host in this browser tab. If you then join the waitlist, those attribution values are submitted to Palette with the signup and stored on the waitlist record. They help us connect a signup to the campaign that brought the visitor to Palette.

How we use information

We use this information only to confirm your signup, tell you when it is your turn to access Palette, operate the waitlist, and prevent abuse. With the relevant optional consent, we use masked behavioral analytics to improve the public waitlist experience and campaign attribution to understand which Palette ads result in signups. We do not use waitlist information for newsletters, product news, research recruitment, fundraising, sale, unrelated marketing, remarketing, or personalized advertising.

Service providers

Amazon Web Services provides hosting and email delivery. Cloudflare provides abuse prevention, and Google provides our contact inbox. They process information under their own security and retention practices.

After Statistics consent, Microsoft Clarity provides heatmaps, behavioral analytics, diagnostics, and reconstructed session replays. Before this feature is enabled, Palette's release gate requires Clarity's Strict masking mode. The waitlist form also carries Clarity's data-clarity-mask control so its contents, including your email address, are excluded from replay. Masking does not cover every item: page and referring URLs, and link text and destination URLs associated with clicks, can remain available to Clarity. Palette removes approved campaign parameters and fragments before any optional vendor starts, except for the validated, consented LI_FAT_ID exposure to LinkedIn described below, and leaves optional measurement off when an incoming referrer contains more than its origin.

Cookiebot's built-in Microsoft consent mapping uses Statistics to control Clarity analytics storage and Marketing to control Clarity advertising storage. Palette withholds the Clarity tag before the relevant optional consent and on ineligible routes. After Statistics consent, Clarity can use first- and third-party analytics cookies for session continuity. Palette and Microsoft act as independent controllers under the Microsoft Clarity Terms. Microsoft may independently use and process the data, including in the United States, as described in the Microsoft Privacy Statement.

With Marketing allowed, Clarity may share data with Microsoft Advertising for advertising measurement and optimization. If you later withdraw Statistics after Clarity has loaded, Cookiebot sends a denied analytics-storage signal. Clarity then stops cookie-based analytics and full features such as session replay, but Microsoft states that the loaded tag can continue sending limited cookieless data. Denying Marketing prevents Clarity from sharing data with Microsoft Advertising.

After Marketing consent, Google Ads provides campaign measurement. We use Google's Basic Consent Mode and do not load its tag or send cookieless advertising pings before consent. Cookiebot's built-in Google consent mapping uses Marketing to control ad storage, advertising user-data processing, and ad personalization signals. Statistics controls analytics storage. Palette currently uses Google Ads for campaign conversion measurement, not remarketing audiences or personalized advertising. Read the Google Privacy Policy and Google's explanation of how it uses information from sites that use its services.

If you later withdraw Marketing after the Google tag has loaded, Cookiebot sends denied ad-storage, advertising user-data, and ad-personalization signals. Palette does not send another waitlist conversion, and Google may not use advertising cookies, advertising user data, or personalized advertising under those denied states. Google states that an already-loaded tag can still send the consent state and limited measurements without cookies.

After Marketing consent, LinkedIn's Insight Tag provides campaign measurement. Palette withholds the tag before that affirmative choice, loads it only on approved public marketing routes, and sends a conversion only for a backend-confirmed new waitlist signup. After consent, Palette briefly restores only a validated LI_FAT_ID to the cleaned URL while the tag executes, then removes it; other campaign parameters remain removed. We do not send your waitlist email or other form-field values to LinkedIn, and this implementation does not use Enhanced Matching or LinkedIn's user-data API. The Insight Tag can support audience insights, website retargeting, and auto-created Website Actions conversions. Palette does not create or activate Matched Audiences from these signals and selects only the explicit backend-confirmed waitlist conversion for this campaign. If you withdraw Marketing after the tag executes, Palette stops new LinkedIn calls and reloads the page to remove the vendor runtime; a fresh document does not load the tag unless Marketing remains allowed. Read LinkedIn's LinkedIn Privacy Policy and Cookie Policy.

Your measurement choices

Usercentrics' Cookiebot consent-management platform controls optional technologies on Palette's reviewed public and privacy routes. The browser requests Cookiebot from consent.cookiebot.com on those routes so the consent interface can load before optional services. It is absent from product, account, participant, preview, tokenized, API, and unknown routes. Cookiebot uses four standard categories: Necessary, Preferences, Statistics, and Marketing. Necessary is always active. The other categories are off by default worldwide until you allow them.

Cookiebot stores the current domain's consent state in the necessary first-party CookieConsent cookie for up to 12 months. Its consent log records an encrypted consent ID, timestamp, consent state, submission URL, browser user agent, and a shortened form of the IP address. The record documents the choice and is retained for 12 months.

Where data protection law requires a legal basis, Palette relies on your consent for optional technologies. We apply the same prior-choice standard worldwide as a product rule. Refusing or withdrawing Preferences, Statistics, or Marketing does not affect the essential waitlist experience or the lawfulness of processing completed before withdrawal.

The public waitlist (/waitlist) is eligible for optional Clarity, Google Ads, LinkedIn Ads, and browser attribution after the corresponding consent. The same reviewed public-page rule covers the Blog index (/blog) and each published Blog guide listed there. This notice (/waitlist/privacy) can load Cookiebot so you can manage a choice, but remains ineligible for optional measurement. Unknown Blog URLs, the leave-waitlist page (/waitlist/leave), product, account, participant, preview, tokenized, API, and every other unlisted or noncanonical route are excluded from Microsoft Clarity, Google Ads, LinkedIn Ads, and browser attribution. Unknown query parameters also disable optional measurement. Use the Cookiebot privacy trigger shown in the lower-left corner to review, allow, refuse, or withdraw an optional category. A change applies to future optional processing. It does not retroactively remove attribution already submitted with a waitlist signup; leaving the waitlist deletes the live signup record.

Leaving and retention

Every waitlist email includes a link to leave. Using it deletes your live waitlist record immediately. Otherwise, we keep your record while the access program is active and delete remaining records within 12 months after it ends. Backups, security logs, and provider records expire under their own retention schedules.

Consented first-touch campaign information is kept in session storage for the browser-tab session and is cleared sooner if Marketing is no longer allowed. Attribution already submitted with a signup is retained with the live waitlist record under the deletion schedule above; withdrawing measurement consent does not delete that submitted copy. Microsoft's published Clarity schedule keeps ordinary replay data for 30 days. Labeled or favorited sessions, a limited recording sample, and click and heatmap aggregates can remain for up to nine months. Microsoft states that a specific visitor's Clarity data cannot be deleted without deleting the entire project.

Palette retains historical public-site measurements already in its current Clarity project and lets them expire under that schedule. Withdrawing Statistics stops future cookie-based analytics and full Clarity features, including session replay, but an already-loaded tag can continue limited cookieless measurement under the denied state. Google and LinkedIn retain information already received according to their own policies and controls. Withdrawal does not retroactively delete provider history.

Contact

Send waitlist privacy questions or requests to waitlist@palettelabs.ai.

Isotropic, Inc.
2810 N Church St STE 88937
Wilmington, DE 19802
United States