How Competitive Screening Privacy Works
Effective July 21, 2026 · Break-glass uses since launch: 0
Sponsors on The Token Playbook can build a private watchlist of competitors. This page explains — precisely — who can see what.
What’s sealed
Your watchlist (who you watch and how you’ve tagged them), your tracked topics, your dismissed suggestions, and your email cadence are encrypted before they reach our database. The database stores ciphertext. The decryption key is derived from a secret that exists only in our compute layer — it is not in the database, not in our code repository, and not available to any person’s login.
Who can decrypt
Exactly two automated services: the matcher that builds your feed, and the brief-builder that assembles your email. Both run only in your authenticated context or on your behalf. Every decryption writes a row to an append-only audit log — a log that physically rejects edits and deletions.
What TTP staff can see
That competitive screening is active on your account, how many watchlist slots you’re using, and when your configuration last changed. Billing and support facts. Never the contents. Our admin console has no code path that displays sealed data — it isn’t hidden behind a permission; it was never built.
What we publish
Aggregate statistics only, and only when at least 5 sponsors contribute to a number (for example, “watched by 7 sponsors”). Counts update on a batch schedule so timing can’t reveal individual activity. The complete list of aggregates we compute is:
- Watcher counts per provider (“watched by N sponsors”) — updated weekly, only when at least 5 sponsors contribute.
The honest limit
This is operational blindness with an audit trail, not cryptographic impossibility. An engineer with production deployment rights could, in principle, alter the system to expose data — and would leave audit evidence doing so. Any emergency access to a sponsor’s sealed record (for example, repairing corruption) requires two people’s authorization and generates a notification to that sponsor. It has never been used.
Break-glass uses since July 21, 2026: 0
Positioning battlecards
Battlecards are generated on demand from public Registry data and public signal events. We record that you ran a battlecard (for your monthly meter) but not who it concerned. Battlecard content is generated via Anthropic Claude and is not retained by TTP after delivery.
API access
Pro plan subscribers may access their registry data, own coverage signals, CI feed, and battlecard generation via API key. A key can read only what its owner sees on the dashboard — the same trust boundary applies. Watchlist reads via the API write identical audit records to dashboard reads. No API call reveals who else watches a given provider.
One rule above all
A sponsor’s subscription changes what they see. It never changes what the Registry says about anyone — including them, including us. Vertalo, whose founder operates TTP, receives no exception to any rule on this page.