MEET FINGERLYA clearer picture of every session.Explore the signals
Privacy by design

Device intelligence with boundaries.

Recognising devices is sensitive work. These are the boundaries built into the product, and the work that is still in progress, stated plainly so you can plan a responsible implementation.

  • No promptsVisitors are never interrupted.
  • No cookiesNothing written to the device.
  • Scoped IDsNever shared across customers.
  • ExplainableEvery score lists its reasons.
Privacy by design

Collect what the device says about itself. Nothing about the person. The SDKs read characteristics of the device and browser to recognise it and to tell whether it is being misrepresented. They do not read what a person writes, clicks or keeps on the device.

  • No page content, form fields or keystrokes
  • No mouse movement or session recording
  • No clipboard, contacts, photos or location services
  • No advertising or marketing use of any kind

Boundaries in the product.

Each of these is a property of the code, not a policy to remember.

Never asks, never interrupts

No permission prompt, picker or dialog on any platform. The rule is enforced by tests in every SDK.

Nothing stored on the device

No cookies, local storage or IndexedDB entries of its own. There is no Fingerly cookie for your notice to list.

Identifiers stay with you

A visitor ID belongs to one organisation. There is no cross-customer identity graph, and visitor data is never sold or shared.

Networks are not identities

The IP address is used for network signals and never to decide who a visitor is.

Hardened browsers respected

Browsers that randomise their characteristics are not turned into a new visitor on every page load.

Assistive technology is not suspicious

Accessibility services are never counted as a sign of automation.

Every score can explain itself.

If you use a score to refuse a signup or hold a payment, the person affected may be owed an explanation. Every assessment is stored with the signals that fired, the weight each was given, its confidence, and the threshold in force at the time.

Privacy tools are treated as context, not guilt: a VPN, a private window or a privacy-focused browser ships with a small weight, and no single signal is designed to decide an outcome on its own.

  • Signals, weights and confidence stored per assessment
  • Weights and thresholds under your control
  • The API never blocks a person by itself

Security for the data we hold.

What protects credentials and visitor data today.

Hashed credentials

SDK key secrets are stored as keyed hashes and shown once. A copy of the database holds no usable keys.

Regional data planes

Visitor data lives in the region chosen for the organisation, separate from accounts and billing.

Data residency

Least-privilege roles

Owners, admins, developers and billing members each get only what their work needs.

Access controls

What is still being built.

You should know the gaps before you promise anything in your own privacy notice. These are open today, and they are stated here rather than left for you to discover.

  • There is no consent option in the SDKs yet, so gate initialisation on the basis you decided on
  • Erasure requests are handled on request by the team, not through a self-service API
  • Retention limits for the device identity index and the full event archive are not yet in place
  • No privacy or security certification is claimed

You are the controller for your visitors’ data. Your notice, legal basis and any consent are yours to decide. Have your privacy and legal teams review the implementation.

[ IDENTIFY ][ UNDERSTAND ][ DECIDE ][ FINGERLY ]
Less guessing. More knowing.

Make the next connection a trusted one.

Start with the signals, keep your own decisions, and pay only for what you identify. No credit card needed.