generated: '2026-08-13' method: searched source: https://choozle.com/privacy-policy/ also_derived_from: - openapi/_original/openapi.yml - live probes of https://app.choozle.com/api/* on 2026-08-13 summary: >- Choozle conforms to no cross-cutting API standard — auth is a bespoke HMAC handshake rather than OAuth 2.0 or OIDC, errors are a bare string envelope rather than RFC 9457, and there is no OpenAPI, discovery document or event spec published by the provider. Its real conformance story is on the advertising-privacy side: Choozle publishes adherence to the NAI Code, the DAA Self-Regulatory Principles, GDPR and CCPA, and offers a Data Processing Agreement. standards: - id: oauth2 conforms: false evidence: >- No oauth2 security scheme. Auth is a custom HMAC-SHA256 signed handshake returning a two-hour opaque token carried in a `token` header. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 404 on app.choozle.com. - id: rfc6750-bearer-token conforms: false evidence: >- The credential is sent in a custom `token` header, not Authorization: Bearer. - id: rfc8414-oauth-authorization-server-metadata conforms: false evidence: /.well-known/oauth-authorization-server returns 404 on app.choozle.com. - id: rfc9457-problem-details conforms: false evidence: >- Errors are application/json with the shape {"error": ""}, not application/problem+json. Observed live on 2026-08-13. - id: rfc9116-security-txt conforms: false evidence: >- /.well-known/security.txt returns 404 on app.choozle.com and a soft-404 HTML page on choozle.com. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header support and no deprecation policy published. - id: rfc9110-conditional-requests conforms: partial evidence: >- The static apiDoc assets serve ETag and Last-Modified, but the API endpoints under /api do not. - id: openapi conforms: false evidence: >- Choozle publishes no OpenAPI. Its machine-readable contract is an apiDoc 0.13.1 dataset at https://app.choozle.com/apidoc/api_data.json. The OpenAPI documents in this repository are an API Evangelist transcription of that dataset, not a provider artifact. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface is published. - id: graphql conforms: false evidence: No GraphQL endpoint found on any Choozle host. - id: mcp conforms: false evidence: No MCP server published or discoverable. - id: a2a conforms: false evidence: >- No agent card at /.well-known/agent-card.json or /.well-known/agent.json on any host. - id: json-api conforms: false evidence: Plain JSON arrays and objects; no JSON:API document structure. - id: odata conforms: false - id: scim2 conforms: false - id: pagination conforms: false evidence: No limit/offset/page/cursor parameter on any operation. - id: idempotency conforms: false evidence: No idempotency key documented; the only write is the token exchange. - id: https-only conforms: true evidence: All hosts serve HTTPS over TLS 1.3 with HTTP/2. - id: iso8601-dates conforms: true evidence: >- Report dates and the auth timestamp are ISO 8601; the auth timestamp is documented with an explicit offset form (2015-05-04T11:34:02-06:00). compliance_program: published: true url: https://choozle.com/privacy-policy/ note: >- Choozle publishes an advertising-industry privacy compliance posture rather than a security certification posture. No SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP claim is published anywhere on the Choozle site, and there is no trust center. programs: - id: nai-code name: Network Advertising Initiative Code of Conduct claim: >- Choozle states it discloses standard interest segments based on health-related or political information as required under the NAI Code, and references the NAI's Viewed Content Advertising Guidance. evidence: https://choozle.com/privacy-policy/ - id: daa-self-regulatory-principles name: Digital Advertising Alliance Self-Regulatory Principles for Online Behavioral Advertising claim: Choozle states it complies with the DAA Self-Regulatory Principles. evidence: https://choozle.com/privacy-policy/ - id: gdpr name: EU General Data Protection Regulation claim: >- Choozle publishes a GDPR statement and a Data Processing Agreement, and commits to notifying the controller within 72 hours of becoming aware of a personal-data breach. evidence: - https://choozle.com/data-processing-agreement/ - https://choozle.com/wp-content/uploads/Choozle_GDPR.pdf - id: ccpa name: California Consumer Privacy Act claim: Choozle publishes a California Privacy Statement and a CCPA knowledge-base article. evidence: - https://choozle.com/privacy-policy/ - https://help.choozle.com/california-consumer-privacy-act-ccpa - id: iab-europe-opt-out name: IAB Europe industry opt-out claim: Choozle references the IAB Europe opt-out for EEA residents. evidence: https://choozle.com/opt-out/ certifications: [] certifications_note: >- No third-party audited certification (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP, CSA STAR) is published. The programs above are self-declared adherence to industry codes and privacy regulation, which is a real and checkable published posture but is not an audit.