Privacy and data handling
Your documents are never stored. Files you analyse are read and processed inside your browser. The file itself is never uploaded to our servers.
What we keep when you analyse a file
- File name, size, type and last-modified date
- The file's SHA-256 hash, so you can prove later which exact file was analysed
- The indicators found (for example IP addresses, emails, URLs, domains, hashes, wallet addresses, phone numbers, CVE IDs) with occurrence counts
We do not keep the document, its text, or surrounding context. Our API rejects any request that tries to send document content.
Your account
- Your email, name and organisation are encrypted at the application level (AES-256-GCM) before they're written to the database. Email lookups use a keyed hash.
- Passwords are stored as salted PBKDF2-SHA256 hashes. New passwords are checked against known breaches using a k-anonymity range query, so your password never leaves our server.
- Sessions use a secure, httpOnly, SameSite=Strict cookie. They end after 30 minutes of inactivity or 12 hours at most.
- Sign-ins, failed sign-ins, lockouts and admin actions are recorded in an audit log.
Retention
- Unverified accounts are deleted after 14 days.
- Expired sessions and one-time links are purged daily.
- Audit log entries are kept for about 13 months.
- Archived cases are deleted after 12 months. You can delete a case, a source or your saved indicators at any time.
Third parties
Cloudflare hosts the site, API and database. Resend delivers transactional email. Stripe handles Alpha Access checkout (we never see card numbers). Google AdSense shows one ad on some public pages; there are no ads in the app or on plans or sign-up pages.
Not CJIS compliant
These controls are groundwork only. Project Revelare is not CJIS compliant and must not be used for Criminal Justice Information.
Full details are in the Privacy Policy. Questions or deletion requests: use Report a bug while signed in, or reply to any email from us.