Privacy and data handling
Your documents are never stored. Files you analyse are read and processed inside your browser. The file itself is never uploaded to our servers.
What we keep when you analyse a file
- File name, size, type and last-modified date. For a file inside an archive (ZIP, TAR, GZ), its path within the archive and a link to the archive's own record. Archives are unpacked in your browser too; their contents are never uploaded
- The file's SHA-256 hash, so you can prove later which exact file was analysed
- The indicators found (for example IP addresses, emails, URLs, domains, hashes, wallet addresses, phone numbers, CVE IDs, user-agent strings, payment card numbers masked in your browser to the first 6 and last 4 digits (the full number is never sent, and it is also masked inside any context snippet), and GPS coordinates from photo EXIF unless you tick "Skip GPS coordinates in photos") with occurrence counts and first/last-seen times
- Only if you tick "Also save short context snippets" on that upload (off by default): up to 3 snippets of about 120 characters of the text around each identifier. This is a small amount of document text. Snippets are encrypted like indicator values, visible only to you (in the indicator detail row), never shown in lists, search, reports or link analysis, and deleted when you delete the source, the case or your account
We do not keep the document or its text. Surrounding context is kept only as the opt-in snippets above; without the tick, none is sent. Our API rejects any request that tries to send document content.
Your account
- Your email, name and organisation, your case titles and descriptions, the indicator values and any opt-in context snippets you save are encrypted at the application level (AES-256-GCM) before they're written to the database. Lookups use keyed hashes, and searches decrypt only your own indicators in memory. File names and hashes of sources are not app-encrypted.
- Passwords are stored as salted, peppered PBKDF2 hashes. Optional two-factor authentication (authenticator app) is available on the Security page.
- Passwords are stored as salted PBKDF2-SHA256 hashes. New passwords are checked against known breaches using a k-anonymity range query, so your password never leaves our server.
- Sessions use a secure, httpOnly, SameSite=Strict cookie. They end after 30 minutes of inactivity or 12 hours at most.
- Sign-ins, failed sign-ins, lockouts and admin actions are recorded in an audit log.
Retention
- Unverified accounts are deleted after 14 days.
- Expired sessions and one-time links are purged daily.
- Audit log entries are kept for about 13 months.
- Archived cases are deleted after 12 months. You can delete a case, a source or your saved indicators at any time.
Third parties
Cloudflare hosts the site, API and database. Resend delivers transactional email. Stripe handles Alpha Access checkout (we never see card numbers). Google AdSense shows one ad on some public pages; there are no ads in the app or on plans or sign-up pages.
Not CJIS compliant
These controls are groundwork only. Project Revelare is not CJIS compliant and must not be used for Criminal Justice Information.
Full details are in the Privacy Policy. Questions or deletion requests: use Report a bug while signed in, or reply to any email from us.