Legal

Privacy Policy

Last updated 2026-08-11
This page explains what we collect when you run a scan, create an account, buy an Evidence Pack or subscription, or join the mailing list; how long we keep it; who else processes it; and how to ask us to delete it. It is written in plain language rather than legal boilerplate; see the Disclaimer for what a scan is (and isn't).

What we collect

If you join the launch list: your email address, plus the timestamp, browser user-agent, referring page, and country your request came from (standard anti-abuse signals). We use double opt-in: you'll get a confirmation email and nothing is added to the active list until you click it. Unconfirmed signups are inert and are periodically cleared.

If you run a scan: the URL you submit; your IP address and, if you provide one, your email address, used only to enforce the free daily scan limits described in our Terms of Service and to fight abuse; and a one-time Turnstile (Cloudflare's CAPTCHA alternative) verification token. We do not require an account or email to run a free scan.

What a scan captures: we load the public homepage of the URL you submit in a real browser and record what's visible there: screenshots (desktop and mobile), the rendered page HTML, the list of network hosts and requests the page made, and, if a chat widget is present, a screenshot and text capture of its first message. This is the "evidence" a report is built from. Because it's whatever is publicly visible on that page, it may incidentally include names or other details the page owner has chosen to display publicly (for example, in chat-widget branding). We only use it to generate and, if you request it, deliver your report.

If you create an account: your email address and, if you set a password, a salted hash of it — we never store the password itself, and magic-link sign-in works without one. Your account also records your plan and links to your verified sites, purchases, and monitors. If you turn on monitoring for a verified site, we additionally store that monitor's settings (which site, how often, which checks) and the before/after change events it detects.

If you buy something: payment is handled by Stripe as Merchant of Record — your card number and billing details go to Stripe directly and never touch our servers. We keep the purchase record itself: the product, amount, currency, status, purchase time, the email it belongs to (and your account, if you were signed in), plus reference IDs for the Stripe transaction.

We only fetch what's public

DisclosureProof fetches publicly accessible pages only. We do not accept credentials, do not access anything behind a login, and reject private, local, or otherwise non-public addresses at intake. The free scan is limited to the homepage of the URL you submit; if we ever crawl beyond that single page, we respect that site's robots.txt, identifying ourselves with our own user-agent so a site owner can always see and control what we fetch.

How long we keep it

You can ask for anything of yours to be deleted sooner; see "Your choices" below.

We do not sell scan data

We do not sell, rent, or otherwise trade scan results, waitlist emails, or any other data we collect. Aggregated, non-identifying statistics (for example, "N scans run this month") may be used internally or shared publicly, but never in a way that identifies a specific submitter or target site.

Who else processes it (sub-processors)

Cookies

We don't set first-party tracking cookies of our own. A cookie banner asks before any Google Analytics cookie is set: reject and no analytics cookies are set; accept and gtag.js sets its standard analytics cookies/identifiers to measure aggregate traffic — including on the authenticated dashboard once you have an account. Your choice is remembered in your browser's local storage. Alongside it, Cloudflare Web Analytics measures page views cookielessly and stores no identifier in your browser, so it needs no consent gate. Separately, Cloudflare Turnstile may set a technical cookie or use local storage to complete its bot-verification challenge on the scan page — this is strictly necessary to run the free scan and isn't gated by the analytics choice above. None of this is used to build an advertising profile of you.

Who we are (data controller)

DisclosureProof is an independent service operated by Alena Milan, based in the United States. Throughout this policy, "we," "us," and "DisclosureProof" refer to that operator, who is the data controller for personal data processed through this site under the EU General Data Protection Regulation (GDPR) and the UK GDPR. You can reach us here:

Alena Milan
DisclosureProof
1832 Kempsville Rd, Ste 112 #520
Virginia Beach, VA 23464
United States
hello@disclosureproof.com

Your choices

Email hello@disclosureproof.com to: remove a waitlist entry, request early deletion of a scan record (include the scan URL or ID from your report link), or ask what data we hold about you. We'll act on deletion requests as soon as we reasonably can.

If you're in the EU/EEA or the UK, you also have the right to lodge a complaint with your local data protection authority, though we'd appreciate the chance to put things right directly first.

Changes to this policy

If we materially change what we collect or how long we keep it, we'll update this page and the "last updated" date above. This policy describes the feature set that is live today — free scans, accounts, Evidence Pack purchases and subscriptions, and site monitoring — and will be extended as new features ship.

See also: Terms of Service and the Disclaimer. This page is informational and not legal advice.