Privacy Policy
What we collect
If you join the launch list: your email address, plus the timestamp, browser user-agent, referring page, and country your request came from (standard anti-abuse signals). We use double opt-in: you'll get a confirmation email and nothing is added to the active list until you click it. Unconfirmed signups are inert and are periodically cleared.
If you run a scan: the URL you submit; your IP address and, if you provide one, your email address, used only to enforce the free daily scan limits described in our Terms of Service and to fight abuse; and a one-time Turnstile (Cloudflare's CAPTCHA alternative) verification token. We do not require an account or email to run a free scan.
What a scan captures: we load the public homepage of the URL you submit in a real browser and record what's visible there: screenshots (desktop and mobile), the rendered page HTML, the list of network hosts and requests the page made, and, if a chat widget is present, a screenshot and text capture of its first message. This is the "evidence" a report is built from. Because it's whatever is publicly visible on that page, it may incidentally include names or other details the page owner has chosen to display publicly (for example, in chat-widget branding). We only use it to generate and, if you request it, deliver your report.
If you create an account: your email address and, if you set a password, a salted hash of it — we never store the password itself, and magic-link sign-in works without one. Your account also records your plan and links to your verified sites, purchases, and monitors. If you turn on monitoring for a verified site, we additionally store that monitor's settings (which site, how often, which checks) and the before/after change events it detects.
If you buy something: payment is handled by Stripe as Merchant of Record — your card number and billing details go to Stripe directly and never touch our servers. We keep the purchase record itself: the product, amount, currency, status, purchase time, the email it belongs to (and your account, if you were signed in), plus reference IDs for the Stripe transaction.
We only fetch what's public
DisclosureProof fetches publicly accessible pages only. We do not accept credentials, do not access anything behind a login, and reject private, local, or otherwise non-public addresses at intake. The free scan is limited to the homepage of the URL you submit; if we ever crawl beyond that single page, we respect that site's robots.txt, identifying ourselves with our own user-agent so a site owner can always see and control what we fetch.
How long we keep it
- Free scans (today, every scan): the scan record and its captured evidence (screenshots, DOM, findings) are retained for 7 days, then automatically and permanently deleted, including the underlying files.
- Pro subscribers: scans linked to a site on your account are retained for 90 days while the subscription is active.
- Evidence Pack purchases: the purchased scan and its sealed evidence are retained for 1 year from purchase.
- Business subscribers: evidence is retained for the life of your subscription, with export available at any time.
- Waitlist entries: kept until launch communications are complete or you ask us to remove you, whichever comes first.
You can ask for anything of yours to be deleted sooner; see "Your choices" below.
We do not sell scan data
We do not sell, rent, or otherwise trade scan results, waitlist emails, or any other data we collect. Aggregated, non-identifying statistics (for example, "N scans run this month") may be used internally or shared publicly, but never in a way that identifies a specific submitter or target site.
Who else processes it (sub-processors)
- Cloudflare: hosting, storage (D1, KV, R2), the Workers runtime that runs the scanner itself, Browser Rendering (the headless browser that loads scanned pages), and Turnstile (bot verification). Effectively all DisclosureProof infrastructure runs on Cloudflare.
- Resend: sends our transactional email — waitlist double opt-in confirmations, sign-in magic links and account security notices, purchase receipts, scan-record deliveries, and monitoring drift alerts. Resend only receives the email address and content of that specific message.
- Cloudflare Web Analytics (cookieless): aggregate traffic measurement (page views, referrers) across the site, including the authenticated dashboard once you have an account. It sets no cookies and uses no client-side fingerprinting, so no analytics identifier is tied to you. See "Cookies" below.
- Google Analytics: aggregate traffic analytics (page views, referrers) across the site. It runs under Consent Mode with every signal denied by default, and sets no cookies unless you accept the cookie banner. See "Cookies" below.
- Stripe: processes payments for Evidence Packs and subscriptions as our Merchant of Record (Stripe handles VAT/tax so we don't have to). Stripe collects your billing details directly at checkout — DisclosureProof never sees or stores card numbers.
Cookies
We don't set first-party tracking cookies of our own. A cookie banner asks before any Google Analytics cookie is set: reject and no analytics cookies are set; accept and gtag.js sets its standard analytics cookies/identifiers to measure aggregate traffic — including on the authenticated dashboard once you have an account. Your choice is remembered in your browser's local storage. Alongside it, Cloudflare Web Analytics measures page views cookielessly and stores no identifier in your browser, so it needs no consent gate. Separately, Cloudflare Turnstile may set a technical cookie or use local storage to complete its bot-verification challenge on the scan page — this is strictly necessary to run the free scan and isn't gated by the analytics choice above. None of this is used to build an advertising profile of you.
Who we are (data controller)
DisclosureProof is an independent service operated by Alena Milan, based in the United States. Throughout this policy, "we," "us," and "DisclosureProof" refer to that operator, who is the data controller for personal data processed through this site under the EU General Data Protection Regulation (GDPR) and the UK GDPR. You can reach us here:
Alena MilanDisclosureProof
1832 Kempsville Rd, Ste 112 #520
Virginia Beach, VA 23464
United States
hello@disclosureproof.com
Your choices
Email hello@disclosureproof.com to: remove a waitlist entry, request early deletion of a scan record (include the scan URL or ID from your report link), or ask what data we hold about you. We'll act on deletion requests as soon as we reasonably can.
If you're in the EU/EEA or the UK, you also have the right to lodge a complaint with your local data protection authority, though we'd appreciate the chance to put things right directly first.
Changes to this policy
If we materially change what we collect or how long we keep it, we'll update this page and the "last updated" date above. This policy describes the feature set that is live today — free scans, accounts, Evidence Pack purchases and subscriptions, and site monitoring — and will be extended as new features ship.