Legal

Privacy Policy

Last updated 2026-10-03
This page explains what we collect when you run a scan, create an account, buy an Evidence Pack or subscription, or join the mailing list; how long we keep it; who else processes it; and how to ask us to delete it. It is written in plain language rather than legal boilerplate; see the Disclaimer for what a scan is (and isn't).

What we collect

If you join the launch list: your email address, plus the timestamp, browser user-agent, referring page, and country your request came from (standard anti-abuse signals). We use double opt-in: you'll get a confirmation email and nothing is added to the active list until you click it. Unconfirmed signups are inert; they have no automatic deletion schedule.

If you run a scan: the URL you submit; your IP address and, if you provide one, your email address, used only to enforce the free daily scan limits described in our Terms of Service and to fight abuse; and a one-time Turnstile (Cloudflare's CAPTCHA alternative) verification token. We do not require an account or email to run a free scan.

What a scan captures: we load the public homepage of the URL you submit in a real browser and record what's visible there: screenshots (desktop and mobile), the rendered page HTML, the list of network hosts and requests the page made, and, when a chat widget can be opened and read, a screenshot and text capture of its first message. On verified sites the scan also types a short test message into your chat widget to see how it answers, which can create a conversation in your support inbox. Because it is publicly visible page content, it may incidentally include names or other details the page owner has displayed (for example, in chat-widget branding). We use it to generate your report and, if requested, deliver a report link. Research scans are also used for the study described below.

If you request a report email: your email address and delivery metadata are used to send the report link and limit repeated sends. This request does not enroll you in follow-up or marketing emails. Earlier report follow-up sequences are suppressed; suppression records may remain so we can honor an opt-out.

If you create an account: your email address and, if you set a password, a salted hash of it — we never store the password itself, and magic-link sign-in works without one. Your account also records your plan and links to your verified sites, purchases, and monitors. If you turn on monitoring for a verified site, we additionally store that monitor's settings (which site, how often, which checks) and the before/after change events it detects.

If you buy something: payment is handled by Stripe as Merchant of Record — your card number and billing details go to Stripe directly and never touch our servers. We keep the purchase record itself: the product, amount, currency, status, purchase time, the email it belongs to (and your account, if you were signed in), plus reference IDs for the Stripe transaction.

We only fetch what's public

DisclosureProof fetches publicly accessible pages only. We do not accept credentials, do not access anything behind a login, and reject private, local, or otherwise non-public addresses at intake. The free scan covers the homepage. We check robots.txt for public scans; a signed-in account that has verified ownership of a domain can scan its own domain with an owner override. Our non-browser requests identify as DisclosureProofBot. Browser captures use a standard Chrome user-agent because some widgets refuse to load for headless-browser user-agents. See crawler details.

How long we keep it

Ordinary free scans
the scan record and its captured evidence (screenshots, DOM, findings) are eligible for automatic deletion after 7 days, including the underlying files. If a payment for that scan is still in flight (a checkout left open, or a bank payment still settling), the scan is kept until that payment resolves, and never longer than 15 days in total. The research exception below applies separately.
Pro subscribers
scans linked to a site on your account are retained for 90 days while the subscription is active.
Evidence Pack purchases
the purchased scan and its sealed evidence are retained for 1 year from purchase.
Business subscribers
scans linked to your account's sites remain while the subscription is active. Download available per-scan PDFs and evidence files from the report; there is no account-wide export tool. After the subscription ends, the scan's remaining paid or free retention period applies.
Research scans
scans tagged as study cohort records, including captured evidence, are retained indefinitely as the audit trail for our published State of AI Disclosure study. They are exempt from ordinary free-scan deletion. We publish aggregate results, without per-site records.
Waitlist entries
confirmed and unconfirmed entries have no automatic deletion schedule. You can ask for removal. When you unsubscribe, we keep a suppression entry so another form submission cannot silently re-enroll you.

You can ask for anything of yours to be deleted sooner; see "Your choices" below.

We do not sell scan data

We do not sell, rent, or otherwise trade scan results, waitlist emails, or any other data we collect. Aggregated, non-identifying statistics (for example, "N scans run this month") may be used internally or shared publicly, but never in a way that identifies a specific submitter or target site.

Who else processes it (sub-processors)

Cloudflare
hosting, storage (D1, KV, R2), the Workers runtime that runs the scanner itself, Browser Rendering (the headless browser that loads scanned pages), and Turnstile (bot verification).Effectively all DisclosureProof infrastructure runs on Cloudflare.
Resend
sends our transactional email — waitlist double opt-in confirmations, sign-in magic links and account security notices, purchase receipts, scan-record deliveries, and monitoring drift alerts.Resend only receives the email address and content of that specific message.
Cloudflare Web Analytics (cookieless)
aggregate traffic measurement (page views, referrers) across the site, including the authenticated dashboard once you have an account.It sets no cookies and uses no client-side fingerprinting, so no analytics identifier is tied to you. See "Cookies" below.
Google Analytics
aggregate traffic analytics (page views, referrers) across the site.The Google script loads only after you accept analytics cookies. Advertising storage, advertising user data and advertising personalization remain denied. See "Cookies" below.
Stripe
processes payments for Evidence Packs and subscriptions as our Merchant of Record (Stripe handles VAT/tax so we don't have to).Stripe collects your billing details directly at checkout — DisclosureProof never sees or stores card numbers.

Cookies

We don't set first-party tracking cookies of our own. A cookie banner asks before any Google Analytics cookie is set: reject and no analytics cookies are set; accept and gtag.js sets its standard analytics cookies/identifiers to measure aggregate traffic — including on the authenticated dashboard once you have an account. Your choice is remembered in your browser's local storage. Alongside it, Cloudflare Web Analytics measures page views cookielessly and stores no identifier in your browser, so it needs no consent gate. Signing in also sets a necessary session cookie to keep your account signed in; it is separate from the analytics choice. Separately, Cloudflare Turnstile may set a technical cookie or use local storage to complete its bot-verification challenge on the scan page — this is strictly necessary to run the free scan and isn't gated by the analytics choice above. None of this is used to build an advertising profile of you.

Who we are (data controller)

DisclosureProof is an independent service operated by Alena Milan, based in the United States. Throughout this policy, "we," "us," and "DisclosureProof" refer to that operator, who is the data controller for personal data processed through this site under the EU General Data Protection Regulation (GDPR) and the UK GDPR. You can reach us here:

Alena Milan
DisclosureProof
1832 Kempsville Rd, Ste 112 #520
Virginia Beach, VA 23464
United States
hello@disclosureproof.com

Your choices

Email hello@disclosureproof.com to: remove a waitlist entry, request early deletion of a scan record (include the scan URL or ID from your report link), or ask what data we hold about you. We'll act on deletion requests as soon as we reasonably can.

If you're in the EU/EEA or the UK, you also have the right to lodge a complaint with your local data protection authority, though we'd appreciate the chance to put things right directly first.

Changes to this policy

If we materially change what we collect or how long we keep it, we'll update this page and the "last updated" date above. This policy describes the feature set that is live today — free scans, accounts, Evidence Pack purchases and subscriptions, and site monitoring — and will be extended as new features ship.

See also: Terms of Service and the Disclaimer. This page is informational and not legal advice.