← Back to home

Privacy Policy

Last updated: January 28, 2026

At a Glance

1. What We Collect

We collect information necessary to provide the evidence collection service:

Data TypePurposeRetention
Account email & password hashAuditor authenticationUntil account deletion
Client email addressesSend upload links and notificationsWith request record (30 days)
Company namesIdentify submissionsWith request record (30 days)
Uploaded filesDeliver to requestor90 days (auto-deleted)
Saved templatesReuse evidence request configurationsUntil account deletion
Payment infoProcess credit purchases (via Stripe)Handled entirely by Stripe

What we don't collect: We don't use analytics, tracking pixels, or advertising cookies. We don't collect device fingerprints or build user profiles. We never store plaintext passwords — only salted PBKDF2 hashes.

2. How We Use Your Data

  • Authenticate your account and maintain your session
  • Send evidence request links to clients
  • Notify you when evidence is submitted
  • Process credit purchases
  • Provide download access to uploaded files
  • Send service-related communications (no marketing emails)

3. Who We Share With

By design: When you use ProofRepo, evidence is shared between the requestor and client specified in each request. This is the core function of the service.

Service providers:

  • Cloudflare — Hosting, storage, compute, and KV data store (SOC 2 certified)
  • Stripe — Payment processing (PCI DSS Level 1)
  • Resend — Email delivery (US-based)

We never sell your data, share it with advertisers, or use it for purposes beyond providing the service.

4. Data Retention

DataRetention Period
Uploaded files90 days (automatic deletion via R2 lifecycle rules)
Request metadata30 days
Account dataUntil the user deletes their account
Credit/billing records12 months (stored in account history)

You can delete individual submissions immediately through the Pack Viewer, or request full account deletion by contacting us.

5. Security

  • AES-256 encryption at rest
  • TLS 1.2+ encryption in transit
  • PBKDF2 password hashing (100,000 iterations, SHA-256)
  • HMAC-SHA256 signed session tokens
  • Time-limited signed URLs for client access (72-hour expiry)

For more details, see our Security Practices page.

6. Your Rights

  • Access — Request a copy of your data
  • Deletion — Request we delete your data or your account
  • Correction — Request we correct inaccurate data
  • Portability — Receive your data in a standard format

To exercise these rights, email [email protected]

7. Cookies

We use minimal, essential cookies only: authentication tokens (keeping you signed in) and security tokens (preventing abuse). We don't use tracking cookies, advertising cookies, or third-party analytics.

8. Changes to This Policy

We may update this policy occasionally. Material changes will be communicated via email or notice on our website. The "last updated" date at the top indicates when changes were made.

9. Contact

Privacy questions? Email us at [email protected]

General support: [email protected]