LEGAL / PRIVACY

Privacy policy

We are designed to know as little as possible.

Files: processed in memory to compute fingerprints and run analysis, then discarded. We do not store the documents you upload.

What we store: your account details (name, email, hashed password), document fingerprints (SHA 256), timestamp proofs, analysis reports, API key hashes and usage counters.

Legal basis: performance of contract for the service itself, legitimate interest for security logging. We are based in Cyprus and operate under GDPR.

Processors: hosting infrastructure and the independent timestamp authorities that countersign fingerprints. Only the fingerprint, never the file, is sent to a timestamp authority.

International transfers: we host the service on our own EU based infrastructure. The RFC 3161 timestamp authorities we call may be located outside the EEA. A timestamp request contains a document hash, not readable document content. Where personal data is transferred outside the EEA, it is covered by appropriate safeguards such as the European Commission's Standard Contractual Clauses.

Retention: records live until you delete them or your account. Deletion requests complete within 30 days.

Your rights: access, rectification, erasure, portability and objection. Write to [email protected].

Supervisory authority: you have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection (Cyprus).

Cookies: we use only an essential sign in session cookie. We do not use analytics, advertising or cross site tracking cookies, so no cookie banner is shown.

Last updated 7 July 2026

LudeProof. Document integrity, on the record.