Legal
Privacy policy
This is a plain-language working draft, last updated September 2026. It has not been reviewed by counsel — treat it as a description of current practice, not a final legal instrument.
This describes what we collect, why, and for how long. The short version: we collect what running the service requires, and session content is retained only for the window your plan specifies.
What we collect
- Account data: your email address, and anything you set in your profile.
- Authentication data: sign-in timestamps, the IP address and rough network origin of each sign-in.
- Session metadata: when a session started and ended, its kind (clearnet or Tor), its state transitions, and who ended it.
- Session content: the evidence bundle a session produces — HAR, event timeline, screenshots, packet capture, DNS log, downloads, and video if enabled for your plan.
- Audit events: sign-ins, session actions, invites, role changes, and artifact downloads, tied to your account.
- Billing data, for paid plans, handled by our payment processor — we don't store card numbers ourselves.
Why we collect it
Authentication data lets us allowlist your IP at the node running your session and detect abuse. Session metadata drives the slot-limit logic described on the pricing page. Session content is the product: without it, a session has nothing to show for itself once it ends. Audit events give you and your team accountability over who did what.
Retention
Session content is deleted automatically at the end of your plan's retention window (3, 30, or 90 days). Audit log entries are kept for as long as your account exists, so you retain a full personal history. Deleting your account deletes account data and any session content not already expired.
Who sees it
Your session content is visible to you, and — for team sessions — to your team's admins and moderators, the same people who could have ended that session. We don't sell data, and we don't share session content with anyone outside your account or team.
Where it's stored
Account, quota, and audit data live in Cloudflare's D1 and KV. Evidence bundles are uploaded from the node that ran your session to Cloudflare R2 object storage and served back to you with your own authentication.
Your choices
You can download or delete your session artifacts at any time before they expire, and request deletion of your account. Team admins can remove a member, which ends their access without deleting artifacts they don't own.
Contact
Privacy questions: security@seclud.ing.