Privacy Policy
Our architecture is built around data minimization, evidence isolation, and zero monetization of user submissions.
1. Data Minimization & Privacy First
TrustLayer operates on a strict principle of data minimization. We only collect and process the technical artifacts necessary to execute automated investigations, evaluate indicators, and provide verifiable risk verdicts.
2. Information We Collect
Depending on how you interact with TrustLayer, we collect the following categories of information:
Investigation Inputs
URLs, raw message text, phone numbers, crypto addresses, or uploaded files that you submit explicitly for safety analysis.
Account Information
Your verified email address, display name, account creation timestamp, and subscription tier. Passwords are never stored in plaintext.
Technical Telemetry
IP addresses and browser user-agents recorded transiently at the edge strictly for rate limiting, abuse prevention, and SSRF defense.
Protected Entities
Contact details you voluntarily add under the Protection module (e.g., family members or monitored assets) for identity defense.
3. Evidence Isolation & Security
Artifacts gathered during investigations are cryptographically hashed (SHA-256) to ensure chain-of-custody integrity. We employ strict multi-tenant Row Level Security (RLS) in our database, ensuring that only you have access to your personal investigation history and evidence logs.
Our Commitments:
- We do not sell, license, or monetize your submitted evidence to data brokers.
- We do not share your private investigation records with advertisers.
- Encryption is enforced in transit (TLS 1.3) and at rest across all database tiers.
4. Data Retention & Ephemerality
Unauthenticated checks are processed ephemerally: raw input data is retained only in browser session storage and cleared when the browser tab closes or within 24 hours. Registered users retain their case history until they explicitly request account deletion.
5. Your Rights & Data Control
You have full autonomy over your data. You may update your profile details in your settings at any time, export investigation reports as evidence files, or request complete account closure.
6. Payment Information
- We process payment information through Razorpay, our PCI-DSS compliant payment gateway.
- We store transaction IDs, amounts, and subscription status.
- We do NOT store card numbers, CVVs, UPI PINs, or bank account details.
- Payment data is retained for legal compliance and dispute resolution.
7. Usage Tracking
- We track the number of checks performed per account to enforce plan limits.
- Usage counters reset every 4 hours.
- This data is associated with your account ID, not your IP address.
8. Fact-Check Source Retrieval
- When you use Fact Check mode, we query an external search provider to retrieve publicly available information.
- A search query derived from your claim is sent to that provider. Credentials, payment card numbers and private keys are stripped before anything leaves our servers, but the substance of the claim itself is part of the query.
- Retrieved source data is used solely for cross-referencing your submitted claims.
- We never sell your submissions, and we do not use them to train any model.
- See section 10 for the full list of services that receive submitted data.
9. Plagiarism Analysis
- When you use Plagiarism Detection mode, your submitted text is compared against publicly available web content.
- Your text is NOT stored in any public index or database.
- Comparison results are stored only in your personal case history.
10. External Services That Receive Submissions
TrustLayer cannot check something against the outside world without asking the outside world. When you submit an investigation, parts of it are sent to the services below — only the part each service needs, and only when that kind of indicator is present. Nothing is sent for a service that is not configured.
- Google Web Risk — receives a submitted URL, to check it against Google's malware and social-engineering lists.
- AbuseIPDB — receives an IP address, only when one appears in your submission, to check its abuse reputation.
- RDAP registries (IANA, ICANN-accredited registrars and the regional internet registries) — receive a domain name or IP address, to read its public registration record.
- Tavily — receives a search query derived from your claim or document, in Fact Check and Plagiarism modes only.
- An AI analysis provider — receives the normalised evidence package for narrative synthesis, and only when one is configured. Credentials and secrets are stripped before this boundary.
- Supabase (database and authentication), Vercel (hosting) and Razorpay (payments) process data as part of operating the service.
Passwords, private keys, payment card numbers and API tokens are redacted before any outbound request. TrustLayer is not a zero-knowledge service: we receive your submission, and the services above receive the parts described here.
11. Privacy Contact
If you have questions regarding our data practices, security posture, or wish to request data purging, please contact our security team directly:
