TrustLayer
Back to Overview

Privacy Policy

Our architecture is built around data minimization, evidence isolation, and zero monetization of user submissions.

Effective Date:September 9, 2026

1. Data Minimization & Privacy First

TrustLayer operates on a strict principle of data minimization. We only collect and process the technical artifacts necessary to execute automated investigations, evaluate indicators, and provide verifiable risk verdicts.

Core Architecture Standard:User-submitted content (links, messages, documents) is treated as untrusted and potentially hazardous by default. Artifacts are parsed in isolated analysis environments, and we never train public machine learning models on your private case submissions.

2. Information We Collect

Depending on how you interact with TrustLayer, we collect the following categories of information:

Investigation Inputs

URLs, raw message text, phone numbers, crypto addresses, or uploaded files that you submit explicitly for safety analysis.

Account Information

Your verified email address, display name, account creation timestamp, and subscription tier. Passwords are never stored in plaintext.

Technical Telemetry

IP addresses and browser user-agents recorded transiently at the edge strictly for rate limiting, abuse prevention, and SSRF defense.

Protected Entities

Contact details you voluntarily add under the Protection module (e.g., family members or monitored assets) for identity defense.

3. Evidence Isolation & Security

Artifacts gathered during investigations are cryptographically hashed (SHA-256) to ensure chain-of-custody integrity. We employ strict multi-tenant Row Level Security (RLS) in our database, ensuring that only you have access to your personal investigation history and evidence logs.

Our Commitments:

  • We do not sell, license, or monetize your submitted evidence to data brokers.
  • We do not share your private investigation records with advertisers.
  • Encryption is enforced in transit (TLS 1.3) and at rest across all database tiers.

4. Data Retention & Ephemerality

Unauthenticated checks are processed ephemerally: raw input data is retained only in browser session storage and cleared when the browser tab closes or within 24 hours. Registered users retain their case history until they explicitly request account deletion.

5. Your Rights & Data Control

You have full autonomy over your data. You may update your profile details in your settings at any time, export investigation reports as evidence files, or request complete account closure.

6. Payment Information

  • We process payment information through Razorpay, our PCI-DSS compliant payment gateway.
  • We store transaction IDs, amounts, and subscription status.
  • We do NOT store card numbers, CVVs, UPI PINs, or bank account details.
  • Payment data is retained for legal compliance and dispute resolution.

7. Usage Tracking

  • We track the number of checks performed per account to enforce plan limits.
  • Usage counters reset every 4 hours.
  • This data is associated with your account ID, not your IP address.

8. Fact-Check Source Retrieval

  • When you use Fact Check mode, we query an external search provider to retrieve publicly available information.
  • A search query derived from your claim is sent to that provider. Credentials, payment card numbers and private keys are stripped before anything leaves our servers, but the substance of the claim itself is part of the query.
  • Retrieved source data is used solely for cross-referencing your submitted claims.
  • We never sell your submissions, and we do not use them to train any model.
  • See section 10 for the full list of services that receive submitted data.

9. Plagiarism Analysis

  • When you use Plagiarism Detection mode, your submitted text is compared against publicly available web content.
  • Your text is NOT stored in any public index or database.
  • Comparison results are stored only in your personal case history.

10. External Services That Receive Submissions

TrustLayer cannot check something against the outside world without asking the outside world. When you submit an investigation, parts of it are sent to the services below — only the part each service needs, and only when that kind of indicator is present. Nothing is sent for a service that is not configured.

  • Google Web Risk — receives a submitted URL, to check it against Google's malware and social-engineering lists.
  • AbuseIPDB — receives an IP address, only when one appears in your submission, to check its abuse reputation.
  • RDAP registries (IANA, ICANN-accredited registrars and the regional internet registries) — receive a domain name or IP address, to read its public registration record.
  • Tavily — receives a search query derived from your claim or document, in Fact Check and Plagiarism modes only.
  • An AI analysis provider — receives the normalised evidence package for narrative synthesis, and only when one is configured. Credentials and secrets are stripped before this boundary.
  • Supabase (database and authentication), Vercel (hosting) and Razorpay (payments) process data as part of operating the service.

Passwords, private keys, payment card numbers and API tokens are redacted before any outbound request. TrustLayer is not a zero-knowledge service: we receive your submission, and the services above receive the parts described here.

11. Privacy Contact

If you have questions regarding our data practices, security posture, or wish to request data purging, please contact our security team directly:

Contact options are being finalised and will be published here shortly.