Privacy Policy
Last updated: 2026-09-21
This page describes what the system actually does, checked against the code and the database. We store: name, email (normalized and original), an internal flag for whether the domain looks like a work or a personal one (never a quality judgement), organization and country if you provide them, and the password hash (scrypt, never the password). Each signed-in session stores a hash of your IP, not the IP. Usage analytics store no IP at all: they record country, device type, browser and referrer against an anonymous identifier. Reports are generated on demand and never stored. Queries to RIPE RIS, RouteViews and RIPEstat leave the server without your account data. We do not sell data and use no advertising trackers.
Retention, by kind of data
| The capture file you upload | 60 minutes from upload, then deleted. After that the analysis cannot be re-run. |
| Analysis results (findings, RPKI, incidents) | 30 days after the analysis expires. After that only the analysis’s minimal metadata is kept: identifier, file name, SHA-256, size, type, dates, status and owner. |
| AI Analyst conversations | Deleted together with the analysis results they are about, on the same 30-day schedule. |
| Files downloaded by Import | 180 minutes, then deleted. |
| Account (name, email, organization, country) | Until you delete the account. Deleting it overwrites those fields and detaches your analyses. |
| Signed-in session (cookie and IP hash) | 30 days, or 14 days unused. Changing your password ends all of them. |
| Verification and password-reset links | 24 hours, or until used once. |
| Usage analytics (no IP) | 180 days for individual events; after that only the hourly count remains. |
| Backups | Up to 28 days. Deleted data still exists in backups until they rotate out. |
One thing we would rather not leave implied: "deleted" is not instant while the data is still in a backup. A row removed from the database still exists in the copies until they rotate out.