Effective 8 October 2026. This policy applies to tamperaudit.com and app.tamperaudit.com.
Free scanner. Text, tool names and agent names you paste into the free scan are processed in memory to produce your results. Anonymous scan metadata (a random scan token, finding list, risk score) is stored so results can be retrieved. We do not send scanner input to any LLM provider.
Accounts. Email address, a PBKDF2-SHA256 (100,000 iterations) password hash, organisation name and plan.
Audit data (paid plans). Tool-call metadata you send to the policy gate: timestamps, decision, rule matched, and content only where your own redaction policy allows it.
Never collected: we do not sell personal data, and we do not build advertising profiles.
Contract performance for account data; legitimate interests for security telemetry; consent for any marketing email, which is unsubscribeable in every message.
Free scan records: 90 days. Account data: for the life of the subscription. Audit chain entries: retained for the duration of the plan plus a 12 month export window, as required to evidence EU AI Act Article 12 logging. Aggregated, non-identifying statistics may be retained indefinitely.
Cloudflare (hosting, D1 database, Pages), ANYWAY (payment processing — card data never touches our servers), and an email delivery provider for transactional notices. A current list is available on request.
Access, rectification, erasure, restriction, portability and objection. Write to [email protected]. We respond within 30 days. You may also lodge a complaint with your supervisory authority.
Passwords are never stored in plaintext. Secrets are held in Cloudflare Workers secrets, not in source. Audit events are HMAC-SHA256 chained and Ed25519 signed so tampering is detectable.
Material changes are announced by email and in-product at least 14 days before taking effect.