Privacy information for the local pilot.
This page explains the demonstrated development scope and is not final public-launch legal copy.
Preview copy · Final legal wording requires the external review recorded in the programme open items.
What the pilot stores
The account-first flow stores a normalized reserved .test email, hashed access tokens and sessions, account roles, the reporter relationship and safety decision, and—only after the safety gate—the platform, exact unvisited URL, country and concise concern. Guest preview drafts separately contain safety state, bounded report facts, user-supplied URL text, notice and route data. Claimed synthetic cases add immutable notice versions.
The analyst pilot separately stores assignment, manually transcribed synthetic evidence and its hash, observations, inferences and assumptions, findings, internal destination drafts, and independent reviews. A draft copies the reporter URL and concern with field-level provenance marking both as unverified reporter assertions; that copy is not preserved evidence or a verified finding.
The local email simulator stores an OTP code or legacy bearer link reversibly inside an encrypted mailbox payload. The simulator can decrypt it with its separately configured local key only on loopback during the credential's short validity window; neither credential is stored in plaintext in the mailbox row.
What it does not accept
No files, intimate media, suspected-CSAM narrative, passwords, platform credentials, payment data or behavioural analytics.
Retention status
Guest drafts expire after 24 hours. Claimed cases can be scheduled for deletion with a 24-hour grace period; a deterministic worker removes case content and retains only a minimized purge record. Intake leads do not yet have an implemented user deletion or expiry workflow, so they remain local-pilot data until that separately tested policy exists.
Account identities and roles, expired or consumed account access-token and OTP records, expired or revoked account-session records, and encrypted local mailbox rows do not yet have an implemented purge workflow. Expiry prevents credential use or mailbox display, but does not currently delete those rows. Local backup scripts exist for operator testing, but no managed backup service is configured in the local pilot.
Analyst assignments, evidence, observations, inferences, findings, drafts and reviews also do not yet have an implemented deletion or expiry workflow. They remain synthetic local-pilot data until a separately tested retention policy exists.