# Safe-Link — privacy notice

This automated assessment is informational only. Not forensic evidence.

## What we receive

Only two things:

1. **The address you paste, select or upload** — the URL itself, in canonical
   form, plus its sha256 hash.
2. **Minimal metadata** — where the check came from (paste, bookmarklet,
   screenshot or partner API), the interface language, an optional partner
   identifier, the timing of the request, and your account id if you were signed
   in.

## What we never receive

- The content of the page behind the link. We do not fetch it.
- Passwords, one-time codes, card numbers or account numbers. Do not paste them
  into an appeal or a report either.
- Your cookies, browser storage, headers or anything you typed on the page. The
  bookmarklet sends the selected address and nothing else.
- The screenshot you upload for text extraction. It is read in memory to recover
  the addresses in it and is never written to storage.

## What we store, and for how long

| Item | Kept | Why |
| --- | --- | --- |
| Canonical URL | **90 days**, then removed | Reviewing appeals, investigating false positives |
| sha256 of the URL | Retained | Reusing verdicts, exception list, statistics — it identifies nothing about you |
| Verdict (score, level, flags, model version) | Retained | Statistics and the ability to explain a past verdict |
| Host name, timing, source, language | Retained | Operational metrics |
| Your outcome (avoided / opened / copied) | Retained | Pre-click prevention conversion |
| Appeal or report text | 90 days after the decision | Accountability of the decision |
| Reviewer decisions | Retained in the tamper-evident audit trail | So an exception can always be traced to a named person and a reason |

After 90 days a check keeps its hash, its verdict and its metadata; the readable
address is gone.

## Accounts and rate limits

Checking a link does **not** require an account. A person about to click a
dangerous link should not have to sign up first. Anonymous checks are limited to
20 per hour per connection to keep the service usable for everyone; the limiter
keys on a hash of the connection address, not on a stored profile.

## Training and improvement

- A check on its own is **not** used to train anything.
- Material becomes eligible for review and retraining only when **you send it to
  us deliberately** — through Report or through Appeal. That is the only channel.
- Reviewer decisions and their rationales are recorded in the audit trail. That
  record is what makes an exception auditable later.

## Sharing

We do not sell this data and we do not use it for advertising. It is processed by
the analysis provider behind the assessment, and by nobody else. A partner
embedding Safe-Link receives only the verdict for the address it submitted.

## Your choices

- Contest a verdict with **Appeal**. A human decides within 24 hours.
- Ask for a stored address to be removed before the 90 days are up: write to us
  with the `request_id`, which is shown on every verdict page.
- Do not use the screenshot feature if you do not want an image processed at all —
  paste the address instead.

## Limits

The service assesses an address, not the destination behind it. A clean address
on a site compromised tomorrow will have read clean today. Scoring is
probabilistic: it will sometimes be wrong in both directions. This automated
assessment is informational only. Not forensic evidence.
