Privacy
Minimize, encrypt, expire.
This product policy describes the implemented V1 data model; it is not a substitute for jurisdiction-specific legal review.
Search data
Identifiers are sent server-side to the configured intelligence provider. They are excluded from URLs, analytics, frontend telemetry, and routine logs.
Retention
Unclaimed searches expire after 24 hours. Claimed reports default to 30 days. Uploaded photo bytes and derived data URI are released after provider submission.
Storage and deletion
Production reports are designed for encrypted normalized storage. Users can delete reports; TraceSignal also attempts provider-record deletion where the API supports it.
Provider gap
IRBIS API documentation does not publish a concrete retention period or data-residency commitment. This requires contractual due diligence before launch.
Operator identity, jurisdiction, support address, and final legal review are launch blockers and must be configured before production.
