Last updated: September 8, 2026
Privacy notice
This policy explains how Hide handles personal information when you create a discovery brief or exposure case, use Hide Verify, visit hidedata.app or use an optional account or company feature.
1. Who we are
Hide is operated by Clexa GmbH, Friedrich-Ebert-Straße 31, 92421 Schwandorf, Germany. Clexa GmbH is the controller within the meaning of Article 4(7) GDPR.
Clexa GmbH is represented by Anna-Katharina Schinzel and registered with Amtsgericht Amberg under HRB 8352. For privacy questions or to exercise your rights, email info@hidedata.app.
2. Information we process
The categories below describe what Hide processes across the public product and optional features. Features described as enabled or available are not active until they are offered in the product.
2.1 Website and security dataOur infrastructure processes ordinary request information such as network address, browser and device information, requested page, timestamp and error details. For application rate limiting, Hide stores a daily-scoped hash derived from a network address or submitted email; the raw value is not retained in that rate-limit record.
2.2 Private discovery briefs and personal exposure casesWhen you create a Hide Check, you must first verify and sign in to the email address used for the case. Hide rejects a different submitted email before any discovery starts. Hide Personal currently starts searches only after the account owner confirms that the named profile describes them; searching for another person remains unavailable until a verified delegate flow exists. Hide stores a versioned self-search authorization, its public-Germany scope and the authorization time with the discovery brief. Deleting the brief withdraws that authorization and removes its candidates and unfinished source work. We process your name, verified account email address, country, broad role category, selected exposure category, at least one identity-context field, optional public source URL and hostname, authority and consent records, source-coverage status, source-rule identifier and version for each checked source, possible match URLs, confidence and match reasons, your confirmation or rejection, case status, dated ledger events and a one-way technical capability hash that is not returned to the browser. A signed-in account may save up to ten reusable identity profiles. A profile can contain a current name, former names or aliases, current and former cities, current and former employers or public roles, and optional address, email and phone clues. The complete profile is encrypted at rest with authenticated encryption; only the account relationship and technical encryption metadata remain outside that encrypted payload. An authorized discovery brief receives its own encrypted snapshot so later source checks use the clues that the person approved at the time. Hide decrypts these records on the server only to display them to the owning account or perform the separately authorized search. Where automatic discovery is enabled, Hide sends current and former names together with broad city, employer or public-role context through its authenticated Vercel gateway to Serper's Google Search API with German region and language settings. The gateway forces those settings, returns only a bounded title, public URL and snippet, and does not log or retain the query or response. Hide does not send exact address, email or phone clues as discovery queries; it compares them only against the bounded result already returned and does not retain search-result snippets. If you ask Hide to operate a removal, we also process the approved request text, selected legal playbook, source-rule identifier and version, legal-basis snapshot recorded at approval, recipient email, approval time, whether you approved one follow-up, provider message identifiers, delivery state, response and follow-up deadlines, bounded error details, source-response summaries you enter and escalation or completion state. Outbound and recorded inbound messages receive body hashes for auditability. A scheduled sync reads only recent Strato messages whose subject contains a Hide case reference. It sends Hide the case reference, cryptographic message and content fingerprints, received time, a coarse reply category and whether an attachment exists. Raw reply text, sender details and attachments remain in Strato and are not imported automatically. If the source asks for identity verification, Hide stores the task state, your exact authorization, bounded provider message identifier, delivery state and relevant dates. Hide can send only the displayed data-minimized reply asking the source to explain necessity and offer a protected channel. A trained operator reviews any later source reply and may store a bounded summary of the protected route, minimum evidence, permitted redactions and deadline in your private case; the raw reply and attachments stay in Strato. Identity documents and document fields are not uploaded to or stored by Hide; you complete any necessary verification directly through the source's protected channel and may record only that completion. The approved request is sent only after an account owner confirms it. Before an ordinary website request is sent, Hide makes a bounded request to the supplied public privacy, legal or contact page and checks that the exact recipient address appears there; the page text is not retained. Statutory-register cases are routed to human review because a correction or restriction route may apply instead of erasure.
For outcome proof and optional personal monitoring, Hide may also record public HTTP status and headers, content length, access and check time, cryptographic content and source fingerprints, schedule status, comparison result, the email provider's bounded message identifier and delivery state, alert-suppression reason and time, and whether a change is waiting for your review. When a public response fits the product's safety limit, Hide also retains those response bytes as an encrypted, owner-only snapshot so you can inspect what was observed at that time. The snapshot is never executed as a live page: textual responses are escaped and displayed as inert text, and other file types are downloaded as attachments. A bounce, spam complaint or provider suppression pauses email alerts to that address but does not stop scheduled source checks or private-ledger evidence. The proof record distinguishes a source fetched by Hide from an outcome confirmed by you. After a verified removal, you may optionally report whether the workflow was clear without help and provide two rough minute estimates for manual work and active Hide use. Hide stores the selected clarity category and numbers, not free-text feedback or a covert activity log. Exact address, email and phone clues are optional; Hide never requires identity-document uploads. A possible match becomes an exposure case only after you confirm that it describes you and choose the category of personal information actually visible on the source. That answer replaces Hide's automated snippet-based category in the case, request and evidence ledger. If you mark a possible match as unclear, an authorized Hide reviewer may see the saved identity context, source URL, score and match reasons to dismiss a clear mismatch or return the decision to you; the reviewer cannot confirm identity or create a case for you. New personal discovery records are visible only to their owning verified account, are excluded from search indexing and can be deleted through the account's case controls. Legacy browser-controlled records created before this safeguard remain limited to their original 30-day expiry.
You may explicitly create a redacted outcome link from a private exposure case. Hide stores only a one-way hash of the 32-byte capability token and an immutable snapshot containing the broad exposure category, lifecycle stage, day-level dates, private-ledger evidence count, and whether removal or monitoring had been recorded. The public snapshot excludes the person's name, email, address, source, URL, request and reply text, recipient, case identifier, evidence fingerprints and captured source material. Anyone with the unguessable link can view it for up to 30 days, despite its no-index instruction, so share it only with intended recipients. Creating a new link revokes the earlier active link. You can revoke it immediately, and deleting the case or closing the account deletes every linked public snapshot.
A signed-in account owner may start one human-support conversation inside a private exposure case. Hide processes the selected reason, urgency, message text, conversation state, timestamps and the name of the responding operator. Message text is encrypted at rest with authenticated encryption tied to that conversation and sender. Support is text-only: do not submit passwords, payment details or identity-document images. An urgent-safety label prioritizes operator review but is not an emergency service.
2.3 Hide VerifyWhen you use Hide Verify, the submitted text and, if supplied, original email headers are processed transiently to extract infrastructure indicators and derived routing facts. You may paste this evidence or choose an .eml or text file; the browser sends only a bounded text extract and rejects files larger than 256 KB. You may also choose a PNG, JPEG or WebP screenshot up to 8 MB. The browser downloads Hide's self-hosted English and German text reader from hidedata.app and performs optical character recognition on your device. The screenshot is not uploaded to or retained by Hide. Only the extracted text you review and submit is sent to Hide. Optical character recognition can be inaccurate, so you should correct the extracted text before relying on a result.
Extracted data can include URLs, sender domains, Reply-To and Return-Path domains, supplied SPF, DKIM and DMARC results, referenced DKIM selectors, phone numbers and payment destinations. Recipient addresses in To, Cc, Bcc and Delivered-To header fields are excluded from retained indicator hashes. Hide does not retain the raw message, headers or uploaded file; it also does not retain the screenshot.
Hide stores a cryptographic hash of the normalized submission, cryptographic hashes and broad types of extracted indicators, aggregate report counts, the generated evidence result with its timestamp and a hashed browser-management token. If you are signed in, Hide also connects the result to your account so you can open it across devices. The check compares submitted domains with source domains already in your private Exposure Ledger and adds only aggregate confirmed-case counts, broad exposure categories and the number of overlaps to the result. It does not copy exposed values or unrelated ledger source names into the result, and overlap does not prove who sent a message or how information was obtained. You may later report only that the message was confirmed harmful, confirmed legitimate or remains unknown, together with a structured category describing how that outcome was established. Hide stores those two categories with the original concern band to measure missed danger; it does not request or store a provider name or incident story. Reports without a valid confirmation basis do not count as confirmed ground truth. The result may contain derived domain names, approximate registration age, public certificate-history context, sender-policy status, bounded redirect hostnames and status codes, threat-list match categories, concern levels and recommended actions. Hashing reduces disclosure but is not anonymisation where an input can be guessed. Public DNS resolvers, domain-registration services and certificate-transparency services receive the domain names required for checks. When commercial threat intelligence is enabled, Google Web Risk receives up to three complete public URLs supplied in the message and returns whether they match its phishing, malware or unwanted-software lists. A query string can contain personal or secret values, so remove unnecessary secrets before submitting a message. For up to three supplied links, the linked hosts may also receive bounded HEAD requests through a maximum of four redirects; Hide checks each host against private and reserved networks and does not request page bodies, execute scripts or submit forms.
2.4 Legacy Clear business scansWhen you request a scan, we store the submitted domain, public DNS, registrar-provider and HTTPS observations, source links, timestamps, method version, generated findings and tasks, and any comparison with an earlier scan. Registrar discovery reads the public RDAP service selected through IANA's bootstrap registry and retains only the identified registrar, not registrant contact data. If the creating browser uses remediation controls, we also store the selected action status, optional responsible person or team, work contact, due date and note with that report. Do not enter secrets or unnecessary personal information. A report may later be associated with a company workspace only when the creating browser authorizes the claim and the exact domain has been verified.
Clear requests public DNS records through a DNS resolver and may request the submitted website, its security.txt file and its MTA-STS policy. Those operators receive the technical information normally needed to answer the request. Clear does not test ports, attempt logins or simulate attacks.
2.5 Public reportsClear reports are available to anyone who has the unguessable report URL. They are excluded from search indexing, but no technical measure can prevent a recipient from sharing a URL or copy. Do not submit confidential information or use the service to create a report for harassment, employee profiling or another unlawful purpose.
2.6 Monitoring and early accessIf you request business monitoring, we process your work email, domain, source scan, consent version, verification status, monitoring runs and delivery status. If an authenticated person starts personal monitoring after verifying a removal, or separately approves automatic monitoring as part of a removal operation while an eligible plan is active, Hide rechecks that case's public source every 30 days and emails only when the source fingerprint changes or a page that returned not found responds again. The alert is a request to review, not a claim that personal information returned. Monitoring emails include a direct unsubscribe link. For personal-product early access, we process the submitted email, optional country and consent version.
With an active Hide Personal plan, an account owner may separately authorize recurring discovery for a saved self-identity. Every 30 days, Hide creates a new evidence-preserving discovery cycle from the encrypted identity snapshot and repeats the supported public-Germany source searches. Hide compares normalized source URLs with earlier cycles for that identity, marks already-seen results separately and alerts only when a new possible match requires review. The alert contains no source URL or exposure detail. A new result remains unconfirmed and cannot become a case or removal request until the account owner reviews the original source and confirms identity. Hide stores the schedule, versioned consent, cycle number, linked discovery brief, source attempts, next and last run times, new-result count, bounded failure state and email delivery reference. The account control or signed email link stops future cycles without erasing the dated searches already performed; those remain in the private account until the person deletes the linked brief, identity or account. Losing paid entitlement pauses the schedule.
A person with an active Hide Personal plan can separately opt in to a monthly Exposure Ledger email. The email contains only six aggregate outcome counts for the preceding 30 days: sources found, requests delivered, source responses, removals verified, clear rechecks and changes requiring review. It does not contain source names, exposure details or case history. Hide stores the preference, next and last send times, a bounded provider message identifier, delivery state and bounded failure information. The email links to the private account for details and includes a signed one-click preference link. Stopping this optional summary does not stop source monitoring, delete an account or cancel a subscription.
2.7 Company accounts and organization recordsFor personal and company accounts, we process email, optional display name, sign-in challenges, hashed session tokens, authorization and audit events, and records created in the account. If you enable two-step sign-in, Hide stores the authenticator secret with authenticated encryption and stores one-time recovery codes only as cryptographic hashes. The plain recovery codes are shown once. Replacing them deletes the usefulness of every earlier code and records a security audit event. Authenticator challenges expire after ten minutes and are limited to five attempts. If you prove control of the account email but lose both the authenticator and recovery codes, you may request a delayed reset. Hide stores only a hashed single-use reset token, the account relationship, security timestamps and audit events. The link is unusable for 24 hours; a still-signed-in device can cancel it during that period. Completion removes the old authenticator and signs out every device.
A personal account owner can request permanent account closure while signed in. Hide first blocks closure if a checkout, still-chargeable subscription, payment retry or withdrawal review is open, or if the account belongs to an organization that must be transferred or left safely. A subscription whose renewal has already been cancelled does not delay closure. Closure requires both the active signed-in session and a separately emailed, single-use confirmation link that expires after 30 minutes. On final confirmation, Hide stops monitoring and optional email schedules; deletes the account, sessions, sign-in methods, encrypted identity profiles, discovery records, cases, evidence fingerprints and encrypted response snapshots, removal operations, private support messages and account-linked Verify reports and outcomes from the live product; and removes direct identifiers from product events. If object storage is temporarily unavailable, snapshot deletion remains in a restricted retry queue until it succeeds. De-identified aggregate Verify indicator hashes continue under the separate 12-month retention described below because they are not stored with a submission or user relationship. Accounting and resolved refund records that must remain are separated from the deleted account, assigned a non-identifying internal closure reference and given a synthetic email address. Required security and transaction audit events may remain without the account identifier.
2.8 Paid featuresIf paid features are enabled, the payment provider processes payment-method and billing details. Hide stores only the provider references, amount, currency, payment status and records needed for entitlements, refunds, accounting and support. Hide does not receive or store full card numbers.
2.9 Product events and correspondenceHide records limited first-party events such as scan starts, completions, failures, removal approvals, sends, responses, follow-ups, escalations, verified outcomes, selected outcome and clarity categories, report shares, exports and monitoring requests. Launch attribution is restricted to bounded campaign labels; we do not store raw referrer URLs, request bodies, scan evidence, feedback prose or email addresses in analytics properties. Public personal-outcome metrics are aggregate only and remain unpublished until the exact metric has at least 20 eligible cases or responses. The public report contains no names, email addresses, source URLs or individual case records. We also retain information you send in support, privacy or security correspondence.
3. Why we process information
- Provide the scan, report, export, account or other service you requested.
- Preserve dated source fingerprints and user-confirmed outcomes, and let you verify a later change.
- Deliver a removal request you explicitly approved, track its response deadline and route contested or statutory-register cases to a reviewer.
- Operate consented monitoring and send change, service or optional aggregate monthly outcome messages.
- Verify company-domain control and enforce organization permissions.
- Protect Hide and third parties from abuse, investigate errors and maintain reliability.
- Respond to requests, comply with law and establish or defend legal claims.
We do not sell personal data, use scan evidence for advertising, or use cross-site advertising trackers.
4. Legal bases
We rely on consent under Article 6(1)(a) GDPR to create a private discovery brief or personal exposure case, to process and hash indicators submitted to Hide Verify, and to process optional outcome, clarity and time-estimate feedback you choose to provide. Consent can be withdrawn at any time, including by deleting a personal case or contacting us. We rely on performance of a contract or steps requested before a contract under Article 6(1)(b) to provide requested account and paid services.
We rely on legitimate interests under Article 6(1)(f) to provide requested public-domain scans, secure and improve the service, keep bounded evidence, prevent abuse and answer support requests. Our interests are limited by the non-invasive public scope of Clear, short retention, source transparency and deletion controls. We rely on Article 6(1)(c) where processing is required by tax, accounting, security or other law.
5. Retention
- Private Hide Check discovery and cases
- Account-owned discovery briefs, cases and dated ledger events remain in the private account until you delete the individual record or close the account. Legacy browser-only records expire after 30 days. Mandatory legal retention may apply to a separated, restricted record.
- Encrypted personal evidence snapshots
- A bounded public response may remain encrypted for the life of its linked private case. It is deleted when you delete the case, close the account or a legacy case expires. If object storage cannot be reached at that moment, Hide keeps only its storage key in a restricted retry queue until deletion succeeds.
- Personal removal and verification operations
- For the life of the linked private case, unless you delete the case sooner or longer retention is required to establish, exercise or defend legal claims. Deleting the case removes its operation, verification-task and message-audit records from the live product. Hide does not retain identity documents used through a source's protected channel.
- Private case support conversations
- For the life of the linked private case, unless the case is deleted sooner or longer retention is required for a legal claim. Deleting the case removes the encrypted conversation from the live product.
- Hide Verify results, indicator hashes and outcome categories
- Up to 12 months for repeat-report detection, abuse prevention and safety evaluation, unless earlier deletion is required following a valid request.
- Public Clear snapshots and evidence
- 90 days, unless the creating browser deletes the report sooner.
- Rate-limit identifiers
- 24 hours.
- Monitoring requests
- Until consent is withdrawn, the linked source or case is deleted, or the service ends. Personal monitoring evidence may remain in the private outcome ledger for the case lifetime; operational run records are retained for up to 400 days so annual monitoring history can be shown and audited.
- Monthly Exposure Ledger email preference
- Until you stop the optional summary, delete the account or the service ends. Delivery references, status and bounded failure information remain with the preference for its life and up to 30 days afterwards, except where longer retention is required for a legal or security claim.
- Early-access details
- Until launch, unsubscribe or a deletion request.
- Sign-in, authenticator, session and security-email records
- Expired email and authenticator challenges are kept for no more than 24 additional hours; sessions expire after 30 days or on sign-out. An encrypted authenticator secret and hashed unused recovery codes remain until you disable two-step sign-in or delete the account. A delayed authenticator-reset record expires 72 hours after the request and retains no plain reset token. Hide records the time, kind and delivery state of new-session and completed-recovery notices for the account lifetime, but does not collect an IP address, location, device name or browser fingerprint for them. Live notification records are deleted with the account; bounded security audit events may remain where needed to investigate account access.
- Account, encrypted identity profiles and organization membership
- Until the account or saved identity is deleted, except records subject to legal, contractual or security retention. Completing personal account closure removes live operational account data immediately and signs out all sessions. Organization membership must be transferred or removed before personal closure. Deleting a reusable identity alone does not silently delete an existing discovery brief or outcome ledger; those have their own visible deletion controls.
- Account-closure request
- The confirmation link expires after 30 minutes and the plain token is never stored. A completed request keeps only its hashed token, non-identifying closure reference and security timestamps; replaced or failed requests are deleted or expire.
- Payment and authorization records
- For statutory accounting periods or the documented authorization period. Card data is retained by the payment provider, not Hide.
- Support and legal correspondence
- As long as needed to answer the request and for applicable legal limitation periods.
Access-restricted backups may retain deleted information until their normal expiry. They are not used for ordinary product processing.
6. Providers and recipients
Hide uses service providers only for the functions needed to operate the product. Current categories include Cloudflare-hosted application, database and DNS-resolution infrastructure; public IANA/RDAP and certificate-transparency services for domain evidence; a Vercel custom-domain and authenticated search gateway; Google Web Risk when commercial malicious-link intelligence is enabled; Serper's Google Search API when automatic personal discovery is enabled, including results for publicly indexed documents; email delivery through Resend when email features are enabled; and Stripe when payments are enabled. Hide does not open files behind logins or outside the public index. Submitted website operators receive the network requests required to perform the public checks. A source operator or its privacy contact receives the identity, contact details, source reference and request text that you explicitly approve for delivery. Replies are received in Hide's Strato-hosted mailbox and reviewed before an outcome is recorded.
We may disclose information when legally required, to protect rights and security, or as part of a corporate transaction subject to appropriate safeguards. We do not share personal data with advertisers.
7. International transfers
Some providers may process information outside the European Economic Area. Where required, transfers rely on an adequacy decision, the European Commission's Standard Contractual Clauses or another lawful safeguard. You may request more information about applicable safeguards at info@hidedata.app.
8. Your GDPR rights
Depending on the circumstances, you may request access, rectification, erasure, restriction, portability or objection, and may withdraw consent at any time. You also have the right to complain to a competent data-protection supervisory authority.
The verified account that creates a private Hide Check can delete the discovery brief, case, complete ledger and linked encrypted response snapshots directly. A signed-in person can also download a versioned JSON archive of the account's current identity profiles, discovery coverage, candidate decisions, exposure cases, evidence, removal outcomes, monitoring state, support conversation, Verify summaries, preferences and bounded billing state. Authentication material, encryption material, response-snapshot bytes and provider object identifiers are excluded from that JSON archive; each available snapshot has its own owner-authorized view and download control. A signed-in personal account can also request complete account closure from the account page; a separate short-lived email link and the active session are required before deletion. Billing, an open withdrawal review or organization membership must be resolved first so closure cannot abandon a payment or shared workspace. A legacy browser-controlled personal record remains deletable from the browser that created it until it expires. The browser that creates a public legacy Clear snapshot can delete that snapshot and its linked monitoring request. For other requests, email info@hidedata.app. We may need to verify your identity or authority and normally respond within one month.
9. Automated analysis
Hide Check requires a current or former name plus at least one independently matching location, employer, public role, address, email or phone clue before it surfaces a possible identity match. A former name or alias can never create a candidate by itself. Exact contact and address clues strengthen only a result already returned by the public index and are not sent as search terms. Hide excludes results below a conservative source-specific threshold and caps automatic confidence below certainty. Confidence is not proof: the person must confirm a match before it becomes an exposure case or can lead to a removal request. Hide Verify classifies technical indicators into concern and confidence bands, never issues a definitive safe verdict and does not produce legal or similarly significant effects under Article 22 GDPR. Results include evidence, limitations and source status so they can be reviewed.
10. Security
Hide uses transport encryption, access controls, hashed tokens, optional authenticator-based two-step sign-in, authenticated encryption for saved identity profiles, authenticator secrets, private case support messages and retained source snapshots, user-scoped authorization, bounded retention, rate limiting and network-target validation. Encryption keys are kept separately from encrypted records. No online service can guarantee absolute security. Security concerns can be reported through the trust center.
11. Cookies and local controls
Hide uses only essential first-party cookies for creator-authorized report management and, when enabled, secure company sessions. We do not currently use advertising cookies, optional analytics cookies, session replay or cross-site tracking. The cookie policy lists each cookie, its purpose and duration.
12. Children
Hide is a business and privacy service and is not directed at children under 16. If you believe a child has submitted personal information, contact us so we can review and delete it where appropriate.
13. Changes and contact
We may update this policy when the product, providers or legal requirements change. We will post the revised policy with a new date and provide additional notice when a material change affects existing account holders.
Questions, complaints and rights requests can be sent to info@hidedata.app. The operator details are available in the Impressum.