Privacy and legal
What would you like clarified?

Ask about data handling, retention or your choices, then read the complete policy directly below.

General information from an AI assistant, not a real check. Private by design, never sold or used for training.

Last updated: September 8, 2026

Terms of service

These terms apply when you visit hidedata.app, create a Hide Check discovery brief or case, use Hide Verify or use an optional monitoring, account or company feature. By using the service, you agree to these terms. If you do not agree, do not use the service.

1. Who we are

Hide is operated by Clexa GmbH, Friedrich-Ebert-Straße 31, 92421 Schwandorf, Germany, represented by Anna-Katharina Schinzel. Clexa GmbH is registered with Amtsgericht Amberg under HRB 8352.

Questions about these terms can be sent to info@hidedata.app.

2. Eligibility and authority

You may use Hide only if you can legally agree to these terms. If you use Hide for an organization, you confirm that you have authority to act for it. You must provide accurate information and must not impersonate another person or organization.

3. What Hide Check and Hide Verify provide

Hide Check lets a verified signed-in account create an authorized private discovery brief, search a contracted public-search index using supplied current or former names plus broad city, employer or public-role context, review possible public-source identity matches, turn confirmed matches into removal cases, prepare and explicitly approve a source-specific GDPR request, and track delivery, responses, escalation and outcomes in a private ledger. Exact address, email and phone clues are optional and are used only to corroborate returned results, not as search terms. The case email must match the signed-in account, and Hide may suspend a disputed, abusive or unsafe search for human review. Automatic candidates require a current or former name and at least one independently matching context or exact clue; an alias alone is never sufficient. The index search can surface public web pages, directory and register results, archived pages, and publicly indexed documents; Hide does not open files behind logins or outside the public index. Search coverage depends on indexing and source availability and cannot prove that no other exposure exists. A category inferred from a search title or snippet is only an initial guess. Before confirming a candidate, the account owner must open the source and choose which category of personal information is actually visible; that confirmed category controls the new case, removal wording and evidence ledger. Ordinary website requests require the account owner to verify the recipient on a current privacy, legal or contact page. Hide then fetches that bounded public page and requires the exact recipient address to appear before delivery; recipient-page text is not retained. Statutory-register cases go to human review because publication may be legally required and correction, restriction, objection or a reasoned decision may be the available route. Hide may send the exact approved request and, only where separately approved, one neutral follow-up. A scheduled mailbox sync may classify a reply as an acknowledgement, verification request, claimed completion, refusal or other response. That category is a routing aid only: the original message remains in Strato and a person must review it before recording what the source said. Attachments and identity documents are never imported automatically. If an identity-verification reply provides a protected route, a Hide operator may publish only a bounded, document-free summary of that route and its minimum requirements to the private case. An incoming reply alone never unlocks the person's completion control. The outcome flow records found, removal requested, source responded, removal verified and monitoring stages in order. A queued or delivered message is not a removal. An imported reply category or source claim is not a removal either. For case evidence and monitoring, Hide may preserve a bounded public response as an encrypted, owner-only snapshot tied to its source fingerprint. The snapshot is inert and may be incomplete or unavailable because of the capture limit or source behavior. Source fingerprints and snapshots prove only what bytes and response metadata Hide observed at a stated time; they do not by themselves prove identity, legal compliance or successful erasure. Outcomes marked as person-confirmed depend on the accuracy of that confirmation. Confidence is a screening signal, not proof. The request and guidance are practical information, not legal advice, and Hide does not promise that a source must or will erase information.

An active Hide Personal account may opt in to recurring discovery for a saved self-identity. Hide repeats the supported public-Germany source search every 30 days in a new dated cycle and compares normalized source URLs with earlier cycles. Results previously seen are not presented as new. A newly indexed URL is only a possible match: the account owner must still inspect the original source and confirm identity before any case or request exists. The person can stop recurring discovery from the private brief or a signed email link. Stopping prevents future cycles but does not alter the dated record of searches already performed; the account owner can delete those records through the linked brief, identity or account controls. Deleting the linked brief or identity stops the schedule, and paid-entitlement loss pauses it. Provider and source gaps remain visible and Hide does not promise complete web, archive, register or directory coverage.

Hide Verify extracts infrastructure indicators and derived routing facts from submitted message text, optional original email headers, a bounded text extract from an .eml or text file, or screenshot text extracted on your device. The screenshot itself is not uploaded to Hide. Optical character recognition can miss, invent or misread characters; you must review and correct the extracted text before relying on the result. Hide checks supplied sender-authentication results, public domain-registration, certificate-transparency and DNS evidence, commercial known-threat intelligence when configured, bounded HEAD-only redirect paths, phone and payment formatting, IBAN checksums and known national lengths, EIP-55 checksums where supplied, Bitcoin Bech32, Bech32m and Base58Check rules, Tron Base58Check rules, and earlier matching indicator hashes. Format and checksum results do not identify a caller, account holder, wallet controller, balance, purpose or network. Some addresses can exist on several compatible networks. A provider match can be stale or incorrect, and the absence of a match does not mean a link or message is safe. It returns warning signals, evidence basis, recommended actions and a confidence band, never a guarantee that a message is safe or fraudulent. A legitimate service may use new infrastructure, and a legitimate account can be compromised. If you later report an outcome, choose the strongest structured confirmation basis you can support. Hide treats this as user-reported ground truth, not independent verification, and an outcome report does not retroactively guarantee the original review.

The legacy Clear scanner reviews defined public DNS, email-policy, HTTPS and security-contact sources. All automated results are bounded observations, not penetration tests, legal opinions, warranties, compliance assessments or certifications.

4. Permitted use

Hide Personal currently permits a discovery search only for yourself. You must confirm that the named profile describes you each time a search starts. Searches for family members, employees, clients or another person remain unavailable until Hide provides a verified delegate flow with separate authority evidence. You may use Hide Verify only for lawful protective review. Do not submit messages you have no right to process, secrets unrelated to the check or unlawful content.

Before paying, sharing credentials, approving a removal request or changing technical configuration, review the evidence and verify the recipient through an independent channel. By approving a removal operation, you confirm that the request concerns you or a person who authorized you, that its facts are accurate and that Hide may deliver the displayed text to the verified recipient. If a source asks for identity verification, Hide requires a separate approval before sending the displayed Article 12(6) response requesting necessity, data minimisation and a protected channel. Hide does not email, upload or store identity documents. You decide whether to use the source's protected channel and may record only that you completed the step. Declining the transfer routes the case to specialist review. Hide records the source rule, rule-set version and stated legal basis shown at approval so the later proof and escalation record do not silently change when guidance is updated. Follow-up approval is separate. Incorrect requests and configuration changes can affect third-party rights or interrupt services.

5. Prohibited use

You must not use Hide to:

  • break the law, violate another person's rights or breach a duty of confidentiality;
  • identify, profile, threaten, harass or target individuals;
  • misrepresent a report as certification, a complete security assessment or proof that an organization is safe or unsafe;
  • attempt unauthorized access, test credentials, deliver malware, scan ports or simulate attacks;
  • circumvent rate limits, deletion controls, authorization checks or other service protections;
  • run bulk or automated extraction against Hide without written permission; or
  • interfere with the service or impose an unreasonable load on it.

6. Private cases, public reports and deletion

A new Hide Check discovery brief or case is available only to its owning verified account and remains in that private account until the owner deletes it or closes the account. Legacy browser-controlled personal records created before account verification became mandatory retain their original 30-day expiry and may become inaccessible if their browser data is lost. The account's case controls can permanently delete the discovery brief, exposure case, removal operation, message-audit records, monitoring schedule, ledger, evidence fingerprints and encrypted response snapshots from the live product, subject to mandatory legal retention. If snapshot storage is temporarily unavailable, deletion remains queued and is retried.

The case owner may explicitly create one active redacted outcome link. It shows only a broad exposure category, lifecycle stage, day-level dates, evidence-record count and monitoring state captured at that moment. It omits the person, source, URL, communications, private case identifier, fingerprints and captured material. The unguessable link is available to anyone who receives it until the owner revokes it or it expires after 30 days. Creating a new link revokes the previous one. Search-engine exclusion is an instruction, not a guarantee against recipient copying or resharing. The snapshot records progress at one moment and is not a certificate, complete search, legal finding or guarantee that information remains removed.

A signed-in account may save reusable encrypted identity profiles. Starting a search requires a separate, versioned confirmation that the profile describes you and consent for the stated public-source scope. Deleting the discovery brief withdraws that search authorization and removes its candidates and unfinished source work. Deleting a reusable profile does not delete an existing discovery brief or case because those records may contain an outcome ledger; use the deletion control on each discovery brief or case as well. If you enable two-step sign-in, keep your authenticator and one-time recovery codes secure. Each recovery code works once; Hide cannot recover the original codes after they are shown. If both are lost, the delayed reset flow requires control of the account email, waits 24 hours and signs out every device when completed. A signed-in device can cancel a pending request.

You may request permanent personal account closure from the signed-in account. Closure is unavailable while a checkout, still-chargeable subscription, payment retry or withdrawal review remains open, or while the account has organization membership. Cancelling renewal first allows closure without waiting for the paid period to end. Resolve the remaining relationships first. Final closure requires the active session and a separate single-use email link, removes the private operational workspace and account-linked Verify reports, and signs out every device. It does not cancel obligations or erase de-identified aggregate indicator hashes, accounting, completed refund, security or legal-claim records that Hide must retain; those records are separated from the deleted account and de-identified where possible.

A signed-in account owner may use the private case conversation to challenge a match, explain a removal blocker, ask about a source response or report a possible relisting. Hide may answer with practical evidence and a next action, but support is not legal advice, law enforcement or an emergency service. If anyone is in immediate danger, contact 112 or the police. Do not send identity documents, passwords or payment details through the conversation. An urgent label helps prioritize review but does not guarantee an immediate response.

Hide Personal is offered as an annual subscription where checkout is enabled. The advertised €119 annual consumer price is the total price including VAT. Stripe calculates the included tax portion from the billing address and provides checkout, invoices and billing management. You may cancel renewal through the billing portal; access normally continues to the paid period end.

If you are an EU consumer, you may have a statutory 14-day withdrawal right. To exercise it, use the timestamped withdrawal form in your Hide account or email info@hidedata.app with the account email and purchase date. If you ask Hide to begin service during that period, mandatory law may permit a proportionate charge for service already supplied; these terms do not limit mandatory withdrawal or refund rights.

A legacy Clear report is accessible to anyone who has its unguessable URL. Reports are excluded from search indexing and normally expire after 90 days, but Hide cannot control copies or links shared by a recipient. The browser that creates a report receives a management control that can permanently delete the snapshot and its linked monitoring request.

Do not submit secrets, credentials, private network locations or other confidential information. Hide may remove or restrict a report where reasonably necessary to address abuse, legal obligations, inaccurate attribution or security risk.

7. Monitoring and early access

Personal monitoring can begin only for a case owned by an email-verified account after removal is verified and Hide captures a reachable baseline. The person may start it manually or separately approve automatic activation as part of a removal operation; automatic activation occurs only while an eligible Hide Personal plan is active. Hide normally rechecks the same public source every 30 days. A changed fingerprint or renewed successful response creates a review alert; it does not prove that the person's information returned. Only the person can confirm a relisting in the ledger. You can stop future checks through the case or the unsubscribe link in every alert.

While an eligible Hide Personal plan is active, you may separately opt in to a monthly Exposure Ledger email. It contains aggregate event counts for the previous 30 days, not source names, exposure details or case history. A zero count means only that Hide recorded no event of that type during the period; it does not prove there is no exposure elsewhere. You may stop this optional email through the account or its signed preference link without stopping source monitoring, deleting the account or cancelling the subscription.

Public evidence may change between checks. Alerts can be delayed or fail because of provider outages, mail filtering or other circumstances outside Hide's control. Monitoring does not replace professional security operations or incident response.

8. Company accounts and authorization

You are responsible for keeping email sign-in codes, authenticator and recovery codes, and active sessions secure, and for activity under your account. Organization information and roles must be accurate. Domain verification establishes control of the stated domain for Hide's workflow; it does not prove ownership of every related company, asset or trademark.

Any structured self-test or organization workflow must stay within its written authorization, time window, safe boundary and permitted channels. Hide may immediately stop or disable activity that exceeds those limits.

9. Paid services

If paid services are enabled, the price, currency, taxes, scope and any renewal terms will be shown before purchase or set out in an order. Payments may be processed by Stripe. Except where mandatory law or the applicable order requires otherwise, completed payments are non-refundable. Nothing in these terms limits statutory withdrawal, refund or consumer rights.

10. Intellectual property and feedback

Clexa GmbH and its licensors retain rights in Hide's name, logo, design, software, methodology and report presentation. Public-source facts remain subject to their original sources. These terms do not transfer any ownership rights to you.

If you provide optional outcome, confirmation-basis, clarity or time-estimate feedback, you allow Hide to use the selected categories and numbers to evaluate and improve the service without payment or public attribution. Do not submit confidential incident details as feedback; the product does not offer a free-text field. We will not identify you or your organization in marketing without permission.

11. Availability, changes and suspension

Hide may change, suspend or limit features to improve accuracy, maintain security, protect third parties or comply with law. We do not guarantee uninterrupted availability or that a free report will remain available for its full stated retention period.

We may suspend or terminate access for a material breach, abuse, security risk or legal requirement. Where practical, we will give notice and a reasonable opportunity to correct the issue unless immediate action is necessary.

12. Liability

Hide remains liable without limitation for intent, gross negligence, injury to life, body or health, fraudulent concealment, guarantees and liability that cannot legally be limited. For ordinary negligence involving an essential contractual obligation, liability is limited to the foreseeable damage typical for this kind of agreement.

To the extent permitted by law, Hide is not responsible for indirect or consequential loss, third-party source errors, external service outages, or configuration changes made solely in reliance on an automated report. Mandatory consumer rights remain unaffected.

13. Governing law and disputes

German law applies, excluding its conflict-of-law rules, unless mandatory law in your country of residence provides otherwise. If you are a merchant, legal entity under public law or public-law special fund, the courts at Clexa GmbH's registered place of business have jurisdiction. Mandatory consumer forums remain unaffected.

14. Changes to these terms

We may update these terms when the service, business model or legal requirements change. The revised version will be posted with a new date. If a material change affects an existing account or paid service, we will provide reasonable advance notice where required.

15. Privacy and contact

The privacy policy explains how Hide handles information, and the cookie policy lists essential browser storage. Operator details are available in the Impressum. Security concerns can be reported through the trust center. Questions about these terms can be sent to info@hidedata.app.