Trust center
Privacy and security commitments
These commitments define what Hide may collect, retain and process.
Product commitments
- Hide Personal currently searches only after a signed-in account owner confirms that the named profile describes them.
- We do not support searches for another person until a verified delegate flow can preserve separate authority evidence.
- Every search stores a versioned, time-stamped authorization for a bounded public-Germany scope, and deleting the brief withdraws it.
- Automatic discovery sends the search provider only a name and optional city and company, never the case email address.
- We do not retain search-result snippets after candidate screening.
- We show whether each source is queued, checked, matched or unavailable.
- We require identity confirmation before a possible match becomes an exposure case.
- An unclear match can move to a human-review queue, but a Hide reviewer may only dismiss it or return the decision to the person and can never confirm identity.
- We send no removal request without the account owner reviewing and approving the exact text.
- We require the recipient to be verified and route statutory-register cases to a person before sending.
- We do not count a request sent as a successful removal.
- Outcome proof separates source fetches from facts confirmed by the person.
- Bounded source responses are encrypted, owner-only and displayed as inert evidence; source scripts never run in Hide.
- We do not buy criminal-market data or use false identities.
- Hide Verify never labels a message safe and does not retain raw submitted message text.
- We do not reveal employee exposure before exact-domain ownership verification.
- We retain a source and collection time for every displayed finding when a source exists.
Removal-operation boundary
Hide distinguishes approval, delivery, reply detected, response recorded, escalation and verified removal. An email-provider identifier proves only that the provider accepted a message. The Strato inbox sync imports no raw reply text or attachments; it creates a review checkpoint from a signed, fingerprinted event. When a source requests identity verification, the account owner must separately approve the exact data-minimized response. Hide asks for necessity, redaction limits and a protected channel; it never emails or stores identity documents. An incoming reply does not unlock completion by itself. A Hide operator must confirm that the original reply provides a protected route and publish only a bounded, document-free instruction summary to the person's private case. The person completes any necessary identity check directly with the source and records only the workflow state in Hide. A source reply is reviewed, and the public page is checked before the ledger records removal. German register records may remain public under a statutory duty; those cases use correction, restriction, objection and reasoned-decision routes rather than an automatic erasure promise.
Public scanner safety
Clear accepts domain names, not IP addresses. It checks resolution before outbound website requests, rechecks destinations during redirects and rejects private, loopback, link-local, reserved and documentation networks. Requests have bounded timeouts and redirect limits. Hide Verify applies the same network boundary to submitted links and uses HEAD-only requests, no page-body downloads, through no more than four redirects. It treats loops, HTTPS downgrades, unfinished routes and unusable final responses as explicit evidence instead of converting them into a successful route. Public registry and certificate-history responses are read through strict time and size limits.
When a signed-in person uses Hide Verify, the result can use private Exposure Ledger context without copying the ledger into the check. Only aggregate confirmed-case counts, broad exposure categories and overlap between a submitted domain and an already recorded source domain are attached. An overlap is treated as context to investigate, never as proof of a sender or compromise.
Application security
- Session and result-management tokens are stored as cryptographic hashes.
- Accounts can add standards-based authenticator protection; authenticator secrets are encrypted, recovery codes are stored only as hashes and every recovery code works once.
- Replacing recovery codes requires a current authenticator or unused recovery code, invalidates every earlier code and signs out other devices.
- If both factors are lost, account recovery requires a completed email-code challenge, a separate single-use link and a 24-hour security delay. A signed-in device can cancel the request; completion removes the old authenticator and signs out every device.
- Personal account closure requires both a current session and a separate 30-minute, single-use email link. The database operation is guarded against replay, signs out every device and will not run while billing, refund review or shared organization access remains unresolved.
- People can review active-session times and revoke one or every other session. Hide does not collect IP addresses or browser fingerprints for this list.
- A privacy-minimal security email is sent only after a new session is fully created or account recovery completes. Hide shows its provider-accepted and signed-webhook delivery state in the account without collecting an IP address, location, device name or browser fingerprint.
- Enabling or disabling authenticator protection signs out other devices.
- Organization records are scoped by organization identifiers and server-side permission checks.
- Payment webhook signatures are verified before entitlement changes.
- Secrets belong in hosted environment configuration, not source code or analytics.
- Security headers limit framing, browser capabilities and unnecessary content sources.
Monitoring boundary
Personal monitoring checks only the public source the person confirmed. A fingerprint change means the source response changed; it does not prove that personal data returned. Hide treats a previously missing page that responds again as a stronger relisting candidate, but still asks the person to review it before changing the case outcome. Every personal alert keeps the email provider's message reference so delivery, delay, bounce and complaint events can be reconciled. A bounce, complaint or suppression pauses email alerts for that address while scheduled source checks and private-ledger evidence continue.
Recurring discovery is a separate opt-in paid feature. It repeats the full supported Germany-focused search every 30 days, preserves each cycle and distinguishes a newly surfaced URL from one already seen in an earlier cycle. A new result is never identity proof and never triggers removal automatically. The signed email link stops future discovery without depending on an email-provider webhook.
The optional monthly Exposure Ledger email is deliberately privacy-minimal: six aggregate counts, no source names, exposure details or case history. Full evidence stays behind account sign-in. Its signed preference link stops only that monthly summary, not monitoring, the account or the subscription.
Retention
Browser-only Hide Check cases expire after 30 days. Account-owned cases may remain available while monitoring is active, and the owner can delete the complete case, schedule, ledger and encrypted source snapshots sooner. Personal account closure removes the operational workspace, direct identifiers and linked source snapshots from the live product; a restricted object-deletion queue retries if storage is temporarily unavailable. Legally required accounting and resolved-refund records remain separated and de-identified. Hide Verify stores message and indicator hashes, not raw message text, for up to 12 months. Public legacy Clear snapshots expire after 90 days. Rate-limit identifiers expire after 24 hours. More detail is available in the privacy notice.
Report a vulnerability
Send a concise description and reproduction steps to info@hidedata.app. Do not access data that is not yours, disrupt availability or use social engineering. We will acknowledge good-faith reports and coordinate remediation.