Privacy Policy

This policy describes how Assayer handles information when you submit a link, message, or screenshot for checking. It reflects the behavior of the current product code.

Overview

Assayer is a private evidence-reporting service. You can submit a check without creating an account. Assayer collects only the information needed to run a check, produce a private report, enforce usage limits, and support deletion. Assayer does not sell scan content.

Information you submit

When you use the website scanner, browser extension, or scan API, Assayer may receive:

  • A pasted or submitted URL, pasted text, optional page title, and an optional client source label (for example, website scanner or extension).
  • One or more uploaded or pasted images (JPEG, PNG, or WebP), validated by file signature rather than filename alone.
  • An optional client request identifier you or your browser extension generate to avoid duplicate submissions.

Assayer is designed to examine suspicious shopping, payment, and messaging content. Do not upload full payment card numbers, passwords, bank logins, government IDs, or other unnecessary sensitive documents.

Information Assayer generates

After submission, Assayer may create and store:

  • A scan identifier and a private owner access token (only a one-way hash of the token is stored).
  • Structured report fields such as result label, confidence, summary, evidence items, limitations, and checked items.
  • Usage and cost ledger records for provider calls, budgets, and operational limits.
  • Optional share links created by the report owner. Share links use a separate token (stored as a hash) and can be revoked by the owner.

Why Assayer uses this information

Assayer uses submitted and generated information to:

  • Validate input, run automated checks, and build your private report.
  • Look up URLs with Google Web Risk when a supported HTTP or HTTPS URL is present and the provider is enabled.
  • Run AI analysis through configured server-side providers when paid analysis is enabled and budget limits allow.
  • Enforce rate limits, cost controls, expiration, deletion, and authorized access to private reports.
  • Improve reliability through duplicate detection and eligible result reuse within configured time windows.

Third-party processing

When enabled in production configuration, Assayer sends only the data needed for a specific check to external providers. API keys and provider credentials stay on the server and are not shipped to your browser or extension.

  • OpenAI — When paid analysis is enabled and the OpenAI provider is selected, Assayer may send submitted text, extracted facts, deterministic findings, and image content for structured report analysis. OpenAI's API data handling and retention depend on the configured OpenAI account settings. Assayer does not promise zero provider retention unless the configured account actually has qualifying lower-retention treatment.
  • Google Web Risk Lookup — When enabled and a supported URL is present, Assayer sends the URL to Google's Web Risk Lookup API (uris.search). A clean result means no listed threat was found at check time; it is not proof a site is legitimate.
  • Hosting infrastructure — In production, scan records and temporary uploads may be stored using configured persistence adapters (for example, database and object storage services on the deployment platform).

In local development and testing, Assayer may use non-live fake provider adapters that do not call external services.

Report privacy and access

Reports are private by default. Access requires the unguessable owner token included in your private report link. Owner tokens must be at least 16 characters. Assayer stores only a hash of the token, not the token itself.

Reports are not indexed for public search. If you create a share link, anyone with that separate share token can read the report until the link expires or is revoked. Share tokens are separate from owner tokens.

Product feedback

When you use the Send feedback page or the private report usefulness control, Assayer stores a private operator feedback record. Feedback is not published as a public review, rating, comment feed, or accusation board.

  • General feedback may include your message, optional name, and optional reply email. Reply addresses are stored unmodified so operators can contact you when you ask for a reply.
  • Report usefulness feedback requires a valid owner report token. Assayer stores the usefulness choice, optional comment, and scan identifier. Owner, share, and admin tokens are used only for authorization and are not stored in feedback records.
  • Comments and operator admin notes have obvious card-like number patterns redacted before storage.
  • Public feedback submission uses Cloudflare Workers Rate Limiting abuse protection in production (per Cloudflare location, eventually consistent). It is not exact accounting and does not uniquely identify a person. Local development uses an in-process fallback only. Assayer does not store raw IP addresses in feedback records.
  • Feedback is retained for about 90 days from creation (createdAtMs). The same scheduled purge cadence used for temporary uploads removes expired feedback automatically. Operators may also run retention purge through the deployment schedule; no separate public self-service feedback deletion endpoint is offered.

Storage and retention

Anonymous private reports expire after about 24 hours from creation. After expiration, decision evidence is no longer available through the report page.

Raw uploaded image bytes are temporary. Before persistence, Assayer strips container metadata (such as EXIF, XMP, and PNG text chunks) from JPEG, PNG, and WebP uploads while keeping the image content needed for analysis. Expiry is recorded when bytes are first stored (expiresAtMs at upload persistence). Scan processing normally completes within seconds or minutes on the first report poll while uploads remain readable for active analysis. After expiry, scheduled purge jobs remove raw bytes within up to about 15 minutes when upload purge is enabled.

The default retention window is about 45 minutes from upload persistence. With the default purge schedule, scheduled deletion normally completes within about one hour of upload receipt and, under normal operation where processing finishes promptly, within about one hour of completed processing. The retention window can be adjusted in deployment configuration within the one-hour scheduled deletion budget.

Stored text excerpts may have obvious card-like number patterns redacted. When you delete a report, Assayer removes decision evidence from the response, deletes associated raw uploads when present, and redacts stored scan input fields.

Assayer does not promise immediate physical erasure of every backup or log copy on every system. Purge timing depends on the active storage adapters and scheduled jobs in your deployment environment.

Deletion and your choices

You can delete a report from your private report page when you have the owner token. Deletion requires token verification, hides report conclusions, redacts stored input content, and deletes raw upload objects tied to the scan when upload storage is in use.

Deletion is a soft delete in the scan record: the report status becomes deleted and evidence is cleared from responses. Repeated delete requests are handled safely if the report is already deleted.

To reduce what you share, submit only the screenshot, link, or message needed for the check, avoid unnecessary personal data, and delete the report when you no longer need it.

Security limitations

Assayer uses server-side access controls, token hashing, input validation, and cost limits, but no online service can guarantee perfect security. Keep your private report link and owner token confidential. Anyone with the link and token can access the report until it expires or is deleted.

Assayer blocks obviously unsafe URL retrieval targets on the server, but automated checks can still miss risks or produce incorrect conclusions. See the Terms of Service and Safety guidance for product limitations.

Cookies, local storage, analytics, and advertising

In the current version, Assayer does not load live third-party analytics or live advertising networks on public pages. Eligible pages may show labeled ad placeholders only; live AdSense is not active in this build.

If you use optional report features in your browser, Assayer may store saved report references in your device's local storage. That data stays on your device unless you clear it.

Assayer does not use a cookie consent banner in this version because live tracking and advertising cookies are not loaded on public scanner and report pages.

Children

Assayer is not directed to children under 13, does not knowingly collect personal information from children under 13, and will delete such information if discovered.

Changes and contact

Assayer may update this policy as the product changes. Material changes should be reflected here before public launch updates.

For privacy questions or deletion help, use the Support and contact page.

Last updated for the current Assayer product behavior. This page is informational and is not legal advice.