CanITrustThis

Privacy

What we collect

When you check a website, we store the URL, the evidence we collected about it, and the resulting report. When you check an image, we store the image privately for the duration of the analysis, together with the derived evidence (metadata findings, provenance information, analysis results).

Uploaded images

  • stored in a private bucket, never publicly accessible
  • deleted automatically within 24 hours of the analysis
  • never used to train AI models
  • never included in shared reports — only the derived evidence is shown
  • accessible only through short-lived signed URLs on the server

Anonymous use

You can use CanITrustThis without an account. Anonymous checks are associated with a salted hash of connection characteristics solely for rate limiting and to let you view and delete your own recent scans. We do not build profiles of anonymous users.

Accounts

If you sign in, we store your email address and link your scan history to your account so you can revisit and delete it. You can delete any scan at any time from your dashboard; deletion removes the scan, its evidence, its ordinary report and any stored files. A separately purchased buyer-report snapshot remains available after the original scan is deleted.

Third parties

Website analysis contacts public infrastructure (the site itself, RDAP registry endpoints, DNS resolvers). Text excerpts and analysis images may be processed by our AI provider to generate summaries and observations; they are not used for training. We do not sell data.

Advertising

Free usage may be supported by ads served by Google AdSense. Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this or other websites. Google's use of advertising cookies enables it and its partners to serve ads based on your visits to this and other sites. Visitors in the EEA, the UK and Switzerland are shown a consent dialog before any advertising cookies are set and can decline personalized ads; where consent is declined or not requested, only non-personalized ads (or our own plan promotions) are shown.

You can opt out of personalized advertising at any time in Google's Ads Settings or via aboutads.info. Paid subscribers never see ads. Ads never influence trust reports.

Analytics

We use Vercel Web Analytics for page views and PostHog, hosted in the EU, for product usage events such as starting a check or completing a purchase. PostHog uses memory persistence. Separately, we store a random journey identifier and allowlisted campaign labels in your browser tab's sessionStorage to connect steps in the purchase journey. The journey record contains no submitted URL or message text. It normally lasts for the browser tab's session. If browser storage is unavailable, it stays in memory only. We remove query strings and private report identifiers from analytics page URLs. If you are signed in, usage events are associated with your account's internal ID, not your email. Session recording and automatic interaction capture are disabled.

Buyer reports and payment

Stripe processes payments. We retain a buyer order with its payment status, checkout reference, email address and a saved report snapshot. This snapshot is separate from ordinary scan history and survives deletion of the original scan. Private snapshots are available to the purchasing account or a browser with the corresponding access token.

Necessary HttpOnly cookies named citt_buyer_* keep access on your browser for up to one year. Our database stores a hash of each access token. You can request a recovery link sent to the checkout email address; links expire after 30 minutes and can be used once. Redeeming a link replaces the access token for that order. Contact us about deletion of retained buyer-report data.

Contact

Questions or deletion requests: privacy@canitrustthis.app