Skip to main content

Legal

Privacy Policy

How we use personal data alongside our zero-upload file architecture and minimized workflow records.

Service operator

Legal name
Anurodh Acharya
Trading name
Scrub Metadata
Address
88 Kirti Marg, Teentolia, Morang, Nepal
Country of establishment
NP

This operator supplies ScrubMetadata and acts as controller for its own account, website, security, billing support and contact processing. Customer processing follows documented customer instructions when this operator acts as processor. Legal responsibilities follow the actual processing activity, not merely the contract label.

Paddle is the merchant of record for the purchase and handles payment and applicable transaction taxes.

Our Privacy Commitment

Scrub Metadata is built on the principle that raw file processing stays local. We cannot access, view, or store your files during supported local processing because the file bytes stay within your browser.

This DPA applies only to processing where ScrubMetadata acts on documented customer instructions as a processor. ScrubMetadata may act as a controller for separate account administration, security, billing-support, website, and direct-contact processing described in the Privacy Policy. The role follows the actual purpose and activity, not just the name of a data field.

Zero-Upload File Architecture

Your files are processed in your browser using client-side algorithms. This prevents ScrubMetadata from receiving raw file contents during supported local processing.

V1 controlled-trial policy — owner approved|Updated September 19, 2026|Version privacy-2026-09-19-v1

Zero-Upload File Architecture

How It Works

Your Device
→
Browser Processing
→
Clean File Download
File-processing steps happen locally on your device - no raw file transmission to our servers

Raw file data that stays outside ScrubMetadata infrastructure

Raw file bytes and original or processed file contents
Raw extracted metadata values
Local file paths and full raw filenames
Local processing buffers and supported local sanitization artifacts

Professional supports browser and local folder processing. Approved customer-controlled cloud integrations are not part of the current Professional offer. ScrubMetadata can receive minimized workflow evidence such as counts, categories, status, timestamps, and evidence hashes, but not raw file data through these supported processing paths. Support correspondence is separate: do not send raw customer files or raw metadata to support.

Platform data we process

Zero-upload describes the raw-file processing boundary, not an absence of platform personal data. ScrubMetadata processes minimized account, authentication, security, device-trust, consent, billing, operational, error-monitoring, audit, compliance-evidence, and support data for the purposes described in the canonical public data-category register. It does not use visitor analytics, advertising pixels, retargeting cookies, or cross-site behavioral profiling.

Account and organization data

Data
Name, email address, company, professional role and profile link submitted with an application, application status, technical submission information including IP address, user-agent and referrer, account state, subscription entitlement, and saved service preferences.
Purpose
Assess application eligibility, prevent abuse, create and administer the account, provide the contracted service, and maintain organization isolation. Application review may include the professional profile you submit.
When
Processed when you apply, including before approval, or when you create or use an authenticated account. Submitted information is provided by you; any consulted public professional profile is a separate source.
Retention criteria
Application records can exist without an account; account closure does not itself establish their deletion. Completed applications need a decision or withdrawal trigger and pending applications need an inactivity trigger, with justified abuse-prevention exceptions. Account records follow the separate offboarding, legal-hold, backup and provider process. For the controlled trial, return and deletion are operator-managed on request, with a proposed 30-day operational target for active stores, subject to documented holds and exceptions. Provider copies are retained per provider terms; expiry not verified. This is not a statutory deadline or a claim of automatic deletion.
Minimization
Only fields needed for account, organization, entitlement, and access administration are used.

Authentication, security, and device-trust data

Data
IP address or minimized network summary, user-agent, browser and operating-system summary, device name, cryptographic device-fingerprint or proof hashes, session state, login events, and security-risk signals.
Purpose
Deliver magic-link authentication, authorize trusted devices, prevent abuse, investigate security events, and protect accounts and organizations.
When
Processed when authentication, device authorization, rate limiting, or security controls run; this is not advertising or cross-site profiling.
Retention criteria
Sign-in magic links are valid for 15 minutes and approved onboarding tokens for 48 hours. Browser session, CSRF and device lifetimes are listed in the shared storage table. These validity periods are not deletion deadlines for security logs, device history or incident evidence; those records require separate retention and deletion rules.
Minimization
Exports and ordinary reports use redacted or summarized network and device evidence; raw file data is excluded.

Consent and privacy-preference evidence

Data
Consent choice, purpose, notice version, timestamp, withdrawal state and consent identifier stored in this browser. The separately tier-gated server capture paths store pseudonymized subject references and record IP address and user-agent as null.
Purpose
Remember privacy choices and record local choice or withdrawal events. Where the separate organization consent register is enabled, support its audit evidence.
When
Professional does not synchronize this browser preference to the organization consent register. Optional browser error monitoring remains off unless consented. Separate security and request logs can contain network information.
Retention criteria
The browser preference has no automatic expiry; local consent and processing logs keep the latest 50 entries. Clearing site storage removes them. Separately enabled server records need their own retention, legal-hold and deletion schedule.
Minimization
The record excludes raw file data and stores bounded consent evidence rather than browsing-content history.

Billing, subscription, and entitlement data

Data
Billing contact, customer and transaction references, plan, subscription state, invoice or refund status, tax evidence, and webhook reconciliation state. Payment-card data is handled by Paddle, not ScrubMetadata.
Purpose
Provide checkout, billing, entitlement, invoicing, tax handling, refunds, and financial reconciliation.
When
Processed when a customer starts or manages a paid subscription or billing event.
Retention criteria
Retained for subscription administration and applicable financial, dispute, tax, and legal-record periods; provider-side retention is handled separately.
Minimization
ScrubMetadata stores provider references and bounded billing state, not payment-card details.

Service usage and operational-control data

Data
Feature or API action, timestamp, usage and quota counters, rate-limit state, request correlation identifier, workflow status, and bounded performance or availability signals. Application abuse prevention sends IP-address identifiers and hourly allowed or blocked request counts to Upstash.
Purpose
Operate the service, enforce purchased limits, coordinate idempotent work, diagnose failures, measure availability, and prevent abuse.
When
Generated when service functions or operational controls run; no visitor advertising profile is created.
Retention criteria
Short-lived counters expire by design; other operational records follow the configured audit, reliability, billing, or incident retention rule.
Minimization
Raw file bytes, raw metadata values, full filenames, and local paths are excluded from operational telemetry and ordinary exports.

Privacy-filtered error and reliability data

Data
Error type, scrubbed message and stack context, bounded request context, internal account identifier where set, release and environment identifiers, and privacy-filtered browser or server diagnostics. Filtered diagnostics are not necessarily anonymous.
Purpose
Detect, diagnose, and resolve security, availability, and software reliability failures.
When
Server-side operational monitoring is separate from browser consent. Optional browser monitoring stays off unless the user consents and is disabled when this browser sends Global Privacy Control. Session replay and browser performance tracing are disabled in the current configuration.
Retention criteria
Retained only for the configured diagnostic, security, and incident-response period and the enabled provider plan.
Minimization
Credentials, message bodies, raw files, raw metadata values, full filenames, local paths, and local certification events are removed or dropped before provider delivery.

Compliance workflow and audit evidence

Data
Organization-scoped tasks, subject and requester names and email addresses, request descriptions and case narratives, decisions, statuses, deadlines, approvals, counts, categories, redacted evidence, evidence hashes, export manifests, and audit events entered or generated in the compliance workflows.
Purpose
Operate DSAR, DPIA, RoPA, incident, processor, approval, reporting, and accountability workflows requested by the customer.
When
Processed when an authorized user records or generates compliance-workflow evidence.
Retention criteria
Customer instructions and the applicable organization policy govern workflow retention. Completing or hiding a DSAR case does not erase its narratives or underlying records. Archiving an audit record does not delete it. The final case, archive and residual-copy deletion schedule must be established before publication.
Minimization
Raw file data remains outside the platform boundary; reports and exports apply record-specific redaction and manifest rules.

Communications and support data

Data
Recipient and sender address, message content and any attachments supplied to a contact mailbox, support or privacy enquiry, delivery state, suppression preference, and related audit reference.
Purpose
Deliver magic links, security notices, requested compliance communications, service support, and opted-in messages.
When
Processed when a user requests or triggers a communication or contacts a published support channel.
Retention criteria
Retained for delivery reconciliation, support, security, legal-claim, and suppression periods applicable to the communication.
Minimization
Do not send raw customer files or raw metadata to support. Application-generated messages exclude them; unsolicited mailbox attachments require separate handling and do not inherit the local-processing boundary.

Register public-platform-data-category-v1; last technical source review 2026-09-05. The register records current technical purposes, categories, minimization, retention criteria, and provider paths. Owner and privacy or legal review must confirm the final controller-processor roles, lawful basis, retention periods, transfer safeguards, and notice approval. This register does not determine legal compliance.

European Privacy Rights

Why we use personal data

Application review, account administration and requested support

Our legitimate interests under Article 6(1)(f) in assessing suitability for the Professional service, administering a business relationship and helping its authorized users. Where you contract personally, Article 6(1)(b) instead covers processing necessary for that contract or steps you request before it.

We review the professional information you submit and any public professional profile you provide. Required identity and organization information is needed to assess the application and provide protected access. Optional monitoring or marketing consent is not a condition of access.

Authentication, abuse prevention and service reliability

Our legitimate interests under Article 6(1)(f) in protecting accounts, enforcing access and purchased limits, investigating faults and preventing misuse.

These controls use necessary technical identifiers and bounded operational records, not advertising profiles. Browser storage must separately satisfy applicable storage and consent rules; a GDPR interest does not by itself authorize optional tracking.

Subscription administration and handling billing disputes

Article 6(1)(b) where needed for your own contract, or Article 6(1)(f) to administer the organization's purchase, reconcile entitlement and handle claims. A separate legal obligation is relied on only for records the applicable law requires us to keep.

Paddle determines the purposes and legal grounds for its independent payment and tax activities. Its obligations do not create an unlimited retention basis for our own records.

Optional browser error monitoring and promotional communications

Your separate consent under Article 6(1)(a) for the optional purpose you select.

You can refuse or withdraw without losing the core service. Withdrawal stops future optional collection or messages; it does not itself erase records already received. Minimal refusal or suppression evidence is used to respect your choice, not to continue marketing.

Responding to requests about data we control

Article 6(1)(c) where needed to meet applicable GDPR rights and accountability duties; Article 6(1)(f) for a requested enquiry that does not invoke such a duty.

We seek identity information only where reasonably necessary. Requests about your organization's workflow records are referred to that controller and handled on its instructions.

These grounds describe our controller activities where the GDPR applies. They are not the customer's grounds for workflow or sensitive-data processing. For legitimate interests, we assess necessity, reasonable expectations and the effect on people, limit the data and access, and consider objections through the privacy contact. A new purpose or materially different use requires a fresh assessment and appropriate notice.

Your GDPR Rights

Right to information about the personal data we process and why
Right of Access - Request the personal data and processing information applicable to you
Right to Rectification - Correct any inaccurate data
Right to erasure where the right applies, subject to lawful retention exceptions
Right to Restriction - Limit processing of your data
Right to Portability - Request portable data where the right applies
Right to object to processing based on legitimate interests and to direct marketing
Right to withdraw consent without affecting the lawfulness of earlier processing

For requests governed by GDPR, we respond without undue delay and within one month of receipt. Where the law permits an extension of up to two further months for complexity or the number of requests, we explain the reason within the first month. We request additional identity information only where reasonably needed. If the data is controlled by your organization, we assist that controller with the request rather than decide its purpose for it.

Contact Information

Privacy Questions

Purpose: Privacy questions, data-subject requests, and DPA or subprocessor enquiries

Data Subject Requests

Use this route for rights requests and privacy enquiries.

Security Concerns

Purpose: Security concerns and responsible disclosure

These are the canonical published contact routes. DNS, mailbox or alias routing, monitored ownership, receipt, response-time, PGP, and vulnerability-reward claims remain owner and provider runtime evidence gates.

Cookie Policy

Essential Cookies and Optional Error Monitoring

We use minimal essential cookies and local storage required for authentication, security, and remembering privacy choices. Visitor analytics, advertising cookies, and retargeting pixels are not used. Optional browser error monitoring is off unless you consent.

Sign-in and privacy-control storage used by ScrubMetadata. Cookies are sent to the relevant site endpoint. Local privacy choices may also be synchronized to our server as described below. Other providers are described separately.
NamePurposeLifetimeStorage
next-auth.session-token / __Secure-next-auth.session-tokenSign-in sessionUp to 30 days; renewed during continued authenticated useCookie
next-auth.csrf-token / __Host-next-auth.csrf-tokenAuthentication request protection where the authentication library sets itBrowser sessionCookie
csrf-tokenProtect application requests against cross-site request forgeryOne hour from issue or refreshCookie
device-authorizedRemember authorized-device stateUp to 24 hoursCookie
gdpr-consentPrivacy choices, notice version, timestamp and consent session identifierNo automatic time expiry in the current implementation; replaced on a new choice or removed when site data is clearedLocal storage
gdpr-consent-log / soc2-processing-logLocal consent and privacy-setting activity history; the storage name does not claim SOC 2 certificationLatest 50 entries in each log; no automatic time expiry. Removed when site data is clearedLocal storage

What We Don't Use

Google Analytics cookies
Facebook Pixel tracking
Advertising network cookies
Social media tracking pixels
Third-party analytics cookies
Performance monitoring cookies
Marketing automation cookies
Cross-site tracking mechanisms

Cookie Choices

Our minimal cookie usage is designed around privacy-by-default principles. Essential cookies are necessary for the service to function, while optional browser error monitoring remains consent-based and can be rejected or withdrawn.

Cookie Management

You can manage cookies through your browser settings:

Block all cookies: May affect site functionality including login and preferences
Delete existing cookies: May sign you out, but does not necessarily remove the privacy choice stored in local storage. Use Cookie preferences in the footer to withdraw optional monitoring, or clear this site's local storage to remove the saved preference.
Private/Incognito mode: Usually discards that session's site storage when all private windows close. Follow your browser's controls.

Third-Party Service Providers

While supported file processing stays within the browser, local folder, or approved customer-controlled boundary, we use the following source-integrated service providers for essential platform operations:

Payment Processing - Paddle

Purpose: Subscription checkout, billing, invoicing, and tax handling as merchant of record

Data Shared: Billing contact and transaction details needed for checkout and subscription administration. Paddle, not ScrubMetadata, receives and processes payment-card data.

Operational Boundary: Paddle acts as an independent controller for its merchant-of-record activities. The applicable Paddle contracting entity depends on the buyer location. Paddle determines its own retention; deleting a ScrubMetadata account does not erase Paddle records or remove ScrubMetadata service obligations.

Evidence Status: Source-integrated; runtime and legal evidence open

Privacy Policy: www.paddle.com

Application Hosting - Vercel

Purpose: Hosting the web application and serverless request handlers

Data Shared: Account and application request traffic, including technical request information needed to serve the application. Customer file bytes and raw extracted metadata values are excluded from the supported browser-local processing path.

Operational Boundary: Application Functions are configured in iad1, a United States region, also recorded in the 4 September 2026 production deployment receipt. This is not an EU-only hosting claim or a complete inventory of CDN, logs, support, backup or other provider locations. Transfer safeguards and account-specific contractual assurance still require evidence.

Evidence Status: Source-integrated; runtime and legal evidence open

Privacy Policy: vercel.com

Relational Database - Neon PostgreSQL

Purpose: Account, organization, subscription, audit, and privacy-safe compliance workflow records

Data Shared: User and organization account data plus minimized compliance records. Customer file bytes, local paths, raw filenames, and raw extracted metadata values are excluded from the supported browser-local processing path.

Operational Boundary: The production database project was observed in AWS us-east-1, United States, on 5 September 2026. Its configured restore history is six hours. That is not a complete backup-deletion guarantee or a statement about all provider access locations. The account contract and transfer safeguards remain to be established.

Evidence Status: Source-integrated; runtime and legal evidence open

Privacy Policy: neon.com

Cache and Abuse Prevention - Upstash Redis

Purpose: Distributed rate limits, session-related controls, and bounded operational coordination

Data Shared: IP-address identifiers and hourly allowed or blocked request counts for application abuse prevention, plus other minimized identifiers, counters and control state for reliable operation. No customer file content or raw metadata values.

Operational Boundary: Security-critical paths fail closed when their required distributed control is unavailable. The rate-limit window does not establish analytics retention. Actual analytics retention, residency and transfer safeguards remain account-specific evidence requirements.

Evidence Status: Source-integrated; runtime and legal evidence open

Privacy Policy: upstash.com

Email and Magic-Link Delivery - Resend

Purpose: Transactional email, account-security messages, compliance alerts, and opted-in communications

Data Shared: Recipient email address, bounded message content, and delivery status needed to send and reconcile the message.

Operational Boundary: The verified scrubmetadata.com sending domain was observed in us-east-1, United States, on 5 September 2026, with open and click tracking disabled. Resend publishes a 30-day retention period for email content, metadata, delivery events, logs and metrics on Free, Pro and Scale. This does not delete copies in our application, recipient mailboxes or Zoho Mail, or establish complete provider backup erasure. The sending region does not establish every storage or support location. Zoho Mail separately handles contact mailbox replies. Marketing and newsletter messages require explicit opt-in and remain suppressible.

Evidence Status: Source-integrated; runtime and legal evidence open

Privacy Policy: resend.com

Contact Mailbox Hosting - Zoho Mail

Purpose: Receiving and replying to privacy, security, support, billing, and legal enquiries sent to the published ScrubMetadata contact addresses

Data Shared: Sender and recipient addresses, message content, attachments, and delivery metadata supplied by the person who contacts ScrubMetadata. Customers must not send raw files or raw metadata through these contact channels.

Operational Boundary: Zoho Mail hosts the monitored contact mailbox and aliases. Processing location, retention, transfer mechanism, DPA, incident-contact, and change-notice facts remain owner, legal, and provider evidence gates.

Evidence Status: Source-integrated; runtime and legal evidence open

Privacy Policy: www.zoho.com

Privacy-Filtered Error Monitoring - Sentry

Purpose: Application error diagnosis and security/availability alerting

Data Shared: Privacy-filtered technical error context and an internal account identifier where set. This is not necessarily anonymous. Customer file bytes, local paths, raw filenames, raw metadata values, authorization credentials, and message bodies are excluded.

Operational Boundary: Monitoring is governed by the application redaction boundary. Provider enablement and production monitoring evidence remain separate release gates.

Evidence Status: Source-integrated; runtime and legal evidence open

Privacy Policy: sentry.io

DNS and Bot Protection - Cloudflare

Purpose: DNS, network protection, and configured Turnstile bot checks on public intake surfaces

Data Shared: Technical network and challenge information, including IP address, TLS fingerprint, user-agent, site key and associated origin for Turnstile; no customer file content or raw metadata values.

Operational Boundary: Cloudflare is not an interactive authentication provider. Its Turnstile notice distinguishes processing on the website operator's behalf for bot protection from its independent controller processing to improve bot detection. Exact enabled services, locations, and transfer safeguards remain owner/legal/provider evidence gates.

Evidence Status: Source-integrated; runtime and legal evidence open

Privacy Policy: www.cloudflare.com

Interactive authentication: Resend-delivered one-time email magic link. NextAuth is used internally as the database-session facade and is not a third-party OAuth identity provider.

Evidence boundary: Published provider terms establish the contract routes described here, not acceptance by our production accounts. Account coverage, locations, transfer mechanisms, DPAs, SCCs and assurance reports require current owner, legal, and provider evidence. A separate signature is needed only where the governing agreement requires one; incorporation does not fill missing parties or transfer annexes.

Last technical source review: 2026-09-05.

Important: The supported local processing path excludes original file bytes, raw extracted metadata, raw filenames, and local paths from these providers. This does not cover attachments someone sends to a contact mailbox. Do not send raw customer files or metadata to support.

Data Retention Policy

How Long We Keep Your Data

Raw files processed locally

Supported raw-file processing stays on your device. Local buffers, downloads and browser storage are controlled by the application, browser and operating system. We do not promise immediate physical erasure from device memory. Support attachments are a separate data path.

Account Information: Active account and reviewed offboarding

Email, name, and profile information are retained while the account is active. Exit is operator-managed on request. The proposed operational timeframe for deletion from active customer-directed stores is 30 days after the service ends and an authorized instruction is recorded; this is not a statutory deadline. Completion is confirmed in a dated record covering return, deletion, retention exceptions, providers and backups.

Operational records

Short-lived counters expire under their configured controls. Other billing, security and diagnostic records have different retention needs. The final schedule must identify each period or determinable criterion and its starting event; no uniform 13-month deletion guarantee is made.

Audit Logs: retention policy

Security and compliance audit logs (login attempts, API access) follow documented retention and applicable regulatory obligations. Specific preservation exceptions are assessed under their recorded legal basis.

Paddle payment records

Paddle determines retention for its own payment and financial records under its privacy notice and applicable obligations. This may continue after your ScrubMetadata subscription ends.

Support correspondence and backups

Provider-held support, archive and backup records are retained per provider terms; where an expiry has not been verified, the confirmation identifies it as “expiry not verified.” No fixed provider-erasure deadline is promised. Archiving is not deletion. A retention exception must identify a continuing purpose or legal obligation and an endpoint or review criterion.

Data Minimization

Raw-file processing is minimized by architecture and compliance records are designed to use hashes, counts and redacted summaries; complete field-by-field coverage remains under verification. Retention and deletion workflows are policy-governed; complete execution, lawful-preservation and legal-hold evidence remain open.

Data Protection Contact

For any questions about how we handle your data, privacy concerns, or to exercise your rights under GDPR/CCPA:

Privacy Contact

Email: privacy@scrubmetadata.com

General Support: support@scrubmetadata.com

Routing evidence: These are the canonical published contact routes. DNS, mailbox or alias routing, monitored ownership, receipt, response-time, PGP, and vulnerability-reward claims remain owner and provider runtime evidence gates.

Representative boundary: The privacy contact is an operational enquiry channel, not a statement that an EU or UK statutory representative has been appointed. Representative applicability, identity, postal address, and publication remain an owner and legal gate.

For EU Residents

If you are located in the European Union and have concerns about how we handle your data, you have the right to lodge a complaint with your local data protection authority (supervisory authority).

Children's Privacy

This is a professional service for authorized adult users, not a service directed to children.

We do not knowingly collect, use, or disclose personal information from children under 13 years of age. If you are under 13, please do not use this Service or provide any information to us.

If we learn that we have collected personal information from a child under 13 without parental consent, we will delete that information as quickly as possible. If you believe we might have information from or about a child under 13, please contact us immediately at privacy@scrubmetadata.com.

Note for Parents: If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact us so that we can take necessary action.

California Privacy Rights (CCPA / CPRA)

Where the California Consumer Privacy Act, as amended, applies to the processing, California residents have the rights below. Applicability depends on the activity and legal thresholds, not simply access to this website.

Right to Know

Request categories and specific pieces of personal information, including information beyond 12 months where the law provides

Right to Delete

Request deletion of your personal information, subject to certain exceptions

Right to Opt Out of Sale or Sharing

Opt out of sale or sharing where applicable. The absence of a sale does not by itself establish the absence of sharing for cross-context behavioral advertising

Right to Non-Discrimination

We will not discriminate against you for exercising any of your CCPA rights

Right to Correct

Request correction of inaccurate personal information

Right to Limit Use of Sensitive Information

Limit uses and disclosures of sensitive personal information where this right applies

How to Exercise Your Rights

To exercise any of these rights, please email us at privacy@scrubmetadata.com with any description that lets us understand your request. A particular subject line is not required. An authorized agent may act where the law permits.

Access, correction and deletion requests may require proportionate identity verification and normally receive a response within 45 days, with a further 45 days where permitted and explained. Sale or sharing opt-outs do not require that verification and follow their separate, shorter legal timetable. We do not use the access-request timetable to delay an opt-out.

Shine the Light Law

California Civil Code Section 1798.83 permits California residents to request certain information about disclosure of personal information to third parties for direct marketing purposes. We do not share personal information with third parties for their direct marketing purposes.

Privacy by Design Principles

These source-reviewed foundations support Article 25 work. Runtime effectiveness, controller context, owner review and legal compliance remain separately assessed.

Purpose and lawfulness

Purpose, legal-basis and consent workflows record accountable evidence; applicability and legal validity remain controller-reviewed.

Transparency

Public and customer notice controls use versioned, evidence-scoped publication records; owner approval and delivery evidence remain separate gates.

Data minimization

Raw-file processing is minimized by architecture and compliance records are designed to use hashes, counts and redacted summaries; complete field-by-field coverage remains under verification.

Storage limitation

Retention and deletion workflows are policy-governed; complete execution, lawful-preservation and legal-hold evidence remain open.

Integrity and confidentiality

Role, step-up, device, four-eyes and audit controls exist; exact per-action enforcement requires signed current-source replay.

Accountability and data-subject rights

DSAR workflows support accountable intake and lifecycle evidence; identity, fulfillment, delivery and legal exceptions remain separately gated.

Evidence status: source reviewed runtime evidence incomplete. Legal compliance: not determined.

Privacy Notice | ScrubMetadata