Trust center · the reference pages

Trust center

Who touches your data, how to reach us about security, what gets deleted and when, and every incident we have had. The companion to the security page, in reference form.

LAST REVIEWED SEPTEMBER 3RD, 2026

Subprocessors

SUBPROCESSORS · P. 01

A subprocessor is another company that handles some of your data on our behalf. This is the complete list, and the privacy policy carries the same four names. We keep it short on purpose, and we announce any addition 30 days before it takes effect.

Subprocessor What it does Data it handles Location
Cloudflare Infrastructure — hosting, database, and document reading, all inside Cloudflare's own network All application data, as the platform everything runs on. Sensitive fields sit there as ciphertext; a scan image exists only in memory while the request runs and is discarded when it returns, never written to storage. Also carries reminder email as the fallback if Resend is not configured, under the same content rule. United States, with a global edge network
Resend Transactional email — delivers reminders Exactly the recipient address, the subject, and a body of item labels and dates — never identifiers, notes, or any link carrying a token. Reminder emails contain item labels by design, which is one reason the app coaches you to keep labels non-sensitive. Resend also reports bounces and spam complaints back to us. United States
Stripe Billing and subscription management Email address, subscription status, and payment details — entered on Stripe-hosted pages, so card numbers never touch our servers. United States
Proton Mail Hosts our support, privacy, and security mailboxes Whatever you choose to write to us at a validthru.app address, and nothing from the product itself. Keep identifier numbers out of email; the app is the place for those. Switzerland

Document reading stays on Workers AI, inside the same Cloudflare infrastructure that hosts the product. Scan images are never sent to an external AI provider — there is no other company in that path.

There is no other third-party data egress of any kind: no analytics service, no error-reporting service, no font or script host. Any addition to this table is announced 30 days before it handles anything.


Security contact and response times

CONTACT · P. 02

Report vulnerabilities to security@validthru.app. Plain email is fine; include enough detail to reproduce the issue. The same contact is published in machine-readable form at /.well-known/security.txt. These are commitments, not aspirations:

Within 72 hours T+72 H
Acknowledgment

A person confirms we received your report and owns it from there. No autoresponder dead ends.

Within 7 days T+7 D
Assessment

You get our severity assessment and a remediation plan, or our reasoning if we believe the report is not a vulnerability.

Until resolved ONGOING
Updates and disclosure

Progress updates at least weekly, disclosure coordinated with you, and credit if you want it. No legal action against good-faith research.


Incident history

INCIDENTS · P. 03

None to date.

No incidents have occurred. This section exists so there is an obvious place to check.

If an incident happens, it will be published here: what happened, what was reachable — readable operational data, ciphertext only, or decrypted sensitive data — for which users, over what window, and what we changed. If sensitive data was plausibly exposed in decrypted form, affected users hear from us directly and promptly. This page is the record, not the notification.


Deletion policy

DELETION · P. 04

What gets deleted, when, and whether you can change the schedule. Deletion means removal from live systems immediately; database restore history ages out on the stated cycle and is never restored except for disaster recovery.

Scan images NOT STORED
Not stored; read and discarded in the request. The photograph is held in memory only while the request runs and is gone when the response returns — never written to a database, an object store, a cache, or a log, and no preview or thumbnail is derived from it. There is no clock to run, because there is nothing to delete.
Extracted fields awaiting confirmation 1 HOUR
1 hour, then deleted. The three candidate values a read produces — document type, issuer, expiration date — wait on the confirmation screen and are removed an hour later if you never confirm them. Nothing reaches an item until you do.
Items and dates UNTIL YOU DELETE
Kept until you delete them or your account. Deleting an item is immediate and permanent; there is no recycle bin holding copies you thought were gone.
Your whole account PURGED ON CONFIRMATION
Self-serve, from settings. Sign-in is disabled and sessions are revoked the moment you confirm, and every row belonging to the account is purged from live systems before the confirmation screen loads — within 24 hours at the latest if a step has to be retried. Database restore history expires within 30 days. Export is offered first.

Your data is yours to take

EXPORT · P. 05

Export everything your account holds — items, dates, and the identifiers and notes you entered — as JSON or CSV, from settings, any time. Export is available on every tier, always, with no gate. A free account exports exactly as completely as a paid one, and cancelling never locks you out of your own data.


No tracking

NO TRACKING · P. 06

We do not sell data, run ads, or load third-party trackers. Signed-in pages load no third-party scripts of any kind, and there is no session replay tooling anywhere in the product.

This marketing site sets no cookies — which is why there is no cookie banner — and runs no analytics scripts, no embedded widgets, and no trackers of any kind. It makes no third-party requests at all: the Archivo typeface is served from our own domain, and every request the page you are reading made went to us. The same is true of the app.


LEGAL · P. 07

Like any provider, we can be required to produce data under valid legal process. Our policy: we require valid process before producing anything, we produce the minimum it requires, and we notify you before complying unless the law prohibits it. Requests that arrive without valid process are refused.

The most meaningful number here is what a request can reach: no scan images at all, no unconfirmed fields older than an hour, and no identifiers you never gave us. What we never receive, nobody can demand.


Changes to this page

CHANGELOG · P. 08