The formal policy is the Privacy Notice โ but here's what actually matters, the way we'd want it explained to us.
The only thing we store is your account โ your email and billing. Your report and the data behind it are destroyed on a 30-day clock. Not hidden โ shredded. Never a permanent profile.
Your report is encrypted to a key tied to you. Delete it, or let the 30 days run out, and it becomes permanently unrecoverable.
Your data is not a product we resell, and it never trains a model. We can't sell what we delete โ that's the point.
We only run a full report on an address you've verified is yours. You can't use dirigent to look someone else up.
We use the same public sources an attacker would โ disclosed breaches, public profiles, public records. Nothing private, nothing past a login, every finding traceable to its source.
Plain-language summary. The formal GDPR text is the Privacy Notice (German and English, draft v1 ยท under legal review).