DisclosureLens

Privacy

This notice explains two separate things, because DisclosureLens involves two very different groups of people:

  1. People who use this site or the API — what we collect from you, which is very little.
  2. People who may appear inside the public records we index — breach notifications and related documents published by regulators, which can contain personal data about individuals who never interacted with us.

Who we are

DisclosureLens is operated by [PLACEHOLDER: legal entity name, legal form, and registered address]. For privacy questions and requests, contact corrections@disclosurelens.com or use the report / removal page.

[PLACEHOLDER: data protection officer, if one is appointed] [PLACEHOLDER: EU/UK Article 27 representative, if required] [PLACEHOLDER: lawful basis relied on — e.g. legitimate interests and/or the journalism / special-purposes exemption — and the balancing assessment behind it]

1. If you use the site or the API

Browsing without an account

Nearly all of DisclosureLens is browsable anonymously; only account settings and the admin tools require signing in. If you browse without signing in:

If you create an account

Accounts are handled by Clerk, our identity provider. Clerk operates the sign-in and sign-up screens. We never receive or store your password. From Clerk we receive and store:

We additionally store, for accounts that use those features:

We do not collect payment data. No payment processor is integrated and no card data reaches us.

Server logs

Our web server records standard access logs. Authorization headers and credentials are redacted before writing. Logs rotate on size with a configured maximum retention of approximately 180 days [PLACEHOLDER: confirm whether logs are copied or backed up anywhere beyond the production host]. We periodically analyze these access logs with a self-hosted tool (no third party involved) to understand traffic. No IP address, user-agent, device, or location field is stored in our application database.

Cookies

We set none. If you sign in, Clerk sets the session cookies needed to keep you signed in. [PLACEHOLDER: enumerate the Clerk cookie names, purposes, and lifetimes, and decide whether a consent mechanism is required in your target markets]

2. Personal data inside the records we index

This is the part that most often matters to people who have never used the site. We index documents that regulators and other sources publish, and those documents can contain personal data — for example the text of a breach-notification letter, or a health-sector breach report. We also index threat-actor leak-site claims, which are unverified allegations published by criminal groups.

Being precise about what is and is not filtered:

If personal data about you appears in a record, use the report / removal page. We would rather hear from you than not.

Who else processes data

We use the following providers. We do not sell personal data, and we do not use it for advertising.

For clarity, because they appear in our configuration but are not in use: we run no payment processor, no error-reporting service, and no third-party analytics or product-telemetry backend (our only traffic analysis is the self-hosted server-log review described above).

[PLACEHOLDER: data residency — the regions of the hosting, object storage, identity, and email tenants] [PLACEHOLDER: international transfer mechanism (SCCs / DPAs) for each provider]

Retention

[PLACEHOLDER: define a retention period for each category — account records, email delivery logs, suppression lists, usage counters, admin audit logs, archived source documents, and server access logs.]

Two things we should state plainly today, because they are current practice rather than aspiration:

Your rights

Depending on where you live, you may have rights to access, correct, delete, port, or object to the processing of your personal data, and to complain to a supervisory authority.

To exercise any of them, use the report / removal page or email corrections@disclosurelens.com. Requests are handled manually — there is no self-service export or deletion tool today. We aim to acknowledge within 48 hours and may need to verify your identity before acting on a deletion request.

[PLACEHOLDER: US state privacy disclosures — whether any activity constitutes a “sale” or “sharing”, the opt-out mechanism if so, and the status of any data-broker registrations] [PLACEHOLDER: minimum age / children’s data position]

Changes

We will post any change here and update the date below. [PLACEHOLDER: effective date]