Privacy policy

What we collect, what happens to it, how long we keep it, and what you can ask us to do about it.

Before you rely on this

Proofwire is currently operated by a private individual in Italy; VAT registration is in progress and the company details will appear here once it completes. Until then we cannot issue VAT invoices, and these documents have not yet been reviewed by a lawyer. If you are evaluating us as a supplier under a procurement process, tell us and we will say plainly where we stand rather than let you find out at contract stage.

Last updated 2026-08-28

The short version

Two different kinds of personal data pass through this service, and they are treated differently.

Your account data — your email address, your name if you give one, your billing details. We are the controller of that.

The values you submit for verification — phone numbers, email addresses, IP addresses. Those usually belong to your customers, not to you and not to us. You remain the controller; we process them on your instructions and nothing else.

What we store, and what we deliberately do not

DataWhat is actually keptHow long
AccountEmail, optional name, organisation name, a scrypt hash of your password. Never the password.Until you close the account
Single lookupsA redacted preview and a SHA-256 hash — never the full value.ma***@example.com, not the address.90 days
Bulk uploadsThe values you uploaded, so you can download your results. Reduced to the same redacted form afterwards.30 days after the job finishes
Result cacheKeyed by hash, and the stored result has the original value stripped out. The cache cannot be read back into a list of what was checked.7 days phone, 3 days email, 24 hours IP
Account and billing eventsPlan changes, cancellations, key creation, payment events24 months
Credit ledgerMovements of credits and moneyKept as long as tax law requires, even after erasure
Supplier cost recordsWhat each data supplier charged us, and which account the query was forKept as accounting; the link to your account is removed on erasure

The periods above are not aspirations. They are constants in the source code, imported by this page from the same file the deletion job reads, so this document cannot state a period the software does not apply.

Why we are allowed to process it

Your account data — to perform the contract you entered when you signed up. Article 6(1)(b).

Values you submit — we process them as your processor, on your documented instructions. Establishing a lawful basis for holding your customers' data in the first place is yours, not ours. Article 28.

Security and abuse prevention — legitimate interests, Article 6(1)(f). Keeping a record of who created an API key is how a compromised account gets noticed.

Who else sees it

8 sub-processors, each listed by name with exactly what reaches them and where they are: the full list.

The two verification vendors are worth calling out. A phone number goes to the carrier register; an email address goes to the mailbox verifier. Neither is told who submitted it, which account it belongs to, or anything else you have checked.

We do not sell data, we do not build a marketing profile from it, and nothing you verify is used to improve a product other than by being counted.

What you can ask for

Access, correction, erasure, restriction, portability, and objection. Write to the address below and a person will act on it — erasure is a command we can run, not a promise we make and then perform by hand against a live database.

Two exceptions, stated plainly rather than buried. The credit ledger survives erasure: it records money that changed hands and tax law requires keeping it. Supplier cost records survive too, but not attached to you — the row saying we paid a supplier a fraction of a cent stays in our accounts, and the field naming your account is emptied. We keep those rows because deleting them would understate what we spent, which is a number we enforce a monthly limit against.

Everything else goes.

You can also complain to your national data protection authority. In Italy that is the Garante per la protezione dei dati personali.

Cookies

One cookie, pw_session, set when you sign in and holding a random token whose hash is what the database stores. It is strictly necessary for the dashboard to work, so it needs no consent banner. There is no analytics cookie, no advertising pixel and no third-party tracker on this site.

Contact

Privacy questions and data requests: privacy@proofwire.app
Everything else: support@proofwire.app

A person reads both. We aim to answer data requests within 30 days, which is the statutory limit, and in practice much sooner.