Privacy Policy
Last updated: June 24, 2026
1. Data We Collect
We collect: (a) account information (email, API keys), (b) file hashes (never file contents), (c) receipt metadata (timestamps, signatures), and (d) usage logs (API requests, IP addresses).
2. What We Don't Collect
We never see, store, or process your file contents. All hashing happens client-side or through one-way cryptographic functions. We only store the resulting hash — a 64-character string that cannot be reversed to recover the original file.
3. How We Use Data
We use collected data to: (a) provide the provenance service, (b) verify receipts, (c) maintain the immutable ledger, (d) improve service reliability, and (e) communicate with you about your account.
4. Data Sharing
We do not sell your data. We may share data with: (a) service providers who assist in operating Krusade, (b) law enforcement when legally required, or (c) with your explicit consent.
5. Security
We use industry-standard encryption (TLS 1.3), access controls, and regular security audits. Your API keys are hashed at rest. We cannot recover lost keys.
6. Retention
Account data is retained while your account is active. Receipts in the immutable ledger are permanent by design — they cannot be deleted without breaking the chain.
7. Your Rights
You can: (a) access your account data, (b) export your receipts, (c) delete your account (which removes your API keys but not ledger entries), and (d) request data correction.
8. Cookies
We use essential cookies for authentication and session management. We do not use tracking cookies or third-party analytics.
9. Changes
We may update this Privacy Policy. Significant changes will be communicated via email or in-service notification.
10. Contact
Privacy questions? Contact us at [email protected].