Legal

Privacy Policy

Last updated: June 24, 2026

1. Data We Collect

We collect: (a) account information (email, API keys), (b) file hashes (never file contents), (c) receipt metadata (timestamps, signatures), and (d) usage logs (API requests, IP addresses).

2. What We Don't Collect

We never see, store, or process your file contents. All hashing happens client-side or through one-way cryptographic functions. We only store the resulting hash — a 64-character string that cannot be reversed to recover the original file.

3. How We Use Data

We use collected data to: (a) provide the provenance service, (b) verify receipts, (c) maintain the immutable ledger, (d) improve service reliability, and (e) communicate with you about your account.

4. Data Sharing

We do not sell your data. We may share data with: (a) service providers who assist in operating Krusade, (b) law enforcement when legally required, or (c) with your explicit consent.

5. Security

We use industry-standard encryption (TLS 1.3), access controls, and regular security audits. Your API keys are hashed at rest. We cannot recover lost keys.

6. Retention

Account data is retained while your account is active. Receipts in the immutable ledger are permanent by design — they cannot be deleted without breaking the chain.

7. Your Rights

You can: (a) access your account data, (b) export your receipts, (c) delete your account (which removes your API keys but not ledger entries), and (d) request data correction.

8. Cookies

We use essential cookies for authentication and session management. We do not use tracking cookies or third-party analytics.

9. Changes

We may update this Privacy Policy. Significant changes will be communicated via email or in-service notification.

10. Contact

Privacy questions? Contact us at [email protected].