privacy

Where your data sits, and where it passes through.

CSINT's public surface is static and designed to minimise data collection. This page explains what stays in your browser, which requests pass through separate Worker services, and when retained records are deleted.

local-firstbounded accountsno tracking

note 01

What stays in your browser

Resource notes, evidence logs, report drafts, Event Desk workspaces, your theme/accent choice, and the latest update you have seen live in your browser's localStorage. They are never sent to a server, no other user can see them, and clearing browser data deletes them. Use the download buttons in each tool if you want a backup.

note 02

What passes through Worker surfaces

The public pages are static. Selected functions use separate Cloudflare Workers, including accounts, the chat assistant, Web Archive Desk, and Event Desk Pro. A chat question may be sent to the model and an archive query may be sent to the relevant archive service. Event Desk Pro stores only data you explicitly save. Each surface states its boundary before use.

note 03

Paid n8n handoff intake

After written acceptance, the parties can use a local report or screen share. With the optional encrypted transfer, the customer's browser encrypts the baseline, candidate, and scope to Ahmet's public key and downloads a .csint-handoff package to the customer's device. The customer sends that package through the agreed email or other channel; it is never uploaded to or stored by CSINT. The admin imports and decrypts it locally, then prepares a DRAFT PDF and SHA-256 evidence ZIP after human review. Link data stays only in the URL fragment, and the private key stays in Ahmet's local browser profile.

note 04

Event Verification, Incident Lab, and report tools

The standard Event Verification, Incident Lab, Inquiry Room, Evidence Builder, and Report Builder run entirely in your browser: claims, evidence, and report text never leave your device. Only packets you explicitly save to the Event Workspace are stored server-side.

note 05

No unnecessary personal data

The standard static site has no tracking cookies and no analytics scripts. If you use membership or Event Desk Pro, an email digest, session, membership, plan, and related security records may be processed. These fields support access, notifications, invoices, and auditability, not profiling.

note 06

Bot and abuse protection

Cloudflare Turnstile runs when an owner requests a sign-in code and when a private client report is opened or answered. The Worker checks the short-lived browser result through Cloudflare Siteverify; the secret key is never sent to the browser. This control is used to reduce automated requests and service abuse, not for advertising analytics. Cloudflare may process its own technical network and browser signals during verification.

note 07

Limits of a static site

The site is served as static files from GitHub Pages. Hosting and CDN layers (GitHub, Cloudflare) may keep their own standard access logs, which we do not control or access. When you open an external link from the archive, that site's own privacy policy applies.

note 08

Safe research expectations

Think twice before typing sensitive data about real people even into local tools; storing and sharing exported files is your responsibility. See the Ethics and OPSEC pages for research boundaries.

note 09

Security and data reports

If you spot a privacy risk, data leak, or vulnerability, use the security reporting channel on the Support page or email [email protected]. Simple issues such as broken links can go to the Telegram channel.