Baseline policy · 9 August 2026

Privacy

UNCLMD Preflight is designed to minimize stored data. Anonymous Quick scans are processed to return a report and are not stored as user projects. Operational logs use redacted structured events and should not contain private descriptions.

Account data

When Supabase is configured and you sign in, we store your account identifier, private projects, scans, normalized evidence, findings and explicit Passport-sharing state. Row Level Security restricts user records by owner id.

Launch analytics

We record a small set of first-party operational events. Anonymous events use a salted one-way network-identifier hash; event properties exclude the submitted name and description. No third-party analytics script, advertising identifier or tracking cookie is used.

Source data

We store normalized facts, timestamps, source references and hashes needed to audit conclusions. We avoid retaining full third-party payloads where unnecessary.

Payments

Stripe processes checkout and payment information. We store payment identifiers, status and entitlement—not card numbers.

Cookies

Authentication and language preference use essential cookies. No optional analytics or advertising cookies are installed by default.

Public Passports

Projects are private by default. A Passport becomes public only after its authenticated owner opts in, and it can be revoked.

Contact

Privacy requests: support@blueprintiosystems.com