SafeContract
AboutHow to useContact us
← Back to SafeContract
Privacy · For Sellers and Buyers

Privacy Policy

This policy explains what information SafeContract processes during a private delivery, why it is needed, and the choices available to you.

EffectiveAugust 20, 2026
Terms & ConditionsPrivacy Policy

1. Scope and responsible operator

This Privacy Policy applies to people who create deliveries (“Sellers”), people who open, verify, or unlock them (“Buyers”), and visitors to this SafeContract deployment. The operator of the deployment is responsible for personal information processed through it. A production operator must publish its legal name, address, privacy contact, and any required representative or data-protection-officer details before public use.

2. Information we process

Information provided by Sellers

  • delivery title, description, price, currency, selected expiry, and payout method;
  • an EVM-compatible crypto wallet address provided for the Seller payout;
  • uploaded files and file details such as name, type, size, and cryptographic hash;
  • when selected, a website URL, login identifier, and password for authorized credential verification; and
  • the Seller's use of the generated private link and delivery controls.

Information provided by Buyers

  • the private link or delivery token used to open a delivery;
  • questions submitted for file evaluation;
  • a website URL and optional authenticated-page expectation submitted for credential verification;
  • the crypto wallet address used for checkout, the selected network, and the resulting transaction hash and payment status; and
  • checkout, unlock, download, and verification activity, including any crypto-paid verification fee.

Generated and technical information

  • bounded evidence extracted from a file, automated assessment results, limitations, and safety decisions;
  • credential-verification status, attempt count, timestamps, and limited authenticated-page check results;
  • credential-verification diagnostic reports containing redacted control metadata, decision and action records, timings, detected status signals, and error types;
  • delivery, expiry, crypto-payment authorization, and checkout records; and
  • aggregate first-party analytics dimensions derived from event data, including a two-character country or edge code supplied by the production traffic proxy, referrer hostname, page path, broad device category, asset type, payment method, and checkout value; the application does not store the raw IP address for this purpose;
  • when enabled for this deployment and after the current Terms and Privacy acceptance, Yandex Metrica page-view, link-copy, clickmap, ecommerce, and Webvisor usage measurements, along with the browser and traffic information that Yandex processes for its service; the SafeContract integration redacts private-link URLs to the generic /deal path and does not send credentials, file contents, payment details, or its first-party visitor ID to Yandex; and
  • standard server or security logs that a deployment host may collect, such as IP address, request time, route, browser details, and error information.

Information stored in your browser

SafeContract uses session storage to remember whether you accepted the current Terms for the current browser session. If you choose “don't show again,” it also stores the current consent version in local browser storage. The app stores an anonymous random visitor ID in local storage for first-party product analytics. When enabled, Yandex Metrica loads only after the current Terms and Privacy acceptance. SafeContract does not use its first-party storage for advertising or cross-site tracking.

3. Why we use information

We process information to:

  • create, store, display, expire, verify, and unlock private deliveries;
  • run bounded file analysis and authorized credential checks;
  • prepare crypto-payment authorizations, route Seller payouts, provide checkout status, and protect unlock receipts;
  • enforce question, retry, size, security, and abuse-prevention limits;
  • measure aggregate product usage, including broad country/edge distribution, and improve reliability;
  • when enabled and after the current Terms and Privacy acceptance, measure page visits, link-copy actions, and product usage with Yandex Metrica; and
  • debug failures, maintain reliability, and protect users and third parties; and
  • comply with legal obligations and enforce the Terms & Conditions.

4. Legal bases

Where data-protection law requires a legal basis, the basis depends on the processing and your relationship with the operator. It may include performing a contract or taking steps you request, the operator's legitimate interests in providing and securing the service, compliance with legal obligations, and consent where specifically requested. Yandex Metrica is described in this Privacy Policy and loads after the current Terms and Privacy acceptance when enabled for the deployment. You may withdraw consent for future processing where consent is the basis, without affecting processing that already occurred lawfully.

5. How verification handles protected material

Uploaded files

Files are stored as protected opaque bytes. The service may locally extract bounded metadata and printable-text evidence for analysis. Depending on the configured analysis mode, that bounded evidence, the Buyer's question, and a pseudonymous safety identifier may be processed by a local model or a hosted AI provider. The raw uploaded file is not intentionally sent to the AI model in the current workflow. Public responses are passed through the production privacy and safety filters.

Credentials

Credentials are encrypted at rest. During an authorized verification, an isolated browser sends them to the website specified by the Seller, just as a normal login would. The AI planner, if enabled, receives redacted page structure and control labels—not the login or password. Third-party websites process the login under their own privacy policies, and may receive normal connection information from the verification environment. For reliability debugging, each verification attempt also creates an owner-only diagnostic report. The report does not contain the login, password, or raw page body text.

Credential verification

The Buyer's submitted URL is compared with the Seller's protected URL before any navigation. Only the Seller's stored HTTPS URL may be opened by the isolated verifier. The verifier is limited to the login and the optional yes/no authenticated-page expectation; it does not download files, make purchases, send messages, change settings, or reveal credentials to the AI model.

6. When information is shared

Information may be disclosed only as needed to:

  • the Seller or Buyer through the private-link, verification, checkout, and unlock workflow;
  • hosting, storage, security, logging, wallet-connection, blockchain, and other infrastructure providers used by the operator;
  • Yandex, if Yandex Metrica is enabled and the current Terms and Privacy acceptance has been completed, subject to Yandex's own terms and privacy policy;
  • a configured hosted AI provider, limited to the bounded inputs described above;
  • the Seller-specified website during an authorized credential verification;
  • professional advisers, auditors, or a successor operator under confidentiality duties; or
  • authorities or other parties when required by law or reasonably necessary to protect rights, safety, and service integrity.

SafeContract does not sell personal information or share it for cross-context behavioral advertising in the current application. A production operator must update this Policy before adopting a materially different practice.

7. International processing

Infrastructure, AI, wallet-connection, blockchain, or other providers may process information in countries other than your own. The production operator is responsible for identifying those providers and locations and using any safeguards required by applicable law, such as approved contractual terms or another lawful transfer mechanism.

8. Retention and deletion

Protected file and credential payloads are temporary and are deleted when the configured expiry is processed. A checkout or download may also make a payload unavailable. Do not treat SafeContract as permanent storage.

The current database may retain delivery metadata, Buyer questions, privacy-filtered results, credential-verification records, expiry status, crypto-payment authorization records, transaction hashes, wallet addresses, and checkout status after the protected payload expires. The current application has no automatic deletion schedule for those records. Analytics events, including anonymous visitor identifiers and country/edge codes, are configured for a 365-day retention period by default and are purged during backend cleanup. Optional Yandex Metrica data is retained and managed according to the configured Yandex counter and Yandex's policies; server and security-log retention depends on the deployment host. Credential-verification diagnostic reports are retained for 30 days by default and then removed when a later report triggers cleanup. The production operator must set, publish, and enforce retention periods appropriate to its legal obligations.

Browser consent is stored for the current session unless you choose “don't show again,” in which case the current consent version remains in local browser storage until it is cleared or replaced by a later consent version.

9. Security

SafeContract uses measures such as unguessable private tokens, temporary storage, encryption of credentials at rest, isolated login checks, bounded analysis, authorization headers for unlock receipts, and privacy filters. No system is completely secure. Sellers should submit only what is necessary, use the shortest practical expiry, and share links through a trusted channel. Buyers should protect private links and unlocked material.

10. Your choices and rights

Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, or portability; withdraw consent; opt out of certain sharing; or complain to a privacy regulator. These rights may be limited by law and by the need to protect another person's confidential material, verify your authority, prevent fraud, or retain legally required records.

You can clear browser storage through your browser settings. Avoid submitting personal information that is not necessary for the delivery. Requests about a private delivery should include enough information to identify the relevant deployment and record without sending a password or other unnecessary secret.

11. Children

SafeContract is not directed to children, and users must be at least 18. Do not submit a child's personal information unless you have a lawful basis and the production operator has expressly confirmed the service supports that use.

12. Changes to this Policy

We may update this Policy when the service, providers, or legal requirements change. We will change the effective date and may request fresh acceptance when a change is material. The version displayed when you use the platform applies to that use.

13. Contact and complaints

Privacy questions and rights requests should be sent through the privacy or support channel published by the operator of the deployment you use. Operator contact details are not configured in this deployment and must be published before public use. You may also have the right to complain to the data-protection authority where you live or work.

Temporary delivery. Evidence, not guarantees.Payments via configured methods
AboutHow to useContact usTerms & ConditionsPrivacy Policy