1. Information processed
DeepHelp AI processes the message text, URL string, document, or screenshot you submit. It also processes an opaque browser-session identifier, limited technical request data used for security and rate limiting, and an email address if you join the waitlist.
2. Scan content and history
Raw submitted text, raw uploaded files, and full extracted file text are processed in memory. DeepHelp AI persists a content hash, a short redacted or generated preview, input type, timestamps, processing metadata, verdict fields, and evidence needed for current-session history.
Raw uploads and full extracted text are not written to a database, temporary files, S3, or Buckets. Upload history does not retain the original filename stem.
Creating a public warning link is optional. The link exposes a sanitized warning snapshot, not your private history or submission. Score and confidence, and an eligible website hostname, are excluded unless you choose to include them. Raw messages, uploads, filenames, full URLs, private analysis narratives, and browser-session identifiers are not included in the public snapshot.
Anyone with a public warning link can view it until it expires 30 days after creation or you revoke it from the owning browser session. Reusing the same active link does not extend its expiry. Changing disclosure options replaces the link and revokes the previous one. Revocation or expiry stops future access through DeepHelp, but cannot remove copies already saved by recipients.
3. Browser-session and technical data
The browser creates an opaque random session identifier in localStorage. The API stores only its HMAC hash to scope history and prevent one browser session from viewing another session's records. Client IP addresses are normalized and immediately HMAC-hashed for abuse controls; raw IP addresses are not stored. For protected operational review, DeepHelp also stores a shortened Network ID that rotates daily, coarse country and region when locally or ingress-provided, a bounded country-source label and a conservative possible VPN, proxy, or device-timezone mismatch indicator, browser family and major version, operating-system family, and a broad device class, plus the browser-resolved bounded IANA timezone identifier for daylight-saving-aware operational timestamps. Timezone is not inferred from location or used to replace country. Browser clock readings, raw UTC offsets, the full User-Agent, precise location, device fingerprints, and durable cross-session identity are not stored. This context is available only in a protected individual check detail, not public results, history, metrics, logs, or exports.
4. External processing providers
Depending on deployment settings, our AI provider may process the current submission to support extraction, risk-signal analysis, or explanation refinement. Provider requests use storage-disabled settings, and DeepHelp does not enable browsing, tools, code execution, or external actions for this processing. When enabled, submitted URL strings and selected URLs extracted from documents or screenshots, including decoded QR destinations, may also be checked against our Web Risk reputation service provider; only the URL string is sent, reputation results can only add warnings, and DeepHelp does not persist raw lookup URLs or provider responses. URL history can retain a bounded, redacted URL preview. Local analysis remains available when optional provider features are disabled or unavailable.
5. How information is used
Information is used to provide the requested analysis, maintain session-owned history, protect the beta from abuse, operate and debug the service using bounded metadata, and send product updates to people who join the waitlist.
6. Retention
Raw upload buffers and full extracted text are not retained after processing by DeepHelp AI. Analysis hashes, previews, metadata, verdicts, history records, audit metadata, waitlist emails, sanitized public warning snapshots and their token hashes are persisted. Public-link expiry and revocation do not delete those records. The current repository does not define a public deletion schedule, so formal retention periods require product and legal review.
7. Security and your choices
DeepHelp AI uses session isolation, HMAC hashing, validation, bounded processing, restrictive browser headers, and rate limits. You can clear local browser storage to replace the browser-session identifier, but doing so disconnects that browser from its prior session history.
8. Contact
Send privacy questions to [email protected].