Last reviewed: 2026-08-20
Privacy policy
This page describes what Valyzer actually does with your data today: what it stores, through which cookies and for what purpose. It does not include a registered company identity, a legal retention schedule or a rights channel, because as of the review date below none of that text exists in this repository — it is marked as missing rather than invented.
Who processes your data
Valyzer is a product under active development. The legal identity of the entity responsible for processing is not yet defined in this repository's code or documentation.
What data we process
Account: the email address you provide when signing in with Google or with a one-time email link. If you sign in with a password instead, that password is handled by the configured authentication provider, never by Valyzer in plain text.
Session: once you sign in, the server writes a cookie (`__Host-valyzer_session`) marked HttpOnly and Secure — only the server can read it — that expires after one hour or when you sign out.
Sign-in in progress: while you complete Google sign-in or the email-link flow, a second, temporary cookie (`__Host-valyzer_oauth`), also HttpOnly and Secure, holds that operation's state for at most ten minutes and is cleared as soon as it finishes.
Analytics, only if you allow it: if you accept the cookie notice, we store your decision in our own cookie (`valyzer_consent`) and record minimal, anonymous usage events — see the cookie policy. Without that explicit acceptance, no event is ever recorded.
Public content: what Valyzer publishes (events, indicators, evidence) comes from official sources with a rights decision reviewed before publication. It is not personal data about you.
Who we share it with
The service runs on Cloudflare (web app and API) and a PostgreSQL database managed on Supabase. We use no third-party analytics or advertising: any usage event you agree to share goes only to a Valyzer endpoint of our own, with no external SDK.
How long cookies last
The session cookie lasts one hour. The sign-in cookie lasts ten minutes. The analytics consent cookie lasts about 180 days, or until you withdraw it.
Your rights
If the law that applies to you grants rights of access, rectification, erasure, objection or portability over your data, the channel to exercise them is meant to appear on the contact page — today, however, none has been confirmed yet.
Changes to this policy
When what the system actually does changes, we will update this page. The last-reviewed date appears at the top.
Missing legal information
- TODO_LEGAL: the registered company name, address and tax id of the entity responsible for processing are missing.
- TODO_LEGAL: a verifiable data-protection contact or DPO is missing.
- TODO_LEGAL: the hosting region for Supabase and Cloudflare still needs confirming and documenting for international transfer purposes.
- TODO_LEGAL: a defined retention period for user accounts and for analytics events is missing, once the structured log sink is replaced with a persistent store.
- TODO_LEGAL: a verified contact channel for exercising access, rectification, erasure, objection or portability rights is missing.