1. Who we are
Orisift is a trading name of Tervra Limited, company number 17410031, registered office 108 Fonthill Road, London, England, N4 3HT. Tervra Limited is the data controller for your account data and can be reached at privacy@orisift.com.
For identifiers you submit for validation, you are the controller and we act as your processor: we check what you send us, on your instruction, and return the result.
For your own account data, such as your email address and billing details, we are the controller.
2. What we collect and why
Account data: your email address, name and company if given, a password stored only as an Argon2id hash, and a Stripe customer reference. Used to operate your account and bill you.
Submitted identifiers: a normalised identifier, fingerprint and result evidence are stored with every lookup. Normalisation is not anonymisation; email addresses, domains, phone numbers and IP addresses remain identifiable, and the normalised value can equal the submitted value. With retain_input: false, newly saved results omit the separate input property and scrub other strings containing the submitted form, except strings equal to the normalised value. retain_input: true preserves the submitted form as well.
Results: the verdict, evidence and coverage limits for each lookup, so you can review your history.
Technical data: a keyed hash of the IP address for rate limiting and abuse prevention. The raw address is not stored. Session tokens and API keys are stored only as keyed hashes.
3. What we never do
We do not sell personal data, and we do not build or sell a database of the identifiers our customers check.
We do not write identifiers, passwords, session tokens or API keys to logs. Our logger fingerprints identifiers and drops credentials entirely.
We do not use your submitted identifiers to train any model.
4. Processors and international transfers
Public DNS resolvers: hostnames and IP addresses being checked are, necessarily, sent to public DNS resolvers as part of the lookup. This is inherent to checking a domain or address at all.
Anthropic: when AI is allowed for your account and available, lookup evidence is sent to Anthropic for assessment. The submitted identifier is removed from the evidence before it is sent. You can opt out in Settings for future dashboard and API lookups. Anonymous previews do not use AI. Opting out does not recall information already sent or stop requests already in progress.
Stripe: payment processing. Card details go directly to Stripe and never reach our servers.
Our database and application hosting providers store the data described above.
Some of these processors are located outside the UK and EEA. Transfers rely on the processor's own transfer mechanism, typically Standard Contractual Clauses. We have not obtained an independent audit of those arrangements.
5. Retention
Scheduled daily cleanup targets lookups older than 90 days; deletion depends on that job running. Backups have a separate retention lifecycle.
Expired sessions and used authentication tokens are purged after 7 days; failed-login records after 30 days.
Account and billing records are retained while the account is open, and afterwards only as long as tax and accounting law requires.
Deleting your account removes its active records: the account, its keys, its lookup history, its ledger and the sign-in and password-reset attempt records held against its email address. An opaque account reference and the deletion reason are retained as a record that the deletion happened. That reference is not anonymous: it is the identifier the account was known by, and it can be matched to other records that carry it. Encrypted backups taken before the deletion are scheduled for deletion 35 days after they are taken, with additional processing time by the storage provider before removal completes. Backups are not edited, so data can persist in one until it is removed. Deletions you request are recorded in a separate, immutable log retained indefinitely and re-applied to any restore, so a restore cannot bring back an account that asked to be removed. Deletion does not recall data already sent to a processor.
6. Your rights
Depending on where you live, you may have rights to access, correct, delete or export your personal data, to object to or restrict processing, and to complain to a supervisory authority.
Deletion is available immediately in Settings. For anything else, email privacy@orisift.com and we will respond within 30 days.
If you are an end user whose identifier was checked by one of our customers, that customer is the controller and you should contact them. We will assist them in responding to you, and you can reach us at privacy@orisift.com if you cannot identify who checked your details.
7. Security
Passwords use Argon2id. Session tokens, API keys and reset links are stored only as keyed HMAC digests, so a database dump alone does not yield usable credentials. Traffic is served over HTTPS with HSTS, and the application sets a restrictive Content-Security-Policy.
No system is perfectly secure, and we have not undergone an independent security audit or obtained any compliance certification. We do not claim SOC 2, ISO 27001 or any equivalent attestation.
8. Contact and changes
Email privacy@orisift.com about anything in this notice. We will tell you by email about material changes at least 14 days before they take effect.
See also the terms of service and the coverage matrix.