Data Handling Policy

Last updated: June 3, 2026

Summary for Non-Lawyers

  • Confidentiality by Design: We process all digital forensic files on disconnected (air-gapped) forensic workstations.
  • No Sale or Exploitation: We never sell, rent, or commercialize your personal information, telemetry, or device logs.
  • Strict Retention Limits: Intake submissions are held only for the duration of the active case response and purged immediately afterward.
  • Legal Resistance: If served with a legal demand for data, we will exhaust all judicial appeals to protect your identity.
  • Minimal Tracking: Our website uses privacy-respecting analytics without setting cookies or sending data to third parties.

DeTechtive is committed to protecting the privacy and security of journalists, human rights defenders, and civil society organizations who interact with us. This document outlines how we collect, process, retain, and protect your data.

1. What this policy covers

This policy covers all interactions with DeTechtive, including:

  • Use of our website (detechtive.io)
  • Submission of information via our emergency intake and contact forms
  • Transmission of files, logs, and system images for mobile forensic analysis
  • Communications over encrypted channels (Signal, PGP email)

2. What data we collect

We restrict our data collection to the minimum required to verify identity and perform forensic triages.

  • Intake Form Data: Name, optional organisation, role, country, preferred contact channel and details, list of affected device types, and the description of the concern.
  • Forensic Data: System dumps, packages list, processes logs, or device directories submitted for analysis. These files are processed entirely offline.
  • Website Analytics: Privacy-respecting, cookieless metrics powered by Cloudflare Web Analytics to monitor site health and page visits. No IP addresses or tracking cookies are logged or sent to third parties.
  • Contact Data: Name, email address, optional organization, reason for contact, and message.

3. How we use your data

Your data is used solely to respond to your specific request:

  • To review, triage, and guide incident response for suspected mobile spyware compromises.
  • To perform deep reverse-engineering and indicator matching on submitted file logs.
  • To address general inquiries, partnership proposals, and press requests.
We never use your data for marketing, profile building, or commercial telemetry.

4. Who has access

Access controls are strictly partitioned at DeTechtive:

  • Only named security researchers and incident response analysts actively assigned to your case have access to your intake submission or forensic logs.
  • Administrative staff do not have access to technical device dumps.
  • Every analyst operates under a strict non-disclosure agreement and technical access audits.

5. Third-party sharing

We do not share any personal identifiers or technical findings with third parties (such as other security labs, newsrooms, or helpdesks) without your explicit, written, and cryptographically signed consent. In cases where sample attribution benefits the wider security community, we will strip all metadata, device IDs, and personal indicators before sharing indicators of compromise (IoCs).

If served with a subpoena, warrant, or court order compelling the disclosure of user data:

  • We will immediately verify the legal validity and jurisdictional authority of the request.
  • We will contest any overly broad or legally deficient demands.
  • We will attempt to notify the affected user prior to disclosure, unless prohibited by a valid non-disclosure order.
  • We will utilize a public warrant canary to signal the receipt of gag orders or national security letters.

7. Data retention

We do not retain logs longer than necessary:

  • Intake Records: Purged from active communication channels 30 days after the case is closed.
  • Forensic Artifacts: Device dumps and logs are securely shredded using standard cryptographic wiping algorithms (e.g. Gutmann method) within 14 days of case completion, unless you request an extended retention window.
  • Contact Submissions: Retained for a maximum of 90 days for correspondence purposes.

8. Your rights

You have full ownership of your data. You have the right to:

  • Request a copy of all information stored about your case.
  • Request the immediate, permanent deletion of all intake records and forensic files at any point.
  • Rectify or update contact details.
To exercise these rights, email security@detechtive.io using our PGP key.

9. Security measures

We deploy robust controls to guard against intrusion:

  • Encryption in Transit: All website forms utilize HTTPS (TLS 1.3). PGP is enforced for sensitive email correspondence.
  • Encryption at Rest: Internal databases and workstations use full-disk encryption (AES-256).
  • Air-Gapped Systems: Forensic analyses of mobile files are executed on hardware units completely isolated from the internet.

10. Contact

If you have any questions regarding this policy or our data handling practices, please contact our data officer at:
Email: security@detechtive.io (PGP key details are available on our Verify page)