Privacy Policy

This describes what Pigfox LLC actually does with data on pigfox.com today — the retention windows are the ones the code enforces, not aspirations. Last updated 2026-08-03.

Who we are

Pigfox LLC is a Nevada limited liability company, operating since 2005, founded by Peter Sjolin. Our registered address is 1450 Vassar St, Reno, NV 89502. There is no support mailbox: the contact form is the only channel, and it reaches us directly.

Account data

If you create an account we store your email address and the date you signed up. That is the whole account record.

  • There is no password. Sign-in works by emailed magic link, so we never hold a password to lose.
  • Sign-in links, session cookies and API tokens are stored as hashes, never as the value that was issued to you. Someone reading our database cannot sign in as you.
  • If you buy something, we store a Stripe customer reference and your subscription status. Card details are entered on Stripe's own form and never reach our servers.
  • Your credit ledger is append-only: one row per purchase and one per tool run, recording which tool ran and what it cost. It is a consumption history and it is kept for the life of the account.

IP addresses

Free-tier limits are enforced per visitor, so we need to recognize a repeat visitor without identifying them. IP addresses are therefore stored only as salted hashes — the original address is not recoverable from what we keep.

There is one exception, and we would rather state it than have you find it: when you submit the contact form, your name, email address, message and raw IP address are written to a spool file on our server while the message is delivered. That file is deleted by a sweep that runs continuously and removes anything older than a day.

What each tool keeps, and for how long

Tool data is ephemeral by design. These are the actual windows:

DataRetention
Photos you upload for a reverse-image checkHeld in memory only, roughly two minutes, then dropped. Never written to disk or a database.
TraceCheck check records (the name and role you entered, and the result)Deleted five minutes after the result reaches you; one hour if it never does.
Per-tool free-usage counters (a salted IP hash and a timestamp)24 hours
The TraceCheck free-check log and the cognitive-load usage log30 days
Vendor spend meters (a timestamp per paid API call — no IP, no content)60 days
Contact-form spool file (includes a raw IP)About one day

Deletion is not manual. Background sweeps run every 15 minutes and remove whatever has passed its window.

Several tools keep nothing at all. The phishing analyzer, the email-header analyzer, the prompt-injection tester and the document-authenticity scan run entirely in our own process: what you paste or upload is read to produce the report and then discarded, and no third party is involved. Each of those pages says so, and those statements are accurate.

Who else sees your data

Some tools cannot work without sending your input somewhere else — a reverse-image search happens at a search provider, a breach lookup happens at the breach database. Every such recipient is listed, with what leaves, on the Subprocessors page. The tool pages themselves also name the recipient at the point where you type.

Separately: several tools take a URL or domain from you and fetch it. Doing that necessarily discloses your submitted address to that host and to the DNS resolvers in between. That is inherent to the check, not something we can avoid.

Analytics and cookies

We load Google Tag Manager and Google Analytics on every page of this site. They set cookies and collect your visit — page URL, referrer, device and browser characteristics — and they do so before you are asked and without your prior consent. We do not currently offer a consent mechanism or a way to refuse them from within the site.

Stated plainly so you can act on it: if you do not want that collection, block those scripts in your browser or use an extension that does, because this site will not stop them for you.

Deleting your account

You can delete your account yourself, at any time, from your account page. It asks you to type the word DELETE to confirm, because it cannot be undone.

Deleting erases your account and email address, every sign-in session, your subscription record and its Stripe customer reference, your credit ledger, and your API tokens.

Two things you should know before you do it:

  • It does not cancel your Stripe billing. If you have an active subscription, cancel it in the billing portal first, or it will keep renewing against your card.
  • Unspent credits are forfeited and are not refunded. See the Refund Policy.

Two internal counters keep their rows with your account reference removed, so they no longer point at you: the funnel measurements and the MCP call log. Neither holds anything you submitted — they record an event name, which tool ran, and what a call cost. After deletion they are unattributed totals.

Children

This site is not directed to children and we do not knowingly collect data from anyone under 16.

Changes

If this policy changes materially we will change the date at the top. We do not keep a mailing list to notify you from.

Contact

Questions about this policy, or a request about your data, go through the contact form.