← Site DNAPrivacy

Your evidence stays under your control.

Site DNA sends a public URL to its analyzer only when you start a public capture. The server renders that page to produce structured DOM, style, layout, accessibility, runtime, and route evidence. It does not intentionally store passwords, cookies, form values, response bodies, or page screenshots in exported reports.

Public background jobs store their route frontier and structured reports in private Vercel Blob objects. Records are marked to expire after seven days; an authenticated daily cleanup normally removes them within eight days of creation. The browser keeps the random job capability locally and the server stores only its hash in the job record. Anyone who obtains that capability can read or control that job until removal, so do not share browser storage or the token.

Completed coverage sessions are also stored in your browser with IndexedDB. The Chrome companion stores authenticated evidence only in extension-local storage. Nothing is exported until you choose an export action. Public manifest and brief exports redact URL query values by default and offer additional text/private-term controls; full local archives are unredacted.

Server and hosting providers may retain ordinary security and operational logs, including request metadata, under their own retention controls. Do not analyze a site or account unless you are authorized to do so, and review exports before sharing them.

To remove local data, delete saved sessions in the analyzer and use the companion’s per-origin deletion or confirmed reset controls. Server-side public-job records expire automatically under the policy above.