Privacy Notice
When you upload a document, image, or bounded video, KESTREL retains the byte-authentic original privately on encrypted customer storage together with its byte length, SHA-256 source binding, format, provenance, and bounded derived analysis. Format-specific extraction or normalization creates working representations; it does not replace or alter the authoritative original. Temporary video frames are transferred through process pipes and are not written as retained originals.
The authoritative original and workspace conversation remain in your account across browser closure, sign-out, session expiry, service restart, and later sign-in from another device. They are retained until you explicitly delete that workspace. This is the standard workspace contract, not a session-only opt-in. The full notice is available at Source & Conversation Retention.
Authenticity validation is optional and runs only when you explicitly request it. While the workspace and retained original exist, KESTREL can authenticate or re-read the exact stored bytes without requiring a browser-held copy. Completed derived results and conversations can be restored after refresh.
Before private workspace deletion, KESTREL may create a separate learning candidate only when you previously enabled the separate learning-contribution opt-in for that workspace. It is retained only when a fail-closed gate reliably removes direct and indirect identifiers, embedded metadata, confidential content, and every link back to the account, workspace, upload, or source. Forensic findings and video derivatives are ineligible. Uncertain or ineligible candidates are rejected and destroyed. A retained candidate remains unverified until independent claim verification qualifies it for canonical memory.
Deleting a workspace removes its authoritative original, private representation, source binding, validation findings, and conversation, and returns a non-content receipt that reports whether source cleanup was verified and whether a separately de-identified candidate survived. A bounded, non-reconstructable private research memory may remain available only to the same account under its separate retention controls. Complete account deletion is not currently offered; workspace deletion and account-wide deletion must not be treated as the same operation.
Private workspace sources never become public verified memory or KML material merely because they were uploaded or analyzed. Account isolation prevents one customer from accessing or deleting another customer’s workspace or retained original.
Email verification is not currently configured. New accounts are labeled unverified and receive conservative trial access.