Validation data boundary

No app URL, account, credential, or payment detail is collected.

The public validation surface stores only bounded pseudonymous funnel events and the structured eligibility choices visible on the form.

What is stored

Event type, page path, acquisition class (organic search, referral, direct, or internal navigation), form choices, eligibility result, timestamps, and keyed one-way hashes derived from the server-observed network address and browser agent. Raw IP addresses and browser agents are not written to the FlowProof database.

Retention and deletion

Validation rows are removed after 30 days and hard row caps prevent unbounded storage. Clearing the browser cookie does not create another independent confirmation. To request early deletion or ask a privacy question, use the site operator contact page. Because no email or account identifier is collected here, include the approximate visit time and browser used; the operator may be unable to identify a row without retaining more personal data.

What is not happening

No customer browser run, login, crawl, real payment, automated outreach, cross-site profiling, or sale occurs in this validation stage.