Privacy Policy
01Who we are
Archivepanel is a product of Sverige Analytics AB, a company
registered in Sweden under company number 559538-4917 and based in Umeå,
Sweden (EU). Sverige Analytics AB ("Archivepanel", "we", "us") operates the web
preservation service at archivepanel.com and
dashboard.archivepanel.com. For anything in this policy, including
requests to exercise your rights, write to
support@archivepanel.com.
Sverige Analytics AB is the controller of the personal data described below. We are established in the EU, and the General Data Protection Regulation applies to this processing; this policy is written to meet it.
02What we store
| Data | Where it comes from | Notes |
|---|---|---|
| Email address | You, at registration | It is your account identifier — there are no usernames. Used to sign you in and to send operational notices. |
| Password | You, at registration | Stored only as an argon2id hash with a unique salt. The password itself is never written down and cannot be recovered from the hash. |
| Session tokens | Generated at sign-in | Only a SHA-256 digest of the token is stored, so a copy of our database yields no usable sessions. |
| Two-factor codes | Generated at sign-in | Only the code's digest is stored, bound to one challenge, valid briefly and for five attempts. |
| Archive metadata | Your captures | The address requested, the address after redirects, page title, capture time, stored size, status and origin (manual or scheduled). |
| Schedules | You | The address, kind, cadence and page limit of each recurring capture you configure. |
| Activity log | Your use of the service | Events such as sign-in, capture, schedule change and deletion, with a timestamp and the IP address the request came from. |
| Notifications | The capture worker | Short messages telling you a capture was stored, failed, or was stopped by a storage limit. |
| Server logs | Our web server | Request time, method, path, status, response size, user agent and IP address. |
We do not collect a name, a postal address, a phone number or payment details, because the service does not need them. There is no analytics script, no advertising pixel and no third-party tracker on either site.
03Pages you capture
An archive is a copy of a third-party web page that you asked us to save. We store it on your behalf, in a private bucket, under a key belonging to your account. We do not index it for search, mine it, train anything on it, or make it available to anyone else.
Stored files are readable only through the application. The bucket is private and we never hand out a URL that the storage provider will honour on its own: viewing, downloading and WARC export each stream the object from behind the sign-in gate. A link to one of your archives is worthless to a browser that is not signed in to your account.
If a page you capture happens to contain personal data about other people, you are the one deciding to collect it, and you are responsible for having a lawful reason to do so. See the acceptable-use section of our Terms.
04Why we hold it, and on what basis
- To provide the service — your account, your archives, your schedules. Lawful basis: performance of our contract with you.
- To secure the service — the activity log, server logs, rate limiting and the proof-of-work on sign-in exist to detect and stop abuse, credential stuffing and misuse of the capturer. Lawful basis: our legitimate interest in keeping the service and its users safe.
- To screen registrations — new addresses are checked against a mailbox verification provider to keep out non-existent and disposable addresses. Lawful basis: legitimate interest in preventing fraudulent and throwaway sign-ups.
- To tell you what happened — sign-in codes, capture results and failure notices. Lawful basis: performance of our contract with you.
- To meet legal obligations — where we are required to retain or disclose something. Lawful basis: legal obligation.
We send no marketing email, so there is nothing here you need to consent to or unsubscribe from.
06Processors we use
These are the only third parties that handle data on our behalf:
| Provider | Purpose | What it receives |
|---|---|---|
| Object storage | Storing your archives | The captured files themselves, under a private key scoped to your account. The bucket is hosted in the European Union. |
| Resend | Transactional email | Your email address and the message body — sign-in codes, capture failure notices. |
| Reoon | Registration screening | The email address being registered, once, at sign-up. |
| Cloudflare | TLS termination, caching, abuse mitigation at the edge | Request metadata, including your IP address, in the ordinary course of routing traffic. |
Each acts on our instructions under a data processing agreement. We do not sell personal data, and we do not share it for anyone else's advertising or analytics.
07How long we keep things
- Archives — until you delete them or close your account. They are immutable: we never rewrite one, and deleting is the only way one is lost.
- Account data — for as long as the account exists. You can empty the account of every archive, schedule and notification from Settings and keep the account, or close the account, which removes the account record and everything filed under it.
- Activity log — kept while the account exists, because its purpose is to let you and us reconstruct what happened to a record.
- Server access logs — rotated and discarded on a rolling basis, retained no longer than 30 days.
- Sessions and verification codes — sessions expire or end at sign-out; codes are consumed on use and expire shortly after issue.
08Who can see your data
Every archive query in the application is scoped to the owning account. There is no path by which one user reads another user's records.
One operator address can open a read-only console listing accounts on the deployment with their verification state, storage usage and recent activity, including archive metadata such as addresses and capture times. It exists to run the service — diagnosing a stuck capture, confirming a quota. It is read-only, it cannot change an account, and it does not open archive contents.
As with any hosted service, our operators necessarily hold the infrastructure credentials that the storage bucket sits behind. We do not use them to read customer archives, and we will not, other than where we are compelled by law or where it is strictly necessary to resolve a fault you have reported to us.
09How we protect it
- Passwords are hashed with argon2id (64 MB, unique salt per hash).
- Sign-in is two-step: password, then a six-digit code sent to your address.
- Session tokens and verification codes are stored only as digests.
- All traffic is served over TLS.
- State-changing requests carry a CSRF token; sign-in and registration are guarded by proof-of-work and rate limiting.
- The storage bucket is private, and archives are streamed through the application rather than linked directly.
- Deleting an archive requires re-entering your password.
- Unknown addresses still incur the password-verification delay, so response timing does not disclose which accounts exist.
No system is perfect. If you believe you have found a vulnerability, please tell us at support@archivepanel.com before disclosing it publicly, and we will work with you.
10Your rights
Where the GDPR or a comparable law applies to you, you have the right to:
- Access the personal data we hold about you.
- Correct anything inaccurate.
- Erase your data — you can delete archives one at a time, erase everything the account holds in a single action, or close the account entirely, all from Settings and all without asking us. Each takes your password.
- Port your data. This one is built in: every capture is downloadable as a self-contained HTML file, a text rendering and a standard WARC container, so leaving costs you nothing.
- Restrict or object to processing we carry out on the basis of legitimate interests.
- Complain to your data protection supervisory authority.
Write to support@archivepanel.com and we will respond within one month.
11International transfers
We are established in Sweden and your archives are stored in the European Union. Some of the processors listed above operate outside the European Economic Area. Where personal data is transferred, it is done under the European Commission's Standard Contractual Clauses or another lawful transfer mechanism.
12Children
Archivepanel is not directed at children and is not intended for anyone under 16. We do not knowingly create accounts for them. If you believe a child has registered, tell us and we will remove the account.
13Changes to this policy
If we change this policy we will update the date at the top of the page. Where a change materially affects how we handle your data, we will email account holders before it takes effect.
14Contact
Questions, requests and complaints: support@archivepanel.com.