Project Gates of Valhalla
Sign in Sign up

Privacy

What We Keep


A research tool that maps personal data has no business being vague about its own. This is the whole of it.

No tracking, and an account is optional

There is no advertising, no analytics, and no third-party scripts — the content security policy on this site forbids them outright. Fonts, styles, scripts and images are all served from this domain. Your theme preference is stored in your browser's local storage and never leaves it.

You do not need an account to research. An account exists so your work can be kept, shared with an organisation, and run against your own API keys — nothing more.

If you create an account

  • Your email address and display name. The address is the identity a sign-in provider matches on; it is not used to contact you, and there is no mailing list.
  • Your password, as an argon2id hash. The plaintext is never stored and cannot be recovered from what is. An account created through GitHub, Google, Apple or Facebook has no password at all.
  • Sessions. A session cookie holds 32 random bytes; the database stores only their SHA-256, so a dump of that table does not hand anybody a live login. You can list and revoke your own sessions on your account page.
  • Your API keys, encrypted (libsodium secretbox, with a key derived per purpose). They are never sent back to your browser after you save them — the account page shows a mask.
  • Which provider you signed in with, and the identifier it gave us. We ask providers for your email address and name, and nothing else.

What is stored when you run an investigation

  • The search term and the resulting graph. Entities, relationships, findings and the raw responses sources returned, so a report can cite its evidence.
  • Your IP address, in the audit log alongside the action taken, the account acting (if any) and the timestamp. This is what makes abuse traceable.
  • Cached source responses and cached source conclusions, so two people researching the same domain on the same day cost the sources one lookup rather than two. Both expire on their own, and a cached answer from a source that needs a key is only ever served to somebody who holds that key.

Investigations with no owner — anything run without an account — are deleted automatically after 30 days, along with anonymous timelines. Work saved to an account stays until you delete it. The audit log is kept longer than the research it describes, because the record of who looked outlives what they found.

Who can see an investigation

Every investigation and every timeline is one of three things, and you choose which:

  • Private — you, and platform administrators. Nobody else, link or no link.
  • Shared with your organisation — every member of it.
  • Anyone with the link — unlisted, but public to whoever holds the URL.

An unlisted link is not a private one. Anyone holding the URL of a public investigation can read it, and its link preview shows the search term and the result counts. Pages carry noindex and are excluded in robots.txt so search engines stay out, and a preview card is only ever drawn for an investigation you have marked public — but treat a shared link the way you would treat the report itself.

Personal data found during research

This platform collects information that is already published: registry contacts, published email addresses, public profiles, company filings. It is processed for the purpose of information security research, which is a legitimate interest under GDPR Article 6(1)(f) — and that interest does not extend to anything you like. If you run an investigation here, you are the one deciding it is proportionate. Keep it so, and keep distribution of the output proportionate too.

Where a source marks something as sensitive — a breach that is damaging by membership alone, an address under Danish adressebeskyttelse — the platform says so on the finding rather than presenting it as ordinary data.

Deleting your account

Ask an administrator and the account goes. Investigations do not go with it: they are evidence, other people may be relying on them, and they are detached from the deleted account rather than destroyed. Anything that was private stays unreachable. Say so explicitly if you want the research removed too.

Requests about your data

If information about you appears here and you want it removed, or you want to know what is held, write to THUGS(red). Include the investigation link if you have one; it makes the request much faster to action. Note that we hold copies of public records, not the records themselves — getting something removed here does not remove it from the registry, log or archive it came from, and we will tell you where it came from so you can go to the source.

Security

Traffic is HTTPS-only and HSTS is enforced. The site sends a strict content security policy, denies framing, and limits itself to GET, HEAD and POST. Every database query is parameterised, every outbound lookup is checked so user input cannot turn this server into a proxy for reaching internal systems, and any credential that ends up in the database is encrypted with libsodium rather than stored in the clear.

Found a hole? Tell us before you tell anyone else, and you will get credit for it.

This page describes the software as deployed at valhalla.thugs.red. Last reviewed October 2026.