Beta privacy
Last updated 21 August 2026
Local browser library
Case names and case content are encrypted with a non-extractable device key and stored in IndexedDB. Opaque IDs, timestamps, record version, source, and byte count remain outside the ciphertext. Clearing browser data, forgetting this device, losing the browser profile, or storage eviction can permanently destroy this library. A device-bound case is available only after Cloudflare Access sign-in in the same browser profile. Export an encrypted .blackmold case for portable recovery.
Access and collaboration
Cloudflare Access processes the account email used to enter the private workspace. A shared case stores its deliberately non-sensitive label in plaintext. D1 stores case and membership metadata, encrypted object pointers, hashes, sizes, revision numbers, timestamps, and sanitized audit events. Immutable encrypted revisions are held in R2. BlackMold does not store decrypted case content, recovery secrets, or case keys on the server.
Retention and deletion
Active shared cases retain the latest 24 revisions. Archiving blocks member access immediately. Owners may restore for 30 days; after that, metadata and encrypted revision objects are removed by scheduled or opportunistic cleanup. Removed members cannot access future revisions but may retain material they downloaded earlier.
External services and diagnostics
External lookups and network map tiles are off by default for new web users. Enabling them can send search terms, identifiers, locations, domains, URLs, or IP addresses to the named provider. Support diagnostics contain build ID, browser details, counts, timings, sanitized errors, and request IDs only—not case names, node labels, URLs, emails, identifiers, or case content.