← BlackMold

BlackMold web beta privacy notice

Last updated 25 August 2026

Closed-beta draft: this notice is for a small invitation-only test. Formal controller and public contact details will be completed before any wider release.

Who this notice covers

Controller: BlackMold, established in the European Union (temporary closed-beta description). Closed-beta contact: use the same private channel through which you received your invitation.

This notice covers the controller's operation of the BlackMold web beta, which is available by invitation only. If an employer or another organization asks you to use BlackMold for its work, that organization may separately be the controller for the case information you enter. Ask that organization about its privacy rules. Do not place personal or sensitive information in a shared case label.

What is processed and why

Requested domain checks

Clicking Analyze Domain authorizes one public domain lookup without changing your automatic-networking preferences. BlackMold receives only the submitted domain and sends it to Google Public DNS and the authoritative registration service identified through IANA. No case notes or unrelated graph data are sent. The service does not persist analysis targets, returned source, or reports. To prevent abuse, D1 temporarily stores a hashed account identifier, time bucket, count, and expiry (up to two days). The account identifier is pseudonymous, not anonymous. Infrastructure providers may independently process normal network or security logs under their own policies. Website collection currently remains disabled pending outbound-request safety verification. Results enter the case only when you choose to save them.

Public pages and secure access

Cloudflare serves the website and processes normal network and security data such as IP address, browser and device information, requested URL, timestamps, cookies or session identifiers, and request IDs. For the private workspace, Cloudflare Access also processes your email address, authentication method, country inferred from IP address, and the allow or deny result. This is used to deliver the site, restrict the beta to approved testers, maintain sessions, prevent abuse, and investigate security or availability problems.

Local browser library

Case names and case content in the local recovery library are encrypted in your browser with an AES GCM device key that cannot be extracted and are stored in IndexedDB. Only opaque IDs, timestamps, record version, source, and byte count remain outside that ciphertext. The account recovery secret, when remembered, is also encrypted with the device key before IndexedDB stores it. Privacy choices and a local record of requests to external features are stored in localStorage. These local records can include the provider, purpose, destination service path, time, and whether the request was allowed; they are not sent to the beta server merely because they exist.

Personal account cases

A personal case is available only to the Cloudflare Access email account that created it. D1 stores a generic label, case type, owner email address, opaque case and object identifiers, hashes, encrypted sizes, revision numbers, timestamps, and audit events. It does not store the personal case name. R2 stores immutable encrypted revisions. The browser encrypts and decrypts the case and never uploads the account recovery secret or case key. On a new browser, the user must enter the same account recovery secret once before personal cases can be decrypted there.

Shared cases

For collaboration, D1 stores a deliberately nonsensitive case label in plaintext together with case IDs, owner and member email addresses, nicknames and roles for each case, encrypted object pointers, hashes, sizes, revision numbers, timestamps, and audit events. R2 stores immutable encrypted case revisions. Encryption and decryption happen in the browser. The beta server is not designed to receive decrypted case content, recovery secrets, or case keys.

When a shared case is open, BlackMold temporarily processes the case ID, identity of the signed in member, nickname, opaque tab session ID, working or away state, and time when the member was last seen to show live collaboration presence. Other case members receive the nickname, role, state, and whether an entry represents themselves; they do not receive another member's email through the presence API. Presence is not written to audit history or included in support diagnostics.

Optional network features and support

External lookups, cloud AI, and network map tiles are off by default for new web users. If you enable and use one, the disclosure shown in the workspace identifies the provider and the categories that may be sent, which can include a search term, identifier, location, domain, URL, email address, IP address, map viewport, or content derived from the case that is needed for that request. The provider processes the request under its own privacy terms. Do not include case data in feedback or privacy messages. Server release diagnostics expose aggregate storage and record counts only.

Legal bases

The controller processes invitation, authentication, collaboration, and service data because it is necessary to provide the beta you ask to use and administer the beta terms (GDPR Article 6(1)(b)). Security, abuse prevention, reliability, redacted diagnostics, and limited audit records are processed for the controller's legitimate interests in operating a secure and dependable private beta (Article 6(1)(f)). Information may also be processed where necessary to comply with law or establish, exercise, or defend legal claims (Articles 6(1)(c) and 6(1)(f)). Optional network features run only after your deliberate choice; turn them off at any time. An external provider identifies its own legal basis in its privacy notice.

Who receives the data and international transfers

Cloudflare provides Pages, Access, Workers, D1, R2, network security, and email codes that can be used once for this beta. Cloudflare acts as a processor for customer data where applicable and may use approved subprocessors. Cloudflare operates globally, including in the United States and the EEA, and describes safeguards including the EU Standard Contractual Clauses and, where applicable, the EU and US Data Privacy Framework in its Data Processing Addendum and Privacy Policy. If you choose an optional external provider, data is sent to that provider and its stated transfer safeguards apply. Shared case members receive the plaintext collaboration label, membership information, and encrypted revisions allowed by their role.

Retention and deletion

Your local browser library remains until you delete cases, choose “Forget this device,” clear browser data, lose the browser profile, or the browser evicts storage. Any of those events can permanently destroy the device key and local library. Export an encrypted .blackmold case for portable recovery.

Active personal and shared account cases keep the latest 24 revisions. Their access metadata and audit events remain while the case is active. Archiving blocks access immediately; the owner can restore the case for 30 days, after which its D1 metadata and R2 objects are removed by scheduled or opportunistic cleanup. Removing a shared case member blocks future access and removes current membership, but the security audit event remains until the case is purged and the removed person may retain material downloaded earlier.

A visible shared case tab refreshes “working now” presence. An active entry becomes offline after about 60 seconds without a heartbeat. An away entry is kept for no more than about five minutes. Closing the case, removing a member, or archiving the case attempts to remove presence immediately; expiry is the fallback.

Approved tester emails remain in the invitation configuration while access is required. On Cloudflare's Free plan, Access authentication logs are retained for 24 hours. Privacy or support correspondence is kept only as long as reasonably needed to answer the request, handle a security issue, meet a legal obligation, or resolve a dispute.

Cookies, browser storage, and required information

BlackMold does not use cookies for advertising or behavioural analytics. Cloudflare Access uses strictly necessary cookies or similar session storage to authenticate the private workspace and protect it from abuse. IndexedDB and localStorage provide the encrypted local library, preferences, disclosure acknowledgement, and local privacy audit described above.

An approved email address is required to enter the private workspace and is used to scope personal account cases. A collaboration label that does not contain sensitive information and member details are required only when you use shared cases. Without the required access information, the controller cannot provide the private beta, personal account sync, or collaboration feature. Optional external features are not required.

Your GDPR rights

Depending on the circumstances, you may ask the controller to access, correct, erase, restrict, or provide a portable copy of your personal data, and you may object to processing based on legitimate interests. Where consent is used, you may withdraw it without affecting earlier lawful processing. These rights can have legal limits, including where records are needed for security or legal claims. Local encrypted case content may be accessible only to you because the controller does not hold the device key or recovery secret.

Use the controller contact above to exercise a right. You may also complain to the data protection authority in the EU or EEA country where you live or work, or where you believe an infringement occurred. The European Commission maintains information about EU data protection.

Automated decisions and children

BlackMold does not make solely automated decisions that produce legal or similarly significant effects. Cloudflare Access automatically enforces an invitation list maintained by a person. This workplace beta is not directed to children.

Security and recovery limits

Encryption reduces exposure but does not remove every risk. Control of an approved email mailbox can permit authentication, while the separate recovery secret is still required to decrypt a personal case on a new browser. Anyone with a recovery secret or a copy that was downloaded earlier may be able to read that copy. BlackMold cannot recover a lost recovery secret, decrypt server revisions for you, or remotely erase files another member already downloaded.