Back to Home

Privacy Policy

Last updated: March 11, 2026

Overview

Epstein Search is a searchable archive of declassified documents from the U.S. Department of Justice. This privacy policy explains how we collect, use, and protect your information when you use this site.

Search Query Logging

When you search this site, we collect and store the following information:

  • Your search query: The exact text you entered
  • Hashed IP address: A cryptographic hash of your IP address (not the raw IP)
  • Timestamp: When the search was performed (UTC)
  • Results count: How many results were returned

Purpose: We use this data to:

  • Understand which documents and topics are most searched
  • Improve search quality and performance
  • Detect and prevent abuse (spam, DOS attacks)
  • Generate aggregate analytics (e.g., "top 100 searches")

How we protect it: Search logs are stored in Cloudflare D1 (encrypted at rest). We do not sell or share your search data with third parties.

IP Address Privacy

We hash your IP address using SHA-256 before storing it. This means:

  • We cannot recover your original IP address from our logs
  • The hash is consistent (same IP = same hash), allowing abuse detection
  • We do not log raw IP addresses that could identify you

Documents and PDFs

The documents on this site are sourced from public FOIA releases by the U.S. Department of Justice. They are stored on Cloudflare R2 (cloud object storage) and are publicly accessible.

We track aggregate view counts per document to surface popular documents. View counts are stored in Cloudflare KV and periodically synced to D1. No personally identifiable information is associated with view counts. PDF downloads go directly from Cloudflare R2 to your browser.

Rate Limiting

To prevent abuse, we limit API requests to 60 per minute per IP address. Rate limit counters are stored in Cloudflare KV using a hashed version of your IP address. These counters expire automatically and are not used for tracking.

Cookies

This site uses minimal cookies:

  • Bookmarks: If you save bookmarks, they're stored in your browser's local storage (not a cookie)
  • Auth tokens (Pro users only): JWT tokens stored in secure, httpOnly cookies
  • No tracking cookies: We do not use cookies for analytics or tracking

Web Analytics

This site uses Cloudflare Web Analytics, which is privacy-respecting:

  • No cookies are used
  • No personally identifiable information is collected
  • IP addresses are not logged
  • We only see aggregate traffic metrics (page views, referrers, device types)

Learn more about Cloudflare Web Analytics →

Third-Party Services

This site is hosted on:

  • Cloudflare Pages: Frontend (with Cloudflare Web Analytics)
  • Cloudflare Workers: Search API
  • Cloudflare D1: Search index and metadata database
  • Cloudflare R2: PDF storage

Cloudflare's Privacy Policy →

GDPR & Data Rights

If you are in the EU, you have the right to:

  • Access: Request a copy of your hashed IP data from search logs
  • Deletion: Request deletion of your search history (limited by IP hash uniqueness)
  • Portability: Request your data in a portable format
  • Opt-out: Disable search query logging by using a VPN or proxy

To exercise these rights, email contact@epsteinsearch.info.

Data Retention

Search logs are retained for 90 days. After 90 days, they are permanently deleted.

Security

All communication with this site is encrypted (HTTPS/TLS). The database is encrypted at rest. We do not store or transmit sensitive information (credit card numbers, passwords, etc.).

Policy Changes

We may update this privacy policy as our services evolve. We will notify users of any material changes by posting the updated policy here with a new "last updated" date.

Contact

Questions about this privacy policy? Contact us at:

contact@epsteinsearch.info