HomeGuide Privacy & trust
Privacy & trustEveryone

Your case stays between the parties

The case room — files, chat and timeline — is reachable only by its parties. We tell you plainly what we do: party-only access is enforced at the database level, files are encrypted, stamped with a SHA-256 hash, and access is logged. No marketing spin about “zero-knowledge”.

Party-only access

Who sees what in a case room

A room's contents are visible only to its parties — the client and the chosen specialist. Other users of the platform see nothing: no files, no messages, not even that the room exists.

Membership

Two parties inside, everyone else out

A room has exactly two parties. Every access to files, chat or the timeline goes through a server action that first checks whether you are a party to this room. If you are not, you get no data.

  • The client and the specialist have full access to their case.
  • Other signed-in users and guests are blocked.
  • Access always runs through a membership-checked server action.
Enforced in the database, not just in the UIThe “parties only” rule does not rely on hiding a button. The room tables use Row-Level Security (RLS) with force RLS and direct access revoked for the anon and authenticated roles — even bypassing our code, another user cannot read someone else's case.
Files & storage

Documents in a private, encrypted store

Attachments do not sit at a public address. They go into a private store, are encrypted at rest and transferred over TLS, and can be fetched only through a short-lived, signed URL.

Private bucket

Encrypted at rest, fetched via signed links

Every file lands in a private bucket encrypted with AES-256. When a party wants to open it, the server — after checking membership — generates a signed URL valid for only a few minutes. After that the link expires and stops working.

  • Private bucket — no public addresses to your files.
  • Encrypted at rest (AES-256) and over TLS in transit.
  • Downloads only through a short-lived, signed URL.
Integrity proof

A SHA-256 hash on every file

The moment it is uploaded, each file gets a SHA-256 hash stored with a date. It is a seal: it lets you prove the document is exactly the same as on the day it entered the room.

Tamper-evidence

Prove a document hasn't changed

A SHA-256 hash is a file's digital fingerprint — change even a single byte and the hash is completely different. By comparing the hash recorded at upload with the file's hash today, any party can show the content has stayed intact since the recorded date.

  • The hash is computed and stored at upload, with a date.
  • Any change to the file = a different hash = instantly visible.
  • An evidentiary argument: unchanged since a given day.
Our commitment

Privacy matters most to us

We want to be honest with you about the limits too. Below is what we genuinely guarantee technically — and what, honestly, we do not promise.

Minimal platform access — stated plainlyPrawnet is not an end-to-end or “zero-knowledge” service. We do not review your documents or messages beyond what is necessary to run the service or required by law. Access to users' files is logged, and chat notifications never copy the message body — they only tell you that something arrived.

RLS with force

Room data filtered in the database (force RLS), with direct access revoked for the anon and authenticated roles.

AES-256 at rest

Files in a private bucket, encrypted at rest and transferred over TLS.

SHA-256 per file

Hash computed at upload — tamper-evidence and proof of integrity.

Signed, short URLs

Files fetched only via links valid for a few minutes, issued after a membership check.

Logged access

Access to users' files is recorded; notifications never contain the message body.

6 years, then deletion

A case room is kept 6 years as potential evidence, after which the data is deleted.

Retention & deletion

How long we keep data, and why

A case room is kept for 6 years as potential evidence — in case claims need to be established, pursued or defended. This aligns with GDPR (Art. 17(3)(e)). After that period the data is deleted, and you can download your files at any time in the meantime.

  1. During and after the case — full access

    As long as the room exists, both parties can access files, chat and the timeline, and can download their documents at any time.

  2. 6 years of evidence retention

    A closed room is kept for 6 years as potential evidence — to establish, pursue or defend legal claims (GDPR Art. 17(3)(e)).

  3. Automatic deletion

    Once the retention period ends, the contents of the room are deleted. Before then, download copies of anything you want to keep.

Trust

Verification you can rely on

Privacy protects your case; verification tells you whom you entrust it to. Two badges carry concrete, checkable meaning — they can't be bought or faked.

Badges

Verified profile and verified payment

The green badge next to a name means we checked the specialist's credentials. The “Verified payment” chip appears when a real, paid engagement stands behind the collaboration — proof that a review comes from an actual client.

  • Verified profile = checked professional credentials.
  • Verified payment = a real, paid engagement.
  • Reviews after paid cases are resistant to faking.
See verified specialists
Parties only
room access
AES-256
file encryption
SHA-256
integrity proof
6 years
evidence retention
arrow_backPreviousPublic profile & reviews