Archangel AgencyRequests

How requests are handled

What happens to a request, who can read it, and what we keep.

In short

  • Your request is encrypted before it is stored, and only Archangel Agency holds the keys that open it.
  • We don’t keep your IP address. This site sets no cookies and does no tracking.
  • A person reads every request, and makes every decision about it.
  • Closed requests are deleted 90 days after they close.

Who reads your request

A person at Archangel Agency reads every request that is sent. Nothing you send is decided automatically, and this site does not send requests to AI services.

The form stops some requests based on your own answers, and tells you why. A stopped request is not stored.

Encryption

With JavaScript on, your answers are encrypted in your browser before they leave it. Without JavaScript, they are encrypted on our server as soon as they arrive, and are never stored unencrypted.

We use age, an open file-encryption format. The keys are hybrid post-quantum keys: X25519 combined with ML-KEM-768. The private keys that open requests are held by Archangel Agency staff. They are not stored on our servers.

What we keep

We do not keep your IP address. To limit abuse, we count the requests from each network under a keyed hash that changes every day, and delete the counts the next day. The hash cannot be linked back to an address without a secret key we hold.

What our providers see

This site runs on Vercel. Vercel keeps request logs, including IP addresses. The logs available to us are deleted after a day at most. Requests are stored in a Neon Postgres database.

Neither provider can read a request that was encrypted in your browser. Without JavaScript, your answers pass through our code on Vercel’s servers unencrypted for a moment while they are encrypted, and are never written anywhere unencrypted.

What this site does not do

How long we keep requests

We close every request within 180 days of receiving it, unless it becomes an engagement.

Closed requests are deleted 90 days after they close. After that, encrypted copies can remain in our database provider's backups for up to 30 days.

We keep a request longer only when the law requires it, for example because of a legal claim.

If a request becomes an engagement, its records are kept for as long as the engagement and legal record-keeping require.

If a court, government agency or law enforcement demands information about a request, we check that the demand is legally valid and give only what it requires. Unless the law forbids it, we tell the person who sent the request.

Encryption keeps requests from our providers and from anyone who breaks into our systems. It does not put a request beyond a legal demand: our staff hold the keys, and the law can require us to use them.

What not to send

Do not send classified information, controlled unclassified information (CUI), other government information that is not public, or export-controlled technical data. This includes leaked or published copies. If your request involves material like this, describe the kind of material, not its content.

If you send any by mistake, tell us right away at contact@archangel.agency. Do not repeat the material in the email.

Contact

Email contact@archangel.agency. Email is not encrypted, so do not send request details by email. If you cannot use the request form, see Accessibility.