GDPR & Privacy

Squeaker is designed for privacy-conscious teams. The widget does not load big-tech trackers; verification runs on squeaker.cc infrastructure you configure through the dashboard.

You are the controller for your form data. Squeaker processes verification metadata (hashed IP, timestamps, success/fail) to stop bots. Your organization's privacy policy should describe this processing.

What Squeaker stores

DataRetention
Dashboard email + password hashUntil account deleted
Site name, domains, settingsUntil site deleted
Verification logs (success/fail, hashed IP, timestamp)90 days default
Rate-limit counters, replay nonces, anomaly scoresMinutes (TTL)

What we do not store

Widget data collection

The widget communicates only with api.squeaker.cc. It does not load scripts from Google, Cloudflare Turnstile vendors, or other third-party CAPTCHA providers. No tracking cookies are set by the widget.

Behavior analysis privacy

When triggered (elevated anomaly score only), the widget sends aggregated movement metrics — not raw coordinates. This data is used solely for the current verification attempt and is not stored long-term.

Lawful basis (typical EU use)

Consult your legal team for your specific use case.

Data subject requests

Squeaker does not identify end users by name or account. GDPR access/erasure requests from website visitors typically do not apply to verification logs (hashed IP + timestamp only).

Privacy policy template (suggested wording)

Contact

For privacy questions about Squeaker, contact your account administrator or see squeaker.cc.