Skip to content
UnPack
ProductHow It WorksFor Legal TeamsPricingResources
Try UnPack Free
ProductHow It WorksFor Legal TeamsPricingResources

Company & Trust

About UnPackSecurityApp PrivacyWebsite PrivacyTermsLegal & CompanyContact
Company & Trust
About UnPackSecurityApp PrivacyWebsite PrivacyTermsLegal & CompanyContact

UnPack · Legal & trust

Security & data handling

Last updated: 7 September 2026

UnPack is a privacy-first evidence preparation tool operated by Unravel Consulting. The legal entity responsible for the Service is Antesto (Pty) Ltd, registration number 2014/042585/07.

This page explains the security and data-handling model of the UnPack application at https://app.unpack.legal. It is maintained on the public website at https://www.unpack.legal. See the separate Website Privacy Policy for this website and App Privacy Policy for the workspace.

1. The core principle

Your imported evidence is designed to stay in your browser.

UnPack is intended to let you work with WhatsApp evidence without uploading the evidence itself to UnPack.

The application is designed so that importing, parsing, rendering, searching, hashing and packaging evidence happens locally on your device.

2. What stays local

Depending on the source you import, local evidence may include:

  • WhatsApp TXT files;
  • WhatsApp ZIP exports;
  • messages;
  • participant labels and telephone numbers;
  • case and exhibit information you enter;
  • images, video, audio and other attachments;
  • local file hashes; and
  • previously exported UnPack evidence packages that you re-import.

This evidence is intended to remain inside the browser environment unless you choose to save, print, download, copy or share it.

3. Native TXT and ZIP imports

When you select a native WhatsApp TXT or ZIP export:

  1. your browser reads the selected local file;
  2. UnPack parses the conversation locally;
  3. where media is present in a ZIP, the application associates local media with message references where possible;
  4. the rendered conversation is produced locally; and
  5. the original source material is kept separate from the presentation where technically supported.

UnPack does not need to upload the evidence to a remote parser to perform this workflow.

4. Re-importable evidence packages

An UnPack evidence package may contain source material, media, checksums, a manifest and locally generated presentation files.

You can re-import a supported UnPack package to continue working with it.

Re-import is designed to occur locally:

  • the package is opened in the browser;
  • its manifest is read;
  • original TXT and media are restored where present;
  • saved presentation settings may be restored; and
  • checksums may be recalculated or checked.

Imported package content is treated as data, not as executable code. UnPack should not execute imported HTML or scripts from an evidence package.

5. Source preservation

UnPack distinguishes between source evidence and presentation.

The application should not silently rewrite the original TXT source merely to make the rendered conversation cleaner.

Examples of presentational changes may include:

  • displaying one participant’s messages on the right;
  • masking part of a telephone number;
  • applying a date-range filter to the rendered view;
  • displaying images within conversation bubbles;
  • adding message reference numbers; and
  • formatting content for A4 printing.

These choices do not change what the original imported source file contained.

You should retain your original export independently of UnPack.

6. Telephone-number masking

UnPack may partially mask telephone numbers in the rendered presentation.

This is a convenience for reducing unnecessary disclosure in presentation copies. It is not a complete anonymisation system.

The original TXT or media in an evidence package may still contain full numbers or other identifying information.

Always review an export before sending, filing or publishing it.

7. SHA-256 hashes

UnPack may calculate SHA-256 hashes locally using browser cryptographic functionality.

A hash can help identify whether the bytes of a file have changed.

A SHA-256 value does not by itself prove:

  • who created a file;
  • who sent a message;
  • who controlled a device or account;
  • that a message is true;
  • complete chain of custody;
  • forensic authenticity; or
  • legal admissibility.

Hashes are content identifiers, not legal certifications.

8. Printing and PDF

UnPack’s authoritative printable workflow may use the browser’s native Print / Save as PDF function.

This allows the browser to create a selectable, searchable PDF from the evidence presentation without sending the evidence to a remote PDF-generation service.

The resulting PDF is saved through your browser or operating system. UnPack does not receive the PDF merely because you print or save it locally.

9. Evidence-package downloads

Evidence packages are generated locally in the browser where supported.

A package may contain sensitive source material, including full original message text and media, even where the rendered document masks some information.

Once downloaded, the package is under your control.

For the current MVP, you should assume that a downloaded evidence package is not additionally password-encrypted by UnPack unless the interface expressly states otherwise.

Protect sensitive downloaded files using appropriate device, storage and sharing controls.

10. Media and metadata

Original media may contain metadata or information that is not obvious from the rendered preview.

Where UnPack preserves original media bytes, it may also preserve metadata contained in those files.

If you intend to disclose media outside your legal team or proceeding, consider whether additional review or redaction is appropriate.

11. What still travels over the internet

Your browser must connect to the internet to load the UnPack application from its hosting infrastructure.

That connection may expose ordinary technical information to hosting, networking or security providers, such as:

  • IP address;
  • browser/user-agent;
  • requested application assets;
  • timestamps; and
  • basic network/security information.

This is different from uploading your evidence.

The application is intended not to send imported message content, media, case metadata, participant names, source filenames or evidence hashes to UnPack as part of evidence processing.

Payment checkout and confirmation use a separate payment endpoint and Lemon Squeezy’s hosted test checkout. Only random payment references, signed payment tokens and payment status identifiers are used; evidence is not included. The endpoint temporarily stores a random reference and order ID for up to 24 hours. After a payment is verified, the app can save a signed payment receipt with a downloaded evidence package. Reopening the package sends only that receipt for order verification; no evidence hashes or source content are sent. The receipt is a transferable access credential, so it should be shared only with people intended to receive the package and its export access. Checkout runs in a separate tab, without adding third-party scripts to the evidence app.

12. No analytics in the evidence application

The current MVP is intended to operate without:

  • advertising trackers;
  • behavioural analytics;
  • session replay; or
  • remote evidence-content logging.

If that changes, the App Privacy Policy and this page must be updated to match the production implementation.

13. Your device is part of the security model

Because evidence processing happens locally, your own environment matters.

You should:

  • keep your operating system and browser updated;
  • use a trusted device;
  • use appropriate device login and disk-encryption controls where available;
  • avoid working with sensitive evidence on shared or public computers;
  • keep independent backups of original exports;
  • secure downloaded evidence packages and PDFs;
  • review files before sharing them; and
  • use an appropriate secure channel when sending sensitive material to another person.

14. UnPack is not a forensic certification service

UnPack helps organise and present digital material.

It does not perform a forensic extraction from a mobile device and does not certify:

  • chain of custody;
  • device ownership;
  • message authorship;
  • authenticity;
  • completeness of the original account history; or
  • admissibility.

Those questions may require source-device evidence, witnesses, forensic expertise, legal submissions or other evidence depending on the matter.

15. Security limitations

No browser, device or software system is perfectly secure.

Local processing materially reduces the need to transmit evidence to us, but it cannot protect against every risk, including:

  • malware on your device;
  • compromised browser extensions;
  • unauthorised local access;
  • insecure backups;
  • accidental sharing;
  • operating-system vulnerabilities; or
  • disclosure after you download or print files.

Use UnPack as part of an appropriate evidence-handling process rather than as the sole security control.

16. Reporting a security concern

If you believe you have identified a security issue relating to UnPack, contact:

[email protected]

Please do not include confidential client evidence in an initial security report unless it is genuinely necessary.

See Legal & company information for operator details and the public legal documents.

© 2026 UnPack · By Unravel Consulting
AboutLegalPrivacySecurityTermsContact

May we use Google Analytics to understand how this website is used? This is separate from the UnPack application. Website Privacy