Privacy Policy
Last updated: June 2026
Information We Collect
We collect the minimum necessary to provide the service:
- Account data: Email address and hashed password (for registered users).
- Payment data: Stripe session ID (for paid accounts). We do not store credit card numbers.
- Rate-limiting data: A hashed IP address used solely for rate limiting (retained up to 2 minutes).
What We Do NOT Collect
By design, we never have access to:
- Your encryption keys or secret keys
- Message plaintext or decrypted content
- File contents (only encrypted ciphertext is stored)
- Any personal information beyond what is listed above
How We Use Your Data
Account data is used only for authentication and dashboard access. Message metadata is displayed to you on your dashboard. Rate-limiting data is used to prevent abuse and is discarded after 2 minutes.
Data Retention
Encrypted messages are automatically deleted 7 days after creation. Messages with a max-views limit are deleted immediately after reaching that limit. Account data is retained until you request deletion or when you delete your account in both cases after 7 days all data related to your account is deleted.
Third-Party Services
We use Stripe for payment processing. Stripe receives your payment information subject to their privacy policy. We use ProtonMail SMTP for transactional emails (welcome emails, password resets).
Security
All encryption and decryption happens in your browser using WebAssembly and the Web Crypto API. The server stores only ciphertext that is computationally indistinguishable from random noise. No third-party scripts or CDNs.
Your Rights
You may request deletion of your account and associated data at any time by contacting us.
Contact
For privacy inquiries, open an issue on contact page.