Privacy Policy

Last updated: April 25, 2026

1. What We Collect

We collect the minimum data necessary to provide the service:

  • Account data — your name and email address when you sign up.
  • Secrets data — the environment variables and credentials you store, encrypted at rest.
  • Usage data — basic logs such as authentication events and API calls, used for security and debugging.

2. How We Use Your Data

  • To authenticate you and provide access to your secrets.
  • To send transactional emails (password resets, security alerts).
  • To detect and prevent fraud or abuse.
  • To improve the service based on aggregate, anonymized usage patterns.

We do not sell your data. We do not use your secrets for any purpose other than serving them back to you.

3. Data Storage and Encryption

All secrets are encrypted at rest. Access requires valid authentication and, where enabled, two-factor verification. We use industry-standard practices for key management and data storage.

4. Third-Party Services

We use a limited set of third-party providers to operate the service:

  • Database hosting — to store encrypted account and secrets data.
  • Email delivery — to send transactional emails (e.g., password resets).
  • Authentication (Google OAuth) — if you choose to sign in with Google, your basic profile info is shared per Google's OAuth flow.

We do not share your data with advertisers or analytics providers.

5. Data Retention

Your data is retained as long as your account is active. When you delete your account, all associated data — including stored secrets — is permanently deleted within 30 days.

6. Your Rights

You have the right to:

  • Access the data we hold about you.
  • Request correction or deletion of your data.
  • Export your secrets at any time from the dashboard.

7. Cookies

We use session cookies strictly to maintain your authenticated session. We do not use tracking cookies or third-party advertising cookies.

8. Changes to This Policy

We may update this policy periodically. We will notify you of material changes via email or a notice within the app. Continued use after changes constitutes acceptance.

Also see our Terms of Service.