Privacy Policy
Last updated: October 29, 2025
Secure Link is designed with privacy principles and zero-knowledge architecture. We cannot read your data even if we wanted to.
Data Collection
We collect minimal data necessary for service operation:
- Encrypted note content (without decryption keys)
- Metadata: creation time, TTL, view count
- IP addresses for rate limiting (not stored)
- Anonymous usage statistics (no personal data)
Data Processing
How we process your data:
- Encryption happens in your browser
- Decryption keys are never sent to server
- Notes are automatically deleted per settings
- We do not analyze or read note contents
Data Retention
Retention periods for different data types:
- Notes: until TTL expires or view limit reached
- Metadata: deleted with notes
- Access logs: 7 days for security
- Statistics: aggregated, no personal data
Third Parties
We do not share data with third parties, except:
- Cloudflare (CDN and DDoS protection)
- Upstash (managed Redis storage)
- Vercel (hosting platform)
Note: All listed services also have no access to decrypted data.
Your Rights
You have the following rights:
- Right to deletion: use "Close and burn" button
- Right to portability: export data from browser
- Right to information: contact us with questions
- Right to rectification: recreate note with correct data
Security
Security measures to protect your data:
- HTTPS encryption for all connections
- AES-GCM encryption with 256-bit keys
- Content Security Policy (CSP) headers
- Rate limiting to prevent attacks
- Regular security audits of code
Contact
For privacy questions, contact us:
We respond to requests within 72 hours.