Secure Link

Privacy Policy

Last updated: October 29, 2025

Secure Link is designed with privacy principles and zero-knowledge architecture. We cannot read your data even if we wanted to.

Data Collection

We collect minimal data necessary for service operation:

  • Encrypted note content (without decryption keys)
  • Metadata: creation time, TTL, view count
  • IP addresses for rate limiting (not stored)
  • Anonymous usage statistics (no personal data)

Data Processing

How we process your data:

  • Encryption happens in your browser
  • Decryption keys are never sent to server
  • Notes are automatically deleted per settings
  • We do not analyze or read note contents

Data Retention

Retention periods for different data types:

  • Notes: until TTL expires or view limit reached
  • Metadata: deleted with notes
  • Access logs: 7 days for security
  • Statistics: aggregated, no personal data

Third Parties

We do not share data with third parties, except:

  • Cloudflare (CDN and DDoS protection)
  • Upstash (managed Redis storage)
  • Vercel (hosting platform)

Note: All listed services also have no access to decrypted data.

Your Rights

You have the following rights:

  • Right to deletion: use "Close and burn" button
  • Right to portability: export data from browser
  • Right to information: contact us with questions
  • Right to rectification: recreate note with correct data

Security

Security measures to protect your data:

  • HTTPS encryption for all connections
  • AES-GCM encryption with 256-bit keys
  • Content Security Policy (CSP) headers
  • Rate limiting to prevent attacks
  • Regular security audits of code

Contact

For privacy questions, contact us:

We respond to requests within 72 hours.