Privacy Policy

Last updated: July 2026

1. Encryption and key custody

File encryption happens in your browser using AES-256-GCM. In Simple mode, ZeroLatch stores a wrapped managed key so an intended recipient with a valid release link can unlock files after release. In Private mode, the recovery code stays with the user and ZeroLatch cannot recover it.

2. Data We Collect

We collect the minimum data necessary to operate the service:

  • Accounts: Your email address for login, reminders, and password recovery.
  • Delivery metadata: Delivery names, check-in intervals, safety periods, and status. Recipient emails and messages are encrypted at rest.
  • File metadata: File names, sizes, and MIME types. The file contents are encrypted and unreadable to us.
  • Activity logs: Security audit trail of actions performed on your account.
  • Payment information: Processed by Stripe. We store only your Stripe customer ID — never card numbers.

3. How We Use Your Data

  • Authenticate you and manage your session
  • Operate check-in reminders, safety periods, and eligible delivery release
  • Send account, optional recipient-confirmation, reminder, and release emails
  • Process payments via Stripe
  • Maintain security audit logs

4. Data Sharing

We do not sell, rent, or share your personal data with third parties for marketing purposes. We share data only with:

  • Supabase: Database and authentication infrastructure (hosted in your selected region).
  • Stripe: Payment processing only.
  • Resend: Transactional email delivery only.
  • Your designated recipients: When a delivery is released, recipients receive time-limited access to the encrypted files and sender information configured for that delivery.

5. Data Retention & Deletion

You can delete your account from Account settings. This permanently removes deliveries, encrypted files, and activity logs and cannot be undone. You can export the available account and delivery metadata before deletion.

6. Security Measures

  • Client-side AES-256-GCM encryption with PBKDF2 key derivation (100,000 iterations)
  • Row Level Security (RLS) on all database tables
  • CSRF protection, rate limiting, and input validation
  • Strict Content Security Policy headers
  • HTTPS and strict transport-security headers

7. Cookies

We use secure browser storage and cookies for authentication and basic service operation. On non-sensitive public pages, limited product analytics may record page visits and coarse usage information. We exclude delivery, recipient, download, and authentication routes and do not send file names, content, recipient details, or recovery codes to analytics.

8. Contact

For privacy concerns or data requests, contact us at privacy@zerolatch.com.