Privacy Policy
Last updated: September 2026
1. Encryption and key custody
File encryption happens in your browser using AES-256-GCM. In Simple mode, ZeroLatch stores a wrapped managed key so an intended recipient with a valid release link can unlock files after release. In Private mode, the private password or generated recovery phrase stays with the user and ZeroLatch cannot recover it.
2. Data We Collect
We collect the minimum data necessary to operate the service:
- Accounts: Your email address for login, reminders, and password recovery.
- Delivery metadata: Delivery names, check-in intervals, safety periods, and status. Recipient emails and messages are encrypted at rest.
- File metadata: Private filenames and MIME types are encrypted before upload; file size remains observable. Simple mode permits authorized recovery; Private mode cannot be opened without the user-held secret.
- Private metadata limits: Ciphertext size, recipient address, schedule, billing and operational status remain visible to the service even when payload content is Private.
- Activity logs: Security audit trail of actions performed on your account.
- Payment information: Processed by Stripe. We store customer, subscription, price and webhook identifiers and billing status, but never card numbers.
3. How We Use Your Data
- Authenticate you and manage your session
- Operate check-in reminders, safety periods, and eligible delivery release
- Send account, optional recipient-confirmation, reminder, and release emails
- Process payments via Stripe
- Maintain security audit logs
4. Data Sharing
We do not sell, rent, or share your personal data with third parties for marketing purposes. We share data only with:
- Supabase: Database and authentication infrastructure (hosted in your selected region).
- Vercel: Application hosting, request handling, and operational logs.
- Stripe: Payment processing only.
- Resend: Transactional email delivery only.
- PostHog: Limited analytics on allowlisted public pages, coarse content-free service milestones, and session replay on read-only marketing, legal, and blog pages. Public tools and all account, authentication, delivery, recipient, and download routes are excluded. Replay masks form inputs and does not collect console logs, canvas content, or network headers and bodies. The ZeroLatch project uses US Cloud, discards client IP data, and retains replay data for up to 30 days.
- Your designated recipients: When a delivery is released, recipients receive time-limited access to the encrypted files and sender information configured for that delivery.
5. Data Retention & Deletion
You can delete your account from Account settings. The resumable deletion process stops an active subscription, revokes recipient access, removes stored files and application data, and removes authentication. A minimal deletion-completion or provider record may remain where needed for security, billing, dispute, or legal obligations. You can export available account and delivery metadata before deletion.
6. Security Measures
- Client-side AES-256-GCM encryption. Private passwords use Argon2id key derivation; generated Private recovery phrases use versioned HKDF-SHA-512 key derivation.
- Row Level Security (RLS) on all database tables
- CSRF protection, rate limiting, and input validation
- Strict Content Security Policy headers
- HTTPS and strict transport-security headers
7. Cookies
The fictional demo and checklist use content-free engagement events. Known campaign source, medium and campaign labels may be stored in a first-party cookie for up to 30 days; arbitrary campaign values are discarded. Coarse billing events distinguish trials, positive paid invoices, payment failures and cancellations, without card details. Protected pages remain excluded from page capture and replay.
We use secure browser storage and cookies for authentication and basic service operation. On non-sensitive public pages, limited product analytics may record page visits and coarse usage information. On read-only marketing, legal, and blog pages, privacy-limited session replay may also record navigation, clicks, scrolling, and the public page content displayed in the browser. Form inputs are masked. Public tools and all delivery, recipient, download, authentication, account, and dashboard routes are excluded from replay. A random, first-party acquisition identifier may remain for up to 30 days so we can understand whether a public visit reaches account, subscription, delivery-creation, activation, or check-in milestones. Trusted server events contain no email address, file name, delivery content, recipient details, capability tokens, or Private secrets.
8. International processing
Our infrastructure providers may process account, payment, email, analytics, and operational data outside Australia, including in the United States. Provider locations and subprocessors can change. We limit each provider to the data needed for its service and apply the product controls described above.
9. Contact
For privacy concerns or data requests, contact us at privacy@zerolatch.com.