Skip to content

Legal

Privacy policy

Plain language, because this is about trust. Here's what we collect, why, and the control you have over it.

1. Who we are

Sealkept is operated by Sealkept Ltd, based in Dublin, Ireland ("we", "us"). We are the data controller for personal data processed through sealkept.com and our apps.

If you have any questions about this policy or your data, contact us at [email protected].

2. The short version

  • We collect only what we need to run the service: your account details, your check-in settings, your recipients and the messages you write.
  • Message content is encrypted at rest (AES-256-GCM) and stored on servers we run with Oracle Cloud in Mumbai, India.
  • We don't sell your data, we don't show ads, and we don't use your messages to train AI models.
  • We use only essential cookies. There is no advertising or cross-site tracking.
  • You can export or delete your data at any time.

3. The data we collect

We collect the following categories of personal data:

  • Account data: your name, email address, a hashed password, language and time zone preferences.
  • Switch settings: your check-in interval, check-in methods, reminder count, verifier settings, grace period, and the history of your check-ins.
  • Check-in extras, only if you use them: your confirmed mobile number for reminder texts and calls, a hashed copy of your check-in PIN (never the PIN itself), and, for face or fingerprint check-ins, a passkey's public key. Nothing biometric reaches us; your device only proves it's you.
  • Recipient data: names, relationships, email addresses, optional phone numbers and birthdays of the people you choose to receive messages or act as verifiers.
  • Message content: the letters, voice notes, videos and documents you create, and the delivery rules you set for each.
  • Billing data: if you buy a plan, our payment provider takes your card, UPI or bank details; we never see them. We keep the plan, amount, currency, status and the provider's payment and customer references.
  • Technical data: IP address, browser type and security logs, used to keep your account secure and the service reliable.
  • Correspondence: messages you send to our support team.

We don't knowingly collect data from children under 16 as account holders. Children may be named as recipients by a parent or guardian.

4. Data about your recipients and verifiers

When you add a recipient or verifier, you give us their contact details. Please make sure you're comfortable sharing them and, where appropriate, let them know. We use their details only to contact them under the rules you set: a verifier request, a soft alert, or delivery of a message.

We don't contact recipients for marketing. A recipient who receives a message from us can ask us to stop contacting them, and can exercise their own data protection rights by writing to [email protected].

5. Why we use your data, and our legal bases

Under the GDPR we must have a legal basis for each use of personal data:

  • To provide the service (your account, check-ins, reminders, verifier requests, alerts and delivery): performance of our contract with you.
  • To contact your recipients and verifiers as you've instructed: our legitimate interest in providing the service you asked for, and theirs in receiving messages intended for them.
  • To take payments and keep financial records: performance of contract and our legal obligations.
  • To secure the service, prevent abuse and fix problems: our legitimate interest in keeping accounts and messages safe.
  • To send you service emails, such as check-in reminders and security notices: performance of contract. These can't be switched off while your switch is active, because they are how it works.
  • To send occasional product news, only if you opt in: your consent, which you can withdraw at any time.

Message content may include special category data, such as information about your health. We process it only to store and deliver it as you instruct, based on your explicit consent, which you give when you create the message.

6. How we protect your data

Message bodies are encrypted at rest using AES-256-GCM, and all traffic is encrypted in transit with TLS. Encryption keys are stored separately from the database.

By default our encryption is not end-to-end: the service must be able to decrypt messages to deliver them when your rules say so. If you turn on the optional private seal for a letter, it is encrypted in your browser before it reaches us, with a key that is never sent to us; we store only a server half that is released on delivery, and we cannot decrypt the letter. The letter's title, recipient and dates are not covered by the private seal. Access to production systems is restricted to a small number of authorised staff, is logged, and is used only to operate and support the service. Staff do not read message content as part of normal operations.

7. How long we keep data

  • Account, settings and messages: for as long as your account is open. When you delete your account, we delete this data within 30 days, except where we must keep it by law.
  • Delivered messages: kept available to recipients for 12 months after delivery, so they have time to open and save them, then deleted.
  • Billing records: kept for the period required by tax law (currently up to 7 years).
  • Security logs: kept for up to 90 days.
  • Backups: encrypted backups are overwritten on a rolling cycle of up to 35 days.

8. Who we share data with

We don't sell personal data. We share it only with service providers (processors) who help us run Sealkept, under written data processing agreements:

  • Cloud hosting: Oracle Cloud in Mumbai, India.
  • Cloudflare, which carries and protects traffic to our site worldwide.
  • An email delivery provider, to send reminders, alerts and messages.
  • A monitoring service we run ourselves (OpenObserve), which receives error reports, performance measurements and service events. It never receives message content, names, email addresses or private links.
  • Payment providers, to process subscriptions and one-off payments: Creem and Dodo Payments (who sell to you as merchant of record and handle tax) and, for payments in rupees, Pine Labs Plural in India.
  • Twilio, which sends check-in texts and calls, if you turn them on. It receives your mobile number and the reminder wording, never your letters.

Where a processor handles data outside the EEA, we rely on an adequacy decision or the European Commission's Standard Contractual Clauses, with additional safeguards where needed. We may also disclose data where required by law, or to protect the rights and safety of our users.

9. Cookies and local storage

We use only what's needed for the site to work:

  • Essential authentication cookies, which keep you signed in and protect against cross-site request forgery.
  • A signed-in flag (no account details), so public pages can show a link back to your dashboard.
  • Your light or dark theme preference, stored in your browser's local storage, not sent to us.

We don't use advertising, analytics or tracking cookies, so we don't ask for cookie consent. If that changes, we'll ask first.

10. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • correct inaccurate data;
  • delete your data (the "right to be forgotten");
  • receive your data in a portable format;
  • restrict or object to certain processing, including processing based on legitimate interests;
  • withdraw consent at any time, without affecting processing that took place before.

Most of this you can do yourself in your account settings. Otherwise, write to [email protected] and we'll respond within one month. You also have the right to complain to a data protection authority, such as the Irish Data Protection Commission or the authority where you live.

11. When a user dies

When your switch is released, we deliver your messages to the recipients you chose, as you instructed. Family members or executors may contact us about an account, but we will only release messages according to your own settings and will not give anyone else access to your account.

12. Changes to this policy

If we make material changes, we'll tell you by email before they take effect. The date at the top shows when this policy was last updated.

13. Contact

Sealkept Ltd, Dublin, Ireland. Email: [email protected].


Questions about this document? Write to [email protected].