This Privacy Policy explains what data YourStrongbox collects, why, and how it is protected
when you use our password and secrets manager.
Data We Collect
Account data: your email address and a bcrypt hash of your account password (never the
password itself). Encrypted item data: the content of your passwords, notes, boxes, shared
items and secret links, stored only as AES-256-GCM ciphertext, plus the per-account
cryptographic salt and RSA public key needed to use the Service. Security and session data:
sign-in timestamps, IP address, approximate geolocation, device/browser user agent, and
session identifiers, used to detect suspicious logins and notify you of new sign-ins. Usage
statistics: aggregate activity such as login frequency and feature usage. Support
communications: any information you send us via the support/feedback feature or by email.
What We Cannot See
Because items are encrypted end-to-end on your device before being sent to us, we cannot read
the plaintext content of your passwords, notes, files, messages or secrets. We store and
transmit ciphertext only and have no technical means to decrypt it without your master
password.
How We Use Your Data
We use your data to create and secure your account and authenticate your sign-ins, send you
security notifications such as new sign-in alerts and password-reset links, detect and
prevent fraud and abuse (for example rate-limiting exports or flagging unusual login
locations), respond to support requests, and maintain and improve the Service. We do not sell
your personal data, and we do not use your encrypted item content for advertising or
profiling.
Cookies and Sessions
We use session cookies to keep you signed in (sessions last up to 30 days) and to maintain
basic security state such as CSRF protection. We do not use third-party advertising or
tracking cookies.
Data Retention
Deleted items are retained in a trash folder for 30 days before permanent deletion. Secret
links and shared messages expire automatically based on the time limit or view limit you set
when creating them. Sign-in and security logs are retained for a limited period for
fraud-prevention purposes, then deleted or anonymized. If you delete your account, your data
is permanently deleted, subject to any retention required by law.
Third Parties
We use third-party infrastructure providers, such as hosting, database, email-delivery and
IP-geolocation services, strictly to operate the Service. These providers process data on our
behalf under appropriate confidentiality and security commitments, and never receive your
decrypted item content, master password, or encryption keys.
Security Measures
Items are protected with AES-256-GCM end-to-end encryption, account passwords are hashed with
bcrypt, and key material is derived using PBKDF2-HMAC-SHA256 with a unique salt per account.
Access to production systems is restricted, and we apply regular security updates. No system
is completely immune to risk, and we encourage you to use a strong, unique master password and
to never share it with anyone.
Your Rights
You can, at any time, from your account settings export your stored items, review and update
your account information, or delete individual items or your entire account and all
associated data. Depending on your jurisdiction, you may also have additional rights to
access, correct, or request deletion of your personal data. Contact us to exercise these
rights.
Children's Privacy
The Service is not directed to children under 16, and we do not knowingly collect personal
data from them.
Changes to This Policy and Contact
We may update this Privacy Policy from time to time. Material changes will be reflected on
this page with an updated revision date. For privacy questions or requests, contact us at
[email protected] or 40, Akademika Hlushkova avenue, Kyiv, 03187, Ukraine.