Privacy Policy
This Privacy Policy explains how SimpleKrypt ("we", "us", or "our") handles personal data when you visit https://simplekrypt.com (the "Site") or use the SimpleKrypt application at https://app.simplekrypt.com (the "Service").
SimpleKrypt is a team vault for cryptographic keys, secrets, secure notes, and certificates. The Site provides product information; the Service is where organizations store and manage vault data.
1. Who is responsible for your data?
For the purposes of applicable data protection law, SimpleKrypt is the controller of personal data described in this policy. Contact us at hello@simplekrypt.com.
2. What we collect
Marketing Site
The Site is largely static. We do not require an account to browse it. We may collect limited technical data through hosting and security logs, such as IP address, browser type, referring page, and timestamps. If you email us, we receive the information you choose to send.
SimpleKrypt Service
When you register and use the Service, we process data including:
- Account and identity data — name, email address, and authentication identifiers provided through our identity provider (Clerk).
- Organization data — organization name, membership, roles, project access, and billing plan.
- Vault metadata — resource names, types, folders, fingerprints, expiry dates, audit timestamps, and similar non-secret descriptive fields needed to browse and administer the vault.
- Encrypted vault content — private keys, secret values, note field values, certificate private keys, and other sensitive material stored in encrypted form. Sensitive fields are encrypted before storage; the Service is designed so plaintext sensitive values are not returned in routine API responses.
- Usage and audit data — records of vault actions (who changed what and when), available on eligible plans.
- Support data — messages and diagnostic information you send us, including API trace IDs where provided to help resolve issues.
3. How we use personal data
We use personal data to:
- Provide, operate, and maintain the Service
- Authenticate users and enforce organization access controls
- Process subscriptions and billing through Clerk Billing
- Send service-related communications (for example, invitations, security notices, or billing updates)
- Monitor reliability, prevent abuse, and improve the product
- Respond to support requests and legal obligations
We do not sell your personal data.
4. Legal bases (EEA/UK users)
Where applicable, we rely on:
- Contract — to provide the Service you or your organization signed up for
- Legitimate interests — to secure, improve, and administer the Service, and to operate the Site
- Legal obligation — where we must comply with law
- Consent — where required, for example for optional communications
5. How we share data
We share personal data only as needed to run SimpleKrypt, including with:
- Clerk — authentication, organization membership, and subscription billing
- Cloud infrastructure providers — hosting, storage, and operational services (including Google Cloud Platform for key-management functions used in envelope encryption)
- Email providers — if configured for invitations, notifications, or share-link delivery
- Professional advisers and authorities — where required by law or to protect rights and safety
Share links you create may expose selected vault material to recipients you choose. One-time share links are designed to expire after use or after a time limit.
6. Security
We use administrative, technical, and organizational measures appropriate to a secrets-management product, including envelope encryption for sensitive vault fields, role-based access controls, and audit logging on eligible plans.
No method of transmission or storage is completely secure. Some operations — such as file crypto and share-link delivery — may process content on our servers by design. Details are described in our Service documentation and on the Site.
7. Retention
We retain personal data for as long as your organization uses the Service and for a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce agreements. You may request deletion of your account subject to organizational controls and legal requirements. Organization Super Admins control membership and access within their tenant.
8. International transfers
We and our subprocessors may process data in countries other than your own. Where required, we use appropriate safeguards for cross-border transfers.
9. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or object to certain processing of your personal data, and to data portability or withdrawal of consent where applicable.
To exercise these rights, contact hello@simplekrypt.com. You may also lodge a complaint with your local data protection authority.
10. Children
SimpleKrypt is a business service and is not directed at children under 16. We do not knowingly collect personal data from children.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last updated" date. Material changes may also be communicated through the Service or by email where appropriate.
12. Contact
Questions about this Privacy Policy: hello@simplekrypt.com