๐Ÿšง Diese Seite befindet sich noch in der Entwicklung Beta v3.0
๐Ÿ” Encipher.Me

Anmelden

Zugang zu Ihrem sicheren Bereich

๐Ÿ”’ Privacy Policy

Transparent privacy practices for maximum privacy

๐Ÿง  Zero-Knowledge Philosophy

Our Principles: Encipher.Me was developed according to the Zero-Knowledge principle - we technically cannot decrypt your messages, even if we wanted to. Your privacy is protected by architecture, not just by promises.

1. Responsible Party

Responsible party under GDPR:

[Your Company/Name]
[Street and House Number]
[ZIP City]
Germany

Contact:
E-Mail: privacy@encipher.me
Website: Contact Form

2. What Data Do We Collect?

๐Ÿ” Encrypted Messages

What: Encrypted data blocks of your messages

How long: Maximum 30 days or until configured access limit

Purpose: Providing encryption services

Special note: Zero-Knowledge - we cannot decrypt this data

๐Ÿ‘ค Registered Users (optional)

What: Email address, encrypted password, usage statistics

How long: Until account deletion

Purpose: Account management and extended features

Legal basis: Art. 6 para. 1 lit. b GDPR (contract fulfillment)

๐Ÿช Technical Cookies

What: Session cookies, CSRF protection, theme settings

How long: Session end or up to 30 days

Purpose: Security and functionality of the website

Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest)

๐Ÿ›ก๏ธ Security Data for Registered Users

What: IP addresses, browser information (User-Agent), session IDs, login times

How long: Active sessions up to 1 hour, security logs up to 30 days

Purpose: Account security, session management, fraud detection, security dashboard

Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in account security)

๐Ÿ“ Note: This data is stored exclusively for security purposes and is viewable in your account's security dashboard.

3. What Do We NOT Collect?

  • โŒ No tracking cookies - No analytics or advertising
  • โŒ No message content - Zero-Knowledge architecture
  • โŒ No metadata - Who, when, how often accesses remains unknown

4. Zero-Knowledge Technology

๐Ÿ”‘ Client-Side Encryption

All encryption operations take place in your browser. Encryption keys are never transmitted to our servers.

๐Ÿ”— URL Fragment Technology

Decryption keys are transmitted in the URL fragment (#). Browsers never send these fragments to servers.

๐Ÿšซ Server-Side Blindness

Our servers only receive encrypted data blocks. Even in the event of a complete server hack, your messages remain protected.

5. Your Rights Under GDPR

You have the following rights:

  • Art. 15 GDPR: Information about processed data
  • Art. 16 GDPR: Rectification of incorrect data
  • Art. 17 GDPR: Deletion ("right to be forgotten")
  • Art. 18 GDPR: Restriction of processing
  • Art. 20 GDPR: Data portability
  • Art. 21 GDPR: Objection to processing
  • Art. 77 GDPR: Complaint to supervisory authority

๐Ÿ”’ Zero-Knowledge Notice: Since we cannot decrypt your messages, providing information about specific message content is technically impossible. We can only provide metadata (number of messages, creation times).

6. Data Security

๐Ÿ” Encryption

AES-256-GCM encryption, TLS 1.3 for all transmissions, secure hash procedures for passwords.

๐Ÿ›ก๏ธ Security Measures

CSRF protection, rate limiting, secure session management, regular security updates.

๐Ÿ—‘๏ธ Automatic Deletion

All data is automatically deleted after expiration - no backups, no recovery possible.

7. Cookies in Detail

Cookie Purpose Duration
PHPSESSID Session management for login Session end
csrf_token Protection against CSRF attacks Session end
theme Light/dark mode setting 30 days (localStorage)
cookieConsent Stores cookie consent 1 year (localStorage)

8. Contact and Complaints

Data Protection Officer:

E-Mail: privacy@encipher.me
Contact: Contact Form

Supervisory Authority:

You have the right to complain to the competent supervisory authority:

The Federal Commissioner for Data Protection and Freedom of Information
Graurheindorfer Str. 153
53117 Bonn
Phone: +49 (0)228-997799-0
Website: www.bfdi.bund.de

9. Changes to This Privacy Policy

This privacy policy may be updated as needed. Changes will be published on this page and take effect immediately.

Last updated: 25.08.2025

Questions About Privacy?

We are happy to help with questions about your data and our privacy practices.

๐Ÿ“ง Privacy Contact ๐Ÿ“„ Terms of Service